Information Security vCISO

09/02/2026|1.7 min|

Client: UK and Middle East Based Bank

The Work

Our Client leveraged our vCISO service to assess its Information Security framework and drive the necessary changes to align it to ISO27001 industry standards. The engagement involved providing Information Security leadership, working with the Head of IT and the COO, to position Information Security as a critical focus area with the bank’s executive leadership and the board of directors. One of the main goals was to raise the profile of Information Security and to ensure continuous support of the Client’s initiatives to improve Information Security controls.

How We Helped

The first step was to ensure that the bank’s executive team gained a thorough and realistic appreciation of the nature and ramifications of the threats to the security of data and business operations, as well as the need to act to ensure an appropriate and demonstrable response.

We undertook a comprehensive review of Information Security controls across the bank.

This resulted in a detailed gap analysis and remediation plan to mitigate control gaps and align policies and working practices to ISO27001. At the request of the Head of IT, we led the communication of the findings and recommendations to the executive team and secured their sponsorship to execute the remediation plan in full.

Under the supervision of our vCISO service, a new Information Security Manager (ISM) was recruited. We worked collaboratively with the ISM to define, implement and communicate new policies and procedures.

Our virtual CISO provided guidance and mentoring to the ISM until the role gained credibility and was adequately established within the bank’s governance framework.

Value Added

From a position of low visibility, Information Security risk and control awareness was raised to board level and became a standing agenda item for the Executive Management Committee. An ISO27001 aligned policy set was implemented with a new role of Information Security Manager created to own and maintain Information Security risk management. The result was a structural shift in Information Security management capability at the bank.