Somebody has to own security. At the moment, nobody does
Your IT is covered. Your security isn’t owned by anyone. A named CISO — CISSP and C|CISO certified — for a set number of days a month, at a published price. From £1,200 a month.
Find out what a CISO would actually change
Book your free consultation30 minutes. No obligation. You keep the findings either way.
Most businesses between ten and a hundred people have solved IT. There is somebody in-house, or an outside provider, and between them the laptops work, the email works and things get fixed.
What nobody has is an owner for security. Not a tool, not a supplier — a person whose actual job is to know where the business is exposed, decide what to do about it in what order, and be answerable for the decision.
You notice the gap in specific moments, and always at the worst time.
A customer sends a forty-question security questionnaire before they will sign, and it lands on whoever is least able to say no.
The insurer’s renewal form asks whether you have an incident response plan, and the honest answer is no.
Somebody on the board asks how exposed the business actually is, and the honest answer is that nobody knows.
A supplier gets breached and nobody can say what they had access to.
Every one of those is the same missing role. None of them is an IT problem, and none of them gets solved by buying more software.
The traditional answer is to hire a Chief Information Security Officer — a six-figure salary, plus everything that sits on top of one. For a business of thirty people that is absurd — not because the role isn’t needed, but because the role isn’t needed full time.
This is that role, in the amount you actually need it.
Already a QuantumCare Business Pro client? Then some of this is already included in what you pay. We’ve written out exactly what the difference is, and what you’d actually be adding, rather than hoping you don’t ask. See the pricing section.
One price, one list. Every item below is work that gets done, not access that gets granted.
This is the part of security that isn’t software. There is nothing to install and nothing to license. What you are buying is a named, qualified person doing the work a Chief Information Security Officer does — and the written output of that work, which is yours to keep whatever happens next.
What is not in here matters as much. There is no monitoring, no software and no IT support in this price — this is the leadership half of security, not the technology half. The next section lists every one of those removals by name, with the reason for each.
This is a leadership service. It is deliberately not a technology service, and the two get confused often enough that it is worth being blunt.
None of this is a trap. Everything above is out on purpose, listed rather than buried, and priced separately where it can be bought at all. The most common reason a fractional CISO arrangement fails is that nobody agreed at the start what the person was actually for. This list is that agreement, written down before you pay anything.
Four steps from first conversation to a security programme that is actually running. No long procurement, no surprise costs.
A conversation, not a pitch. Half an hour on where you are, what is being asked of you, and whether this is the right thing to buy at all. If it isn’t, we’ll say so.
We build the risk register, review what you already have, write the policy pack and produce the roadmap. By the end you have a document that answers “how exposed are we?” and a plan with costs and dates on it.
Your committed days, every month, spent on whatever the roadmap says matters. Policies landed, suppliers reviewed, questionnaires answered, your IT provider briefed and checked.
A written report and a meeting: what changed, what it cost, what is next, and what is still on the risk register and why. In language a board can act on.
The first quarter is the one that changes things. Most of what a CISO is worth arrives in the first ninety days, because that is when the guessing stops. If after one quarter you have the register, the roadmap and the policies and you would rather take it from there yourself — that is a fine outcome, and the documents are yours.
Priced by headcount, published in full, and the same figure whoever asks. No quote, and no discovery call before you are allowed to know.
— or pick your band below.
All prices exclude VAT. Rolling monthly, 30 days’ notice, no setup fee and nothing to pay upfront.
Because more people means more accounts, more suppliers, more policies that have to actually land, and more of the risk being about human behaviour.
It is not a perfect measure and we will not pretend it is — a fifteen-person fintech is more work than a fifteen-person builder. The band sets the starting price. If yours is genuinely heavier we will say so on the first call, before you sign anything, rather than after.
The comparison worth making. A full-time Chief Information Security Officer in the UK commands a six-figure salary, and that is before employer’s National Insurance, pension, recruitment fees and the six months you spend hiring. This service costs £1,200 a month — £14,400 a year, for the fraction of the role a business your size genuinely uses.
