Not starting? Some browsers and work networks block in-page audio. Listen on Spotify or Apple Podcasts.
Prefer your own app? Spotify · Apple Podcasts
NIS2 and DORA have changed who is accountable for cybersecurity. Boards are asking questions and regulators want evidence. Hiring a full-time CISO is one answer, but it is not the only one.
Ronan Murray and Ian Finlayson look at the vCISO model: what it involves, how it differs from a full-time CISO, and why it has become a practical route for organisations facing board-level accountability without a dedicated security executive. Ian explains how a vCISO embeds as part of the organisation rather than sitting outside it as a consultant, and why that matters for governance and incident response.
The key thing here is to get the action and momentum underway. If you don't, you're actually moving nowhere.
The best time to start preparing for NIS2 was three, four years ago. The second best time is now.
Ronan MurrayWhile they're not a full-time staff member, they're also not just an external consultant. And it's that identity that's very important.
Ian FinlaysonEveryone is on that journey, but everyone also started at the same place. There's no need for anyone to be embarrassed if the maturity level is low.
Ian FinlaysonHelping the business is key, as opposed to going in and auditing the business and judging the business.
Ronan MurrayA structured review of your security controls, policies and technical posture, with a written report and prioritised roadmap.
See what's included
Episode 10Dr Paul Guckian on systemic cyber risk: why CISOs can't fix cybersecurity alone, why containment matters, and how to plan for resilience.
ListenNIS2 expanded its scope considerably. Here's how to check your organisation's exposure.
ReadSenior security leadership embedded in your organisation, without a full-time hire.
Find out more
Talk to Ian. Ian Finlayson, Chief Security Services Officer at Edge7 Networks, is happy to talk through what this looks like for your environment.
ISO 27001:2022 · ISO 9001:2015 · Cyber Essentials · Networking and security specialists since 2018