glacierr
get in touch
typical engagement
6–8 weeks · then vciso on retainer

service · 05strategy · roadmap · governance · virtual ciso

cybersecurity strategic advisory

a strategy your board will follow.

We set where security goes over the next three years — costed, sequenced and tied to business risk — then stay alongside as senior leadership on tap.

3-year strategy costed roadmap governance zero trust virtual ciso
▼
6–8

weeks to a three-year strategy

3

year roadmap, costed and sequenced

vciso

on a rolling, fixed monthly fee

01what changes for you

what changes for you.

A direction the board can back, spend tied to risk rather than a vendor's pitch, and governance that actually runs — with senior leadership on tap after.

01

a direction the board can back

A three-year strategy tied to business objectives and risk appetite.

02

spend tied to risk

Every roadmap item linked to a risk, a gap or an obligation — not a vendor's pitch.

03

a zero trust path that fits

Sequenced against the Microsoft estate you already run. No rip-and-replace.

04

governance that runs

Policies and control ownership checked against what actually runs.

05

ai landed safely

Guardrails for Copilot and other AI agreed before the data goes somewhere it shouldn't.

06

senior leadership on tap

A virtual CISO for board reporting, risk and vendor reviews.

02what we typically find

programmes grow by reaction. strategy fixes that.

Most security programmes grow by reaction — the last incident, the last audit finding, the last vendor pitch. The result is tools nobody fully owns, a roadmap that is really a wish list, and a board that hears about security only when something goes wrong.

43%
of UK businesses reported a breach or attack in the last 12 months
31%
have a board member responsible for cybersecurity
15%
formally review risks from immediate suppliers

03our approach

discover · assess · shape · steer.

Four stages, each with a gate you sign. Senior consultants only — the people who scope are the people who deliver.

01 · discover

understand the business

02 · assess

see what really runs

03 · shape

build the strategy

04 · steer

stay alongside

04what you get

what you get.

05who it's for

who it's for.

board & ceo

A clear direction, and the decisions that need their name on them.

cfo

An investment case, not a wish list.

cio

A roadmap that fits the technology plan.

ciso & team

A mandate, a budget line and senior support.

Sources: DSIT, Cyber Security Breaches Survey 2025/26 (30 April 2026); DSIT, Cyber Governance Code of Practice (April 2025).

shall we get on with it?

Strategy in six to eight weeks; vCISO on a monthly retainer. We're not another platform trying to 'transform' your cyber tech.

also from glacierr.