Then some of this is already yours. Business Pro includes a named person who is accountable for your security, an information security policy pack and a quarterly review, as part of the £710.
QuantumCare CISO is the same person doing substantially more of it: committed days rather than access, a live risk register reviewed every month, board reporting, supplier review, questionnaires answered for you, and audit support carried all the way through.
Pro clients pay the difference between the two rather than paying twice. Ask, and we will show you the actual figure for your business. We would rather write that down than let you find it out.
A fractional CISO should leave
something behind
The reason fractional CISO arrangements get a bad name is that too many of them are a slide deck and an invoice — somebody who arrives, tells you what is wrong, and leaves you with a list you cannot act on. This is built the other way round. The days are counted, the output is written down, the price is published, and everything it does not cover is on this page rather than in a contract.
The same named individual every month, who by the third month knows your suppliers, your systems and which of your people click things. Not a methodology delivered by whoever was free that week.
The risk register, the policies, the roadmap, the incident plan. If you leave, you keep all of it. We don’t hold your documentation hostage and we don’t build it in a system only we can open.
Rolling monthly, 30 days’ notice, no setup fee and nothing upfront. If it isn’t earning its keep you leave, and we won’t make it difficult.
Past about two hundred and fifty people, or when security becomes a full-time job on its own, you should be hiring rather than renting. We’ll say so — and help you write the job description if you want.
Founder, Systems Secure Ltd · CISSP, C|CISO
I spent twenty-one years in the oil and gas industry, doing IT, networks and cyber security for global corporations. I led multi-million dollar projects that spanned the globe and spent a good deal of those years travelling across America and Europe designing and implementing them. Big budgets, long timescales, and no forgiveness for anything that didn’t work.
In 2016 I sat the Certified Ethical Hacker exam — the opposite discipline, a formal qualification in breaking into systems rather than defending them. What it showed me was that the doors standing open belonged to the small firms, not the global corporations. I had got very good at protecting organisations that could afford to be protected, while the eight-person firm down the road faced the same attackers with none of the same defences — and wouldn’t still be trading six months after a bad week.
So I changed what the company did. Systems Secure has been trading since 2010, the last ten of those years full time, and cyber security is now all it does.
When you ring, you get me.
Security letters after a name are close to meaningless unless you know what somebody had to do to get them. So here is what these two actually required — both published by the awarding bodies, and both checkable without taking my word for anything.
Awarded by ISC2. It cannot be sat on reading alone: it requires five years of paid, full-time security experience across at least two of its eight domains, documented, and then endorsed by somebody who already holds it.
What it tells you The person advising you has done the work, not just studied it.
Awarded by EC-Council. It requires five years of experience in three of its five domains — and the fifth domain is Strategic Planning, Finance, Procurement and Third-Party Management. That is not a technical subject. It is budgets, suppliers and the board.
What it tells you The person advising you has run a security programme, not just secured a network.
Both awarding bodies require 120 hours of documented continuing education every three years — ISC2 for the CISSP, EC-Council for the C|CISO and the C|EH. Miss it and the certificate is suspended. Let it lapse far enough and you sit the exam again.
That is not a promise I am making about myself. It is a condition somebody else enforces, and it is the reason the advice you get in year three will not be the advice from year one.
They are doing two different jobs, and this service needs both.
The CISSP side is what makes a risk register worth reading. Knowing which of a hundred findings actually matters — and which three are worth spending money on this quarter — takes somebody who has fixed them before, and who has been formally trained in how they get exploited. A scanner will hand you a hundred red lines. Ranking them honestly is a judgement about what an attacker would really do first, and that judgement is the difference between a plan and a to-do list.
The C|CISO side is what turns that into a roadmap with costs on it, a supplier review, an answer to the customer’s questionnaire and a report your board can act on.
Somebody with only the first gives you a list of problems. Somebody with only the second gives you a framework. Neither is what you are trying to buy.
Also holds
Recognition
Systems Secure Ltd · trading since 2010 · company registration 7295869 · Copthorne, West Sussex
The main ones that come up on almost every call, answered here so you don’t have to book one to find out.
QuantumCare CISO is priced by headcount, in five published bands. For a business of 10–20 employees it is £1,200 a month. For 21–50 employees it is £2,000. For 51–100 employees it is £3,200. For 101–150 employees it is £4,000. For 151–250 employees it is £4,800.
Each band buys a committed number of days of a named, CISSP and C|CISO certified Chief Information Security Officer: a day and a half a month at 10–20 people, two and a half days at 21–50, four days at 51–100, five days at 101–150 and six days at 151–250.
There is no band above 250. Past that size the honest advice is to employ a CISO rather than rent one, and we will tell you so.
All prices exclude VAT. It is rolling monthly with 30 days' notice, there is no setup fee and nothing to pay upfront. The prices are published in full on this page — there is no quote to request and no discovery call before you are allowed to know.
It is a lot, and it should be — you are buying a day and a half of a senior person, every month, for as long as you want it.
The comparison that matters is not with a piece of software. It is with the alternative, which is hiring somebody to do this job full time. A Chief Information Security Officer in the UK is a six-figure salary before National Insurance, pension, recruitment fees and the months you spend looking. £1,200 a month is a fraction of that, for the fraction of the role a business your size genuinely uses.
The other comparison is with doing nothing, which is what most businesses your size are doing. That is free right up until the contract you lose on the security questionnaire, or the insurance claim that gets refused because the form was answered wrongly.
If the number is genuinely out of reach, say so on the call. There are cheaper things worth doing first and we will tell you what they are.
Everybody on your payroll, full-time or part-time, plus any long-term contractor who works in your systems as though they were staff.
We count heads rather than full-time equivalents, because the security work follows people, not hours. Two people at half time are two sets of logins, two laptops and two people who can click something.
We take your number in good faith. Nobody is audited, and if you are near a band edge we will talk about it rather than push you up one.
Part-timers count. Long-term contractors who work in your systems count. Someone you use twice a year who never touches your data doesn't.
The test is simple: does this person have access to your systems in a way that would matter if their account were taken over? If yes, they are part of the security problem and part of the count.
We tell you before you cross rather than after, and the change lands on the next invoice.
This is a real step — £1,200 to £2,000 is not a rounding — so nobody should be surprised by it. In practice the conversation happens at a quarterly review, with enough notice to plan for it. And if you have crossed the line by one person, we will use judgement rather than a spreadsheet.
Bands change when your headcount changes, and it lands on the next invoice — up or down. If you shrink, the price comes down. That is not something you have to ask for.
Pausing is not something we offer, because a paused CISO is just an ended one with extra paperwork. If you need to stop, give 30 days' notice and stop. Coming back later is easy and there is no penalty for having left.
Yes, a simple written agreement setting out what is included, what isn't, and the notice period. Nothing in it will contradict what is on this page.
It is rolling monthly with 30 days' notice. There is no twelve-month tie-in on this service, deliberately — a CISO relationship that has to be locked in to survive is not one that is working.
No. Rolling monthly from the first month.
Worth being honest about what that means in practice, though: the first ninety days are where most of the value lands, because that is when the guessing stops. Leaving after one month is allowed, and it is unlikely to have been worth your money.
No. Nothing to pay upfront, and the first ninety days of work — the register, the review, the policies, the roadmap — are part of the monthly fee rather than a separate onboarding charge.
Then you leave. Rolling monthly means 30 days' notice and no penalty.
There is no minimum term, no setup fee and nothing to pay upfront, so the most you can be out of pocket is a month you have already had.
You also keep everything written during it — the risk register, the policies, the roadmap, the incident plan. None of it is held back.
They don't roll over, and we would rather print that than have you discover it in month two.
The reason is that the retainer buys availability as much as it buys hours. The month you use half a day is what makes the month you need three days possible, and a rollover system quietly ends up being a bank of hours that nobody can ever schedule.
The other side of it is the same promise in reverse: if a month runs over — and some will, particularly during a certification push — we tell you at the time and agree what happens, rather than quietly doing less somewhere else to make the numbers work.
No. None of it. Nothing gets installed and nobody is watching your systems overnight.
This is the leadership half of security, not the technology half. If you already have monitoring and backup, part of the job is assessing whether they are any good. If you don't, that is what the QuantumCare monitoring packages are for and they are priced separately on their own pages.
Buying a CISO and believing you are therefore defended is the single most expensive misunderstanding available, which is why it is written on the page in as many words rather than left to be inferred.
Both, but the line is worth being clear about, because getting it wrong is how these arrangements sour.
We do: the risk register, the policies, the roadmap, the incident response plan, the questionnaires, the supplier review, the specification of what needs changing and why, and the checking that it actually got changed.
We don't: log into your firewall and reconfigure it, rebuild your Microsoft 365 tenancy, or deploy software. That is hands-on engineering and it belongs with whoever runs your IT.
Specifying properly is most of the work. "Turn on multi-factor authentication" is not a plan; a written change with a scope, an order, a rollback and a date is. You get the second one.
Four things, all written down and all yours:
A risk register — every risk in business language, with an owner, a decision and a date. This is the document that answers "how exposed are we?", and most businesses have never had one.
A review of what you already have — the tooling, the settings, the suppliers, and an honest verdict on each.
An information security policy pack — written for your business, in language your people will read, not a template with your logo dropped on it.
A costed roadmap — twelve months, in priority order, with prices attached so it can go in a budget rather than a wish list.
If you took those four documents and walked away at the end of the quarter, you would have had your money's worth. Some people do, and that is a fine outcome.
Yes, and it is one of the most common reasons people arrive here.
We get you to the point where you would genuinely pass — Cyber Essentials or Cyber Essentials Plus — and support you through the assessment itself. What we will not do is help you answer a question in a way that isn't true. The certificate is worth exactly as much as the honesty behind it, and a customer who later discovers otherwise is a worse problem than not having it.
The certification body's own fee is separate and paid by you directly.
We can do most of the work. We cannot award the certificate, and neither can anybody else selling you one directly — certification comes from a UKAS-accredited certification body, and it has to, or it is worth nothing to the customer asking for it.
What we do is the groundwork: the risk register, the statement of applicability, the policies, the evidence trail, and sitting with you through the audit itself. That is the large majority of the effort.
Be realistic about the timescale. For a business coming from a standing start, ISO 27001 is a twelve to eighteen month piece of work, not a quarter. Anyone promising it faster is either not doing it properly or you were most of the way there already.
No. The DPO under UK GDPR is a defined role with independence requirements attached to it, and it is not the same job as a CISO — a point that gets blurred often enough to be worth stating plainly.
There is genuine overlap and we will work closely with whoever holds it. But appointing us to that role is not what this service buys, and anybody telling you the two are interchangeable has not read the regulation.
No. This service has no software in it at all, so there is nothing that needs to be compatible with anything.
We work with what you have — Microsoft, Google, something bespoke, or a mixture, which is what most businesses actually are. Part of the first ninety days is establishing what "what you have" even means, which is more often a surprise than it should be.
Neither had any of our clients, until the ones who did.
The businesses that get hit aren't targeted for being interesting — they're targeted for being reachable. The question isn't whether you've been unlucky yet.
Then you are ahead of most, and part of the first ninety days is finding out how good it actually is.
But software is not the gap this fills. Nobody's antivirus decides which risk the business accepts and which it spends money on. Nobody's firewall answers a customer's security questionnaire, writes the incident response plan, reviews what your suppliers can reach, or explains to your board where you stand.
Those are decisions and they need an owner. That is the job.
No. Nobody credible can promise that — and you should be wary of anyone who does.
What this commits to is that the decisions get made by somebody qualified, written down, and reviewed. That when something does happen, there is a plan rather than a scramble. And that when somebody asks you to prove your position, the answer is true and the evidence exists.
The goal is simple — fewer incidents, smaller impact, faster recovery, and no nasty surprises on a form.
No. Nobody credible can promise that — and you should be wary of anyone who does.
What we do commit to is fast action: quick detection, rapid containment, and telling you straight away and in plain English when something has happened.
The goal is simple — fewer incidents, smaller impact, faster recovery.
Honestly? On this service, not much, and you should know that before you buy rather than after.
A CISO works business hours. What this buys you is that the incident response plan exists, the numbers are in it, your people know who to ring, and somebody has thought about the decision before the night it has to be made. That is worth a great deal more than most people expect.
What it does not buy is somebody detecting the problem and containing it while you sleep. That is round-the-clock monitoring, it runs through a security operations centre rather than through a person, and it is a different product that we also sell.
If 2am is your actual worry, buy the monitoring first and the CISO second. We will tell you that on the call.
Yes. Insurance and security do different jobs — one reduces the chance of something happening, the other pays for the consequences when it does. Neither replaces the other.
What changes is that the proposal form gets answered accurately, with evidence behind it. That matters more than the premium does: inaccurate answers on a proposal form are one of the main reasons cyber claims get refused, and that is not something anybody wants to discover on the worst day of their year.
Good — keep them. This works alongside your IT provider, not instead of them. They keep the business running; we own the security decisions and give them a clear brief.
Most IT providers are relieved. Security is the part of the job they are most exposed on and least equipped for, and being quietly expected to have thought of everything is an uncomfortable place to sit. A defined brief is easier than an unspoken expectation.
It also means the person checking that security work landed properly isn't the same person who did it. That independence is worth something on its own.
No, and you should be suspicious of anyone who says they do. Somebody still has to run the network, manage the devices and fix things when they break. That is not this job.
What changes is that the security decisions stop being their problem by default. They get a written brief and someone to escalate to; you get someone independent checking the work landed.
You are almost certainly too small to need a full-time one. That is the entire reason this exists.
The role is not really about size. It is about whether anyone owns the security decisions, and in most businesses this side of two hundred and fifty people, nobody does — it lands on the IT manager, the operations director or the founder, on top of a full job, and it gets the attention that leaves.
If you employ fewer than ten people we will usually tell you that your money goes further on protection than on leadership, and point you at QuantumCare Micro Business instead.
No, and this is the question most worth reading carefully.
Business Pro includes, as part of the £710, a named person who is accountable for your security, an information security policy pack, and a quarterly review. That is real and it is not being taken away.
QuantumCare CISO is the same person doing substantially more of it: committed days rather than access, a live risk register reviewed every month, board-level reporting, supplier and third-party review, customer questionnaires answered for you, and audit support carried all the way through rather than pointed at.
If you are already a Business Pro client you pay the difference between the two, not both. Ask and we will show you the actual figure for your business.
We tell you, and we help.
Past roughly two hundred and fifty people — or sooner if security becomes a full-time job on its own, which happens in regulated sectors — you should be employing somebody rather than renting one. At that point the honest advice is to hire, and we will say so, help you write the job description, and hand over the register, the roadmap and the policies to whoever takes it on.
Losing a client that way is a good outcome. It is what the service is for.
CISO stands for Chief Information Security Officer — the person in a large company who owns security at board level. The "v" is for virtual, and it means you rent a share of that person rather than employing one.
The reason the term exists is that the role is genuinely needed well below the size at which the salary makes sense. A hundred-person business has the same questionnaires, the same insurers and the same suppliers as a thousand-person one — it just has a fraction of the budget.
In plain terms: somebody senior enough to make the call, accountable for having made it, for a day or two a month.
Yes, and much more tightly.
Business Pro caps at twenty clients. This cannot be anywhere near that number, because it is committed days rather than shared attention.
The cap here is on the days rather than the clients: no more than ten days a month committed across every CISO client. A business of 10–20 people takes a day and a half of that; one of 151–250 takes six. So in practice it is somewhere between two and five clients at a time, depending on their size.
When those days are gone I say so on the first call rather than stretching and doing it badly.
James Batt. Every conversation, every quarter, every time you pick up the phone. Not an account manager, not a rota, and not a different consultant each quarter who needs your business explained to them again.
By month three you have somebody who knows your suppliers, your systems and which of your people click things. That familiarity is most of the value, and it is the thing a rotating team can never give you.
The advice and the relationship are one person, deliberately. At this price that is what you are buying — a named, accountable individual rather than a methodology delivered by whoever was free that week.
Where QuantumCare's other packages are concerned, the protection behind them is not one person: monitoring, detection and containment run around the clock through a dedicated security operations centre. But that is the monitoring packages, and it is not part of this service.
For QuantumCare CISO, the honest answer is yes — it is one person, on purpose, and that is what makes it worth buying.
Planned leave is a few times a year and you will know well ahead of it. The quarterly review moves; the work does not disappear.
Be straight with yourself about what this means, though: this is a leadership retainer from a named individual, so if that individual is away for a fortnight, your CISO is away for a fortnight. Anything genuinely urgent still reaches me. Routine work waits.
If you need cover that never pauses, what you need is monitoring, and that is a different product that runs through a security operations centre rather than through me.
Not without telling you first. On Business Pro that is a formal promise; here it is simpler than a policy — a CISO who knows both sides of a competitive market is in an impossible position, and I would rather turn the work down than be in it.
If it ever came close, you would hear about it from me before you heard about it anywhere else.
Usually within two weeks of agreement, and the first ninety days start from the first working session rather than from the invoice.
There is nothing to install, so there is no deployment to schedule. What there is instead is a handful of conversations with the people who know how things actually work, which is the part that sets the pace.
We work remote-first, and that is a large part of how the price stays where it is.
The quarterly review can be in person or on a call — your choice, and there is no fee for either. Being far away does not change the service: the work is remote, so a client in Inverness gets exactly what a client in Crawley gets.
Two things do change with distance, and both are said out loud rather than discovered later.
Travel and accommodation are charged at cost. Never marked up, itemised, and agreed with you before anything is booked. Locally that is usually nothing at all.
And the travel time comes out of your committed days. A day spent getting to you and back is a day not spent on your risk register, your policies or your suppliers. That is not a penalty — it is just what the days are. It means most clients further afield take three of the four reviews on a call and save the visit for the one that matters, which is generally the right call anyway.
Any other visit is charged separately: £240 for a short visit of up to two hours, £400 for a half day, £760 for a full day, on the same basis. Short visits are for sites within reach of us in West Sussex; further afield starts at a half day.
Beyond the paperwork, here is what having somebody own it actually buys you.
The questionnaire that arrives before a big deal stops being a scramble across three people who all think it belongs to somebody else. Someone owns the answer, the answers are true, and the weak ones get fixed before the form arrives rather than after it has cost you the work.
The form gets answered accurately, with evidence behind it. That matters more than the premium does — inaccurate answers on a proposal form are one of the main reasons cyber claims get refused, and nobody discovers that on a good day.
“How exposed are we?” stops being met with a shrug, or with a technical explanation nobody in the room follows. It gets a document, a number, a plan with costs on it, and a person who will stand behind all three.
They get a clear security brief instead of being quietly expected to have thought of everything. You get somebody independent checking the work landed. Both of those make the relationship better rather than worse, which surprises people.
The next step
You don’t have to decide anything on the call. We tell you what’s exposed, and you keep the findings either way — even if we’re not the right fit.
No obligation · No sales script · You keep the findings either way
James Batt · CISSP, C|CISO Founder, Systems Secure Ltd

Innovation
Fresh, creative solutions.


Excellence

Systems Secure Ltd
6 The Meadow, Copthorne, West Sussex. RH10 3RG
07702 896 910
Company Registration: 7295869
Copyright 2026. Systems Secure. All Rights Reserved.