Somebody has to own security. At the moment, nobody does

QuantumCare CISO: a Chief Information Security Officer, without the salary

Your IT is covered. Your security isn’t owned by anyone. A named CISO — CISSP and C|CISO certified — for a set number of days a month, at a published price. From £1,200 a month.

UK-based, since 2010 CISSP and C|CISO certified From £1,200 a month A named person, not an account team No lock-in, cancel any time Price published, no quote needed

Find out what a CISO would actually change

Book your free consultation

30 minutes. No obligation. You keep the findings either way.

Cybersecurity Company of the Year — West Sussex Business Awards 2025 Security Solution Specialists of the Year — E2 Media Awards 2025

Your IT keeps the business running.
That isn’t the same as owning its security.

Most businesses between ten and a hundred people have solved IT. There is somebody in-house, or an outside provider, and between them the laptops work, the email works and things get fixed.

What nobody has is an owner for security. Not a tool, not a supplier — a person whose actual job is to know where the business is exposed, decide what to do about it in what order, and be answerable for the decision.

You notice the gap in specific moments, and always at the worst time.

A customer sends a forty-question security questionnaire before they will sign, and it lands on whoever is least able to say no.

The insurer’s renewal form asks whether you have an incident response plan, and the honest answer is no.

Somebody on the board asks how exposed the business actually is, and the honest answer is that nobody knows.

A supplier gets breached and nobody can say what they had access to.

Every one of those is the same missing role. None of them is an IT problem, and none of them gets solved by buying more software.

The traditional answer is to hire a Chief Information Security Officer — a six-figure salary, plus everything that sits on top of one. For a business of thirty people that is absurd — not because the role isn’t needed, but because the role isn’t needed full time.

This is that role, in the amount you actually need it.

Built for a certain kind of business

You’re the right fit if

  • You employ ten or more people — below that the role is real, but the budget rarely is
  • IT is already handled — in-house, an outside provider, or both — and it isn’t the thing that’s broken
  • Nobody owns security. It lands on whoever has time, which means it lands nowhere
  • Customers, insurers or regulators are starting to ask questions you can’t fully answer
  • You want a plan with costs and dates on it, not a list of everything that’s wrong
  • Somebody at board or owner level actually wants to know, and will act on what they hear

You’re probably not the right fit if

  • You’re under ten people — the money goes further on protection at that size, and we’d rather tell you now
  • You want someone to fix laptops, reset passwords or run the network — that’s IT, and it isn’t what this is
  • You want the certificate without the work. We’ll get you ready for Cyber Essentials; we won’t help you answer questions untruthfully
  • You want 24/7 cover. A CISO works business hours — round-the-clock monitoring is a different product, and we sell that too
  • You want somebody to blame rather than somebody to work with — the findings will include things that are your decision, not ours
  • You already have a full-time security leader — then you don’t need one, and we’ll say so on the first call

Already a QuantumCare Business Pro client? Then some of this is already included in what you pay. We’ve written out exactly what the difference is, and what you’d actually be adding, rather than hoping you don’t ask. See the pricing section.

What’s included

One price, one list. Every item below is work that gets done, not access that gets granted.

This is the part of security that isn’t software. There is nothing to install and nothing to license. What you are buying is a named, qualified person doing the work a Chief Information Security Officer does — and the written output of that work, which is yours to keep whatever happens next.

The ownership

Somebody whose job this actually is
A named CISO
James Batt — CISSP and C|CISO certified. Not an account manager, not a rota, not a different consultant each quarter. The same person, who knows your business by month three.
A live risk register
The one document that answers “how exposed are we?”. Every risk written down in business language, with an owner, a decision and a date. Reviewed every month, not written once and filed.
A security roadmap with costs
A rolling twelve-month plan: what to do, in what order, what it costs, and what it buys you. Priced so it can go in a budget rather than a wish list.
The relationship with your IT provider
We take security off their plate and give them a clear brief instead. Most are relieved — it is the part of the job they are most exposed on and least equipped for.

The paperwork that gets asked for

Written for your business, and kept current
Information security policy pack
Written for your business, in language your people will actually read, and kept current. The pack an insurer, an auditor or a customer asks to see.
An incident response plan
Who does what, in what order, and who gets called — written down before you need it, and walked through with your team at least once a year so it isn’t the first time anyone has read it.
Board and management reporting
A written report and a meeting each quarter. Where you were, where you are, what it cost, what is next. Written for directors, not for engineers.
Supplier and third-party review
Which of your suppliers can reach your data, what happens if one of them is breached, and what your contracts actually say about it.

When somebody asks you to prove it

The forms, answered truthfully, with evidence behind them
Customer security questionnaires
The forty-question form that arrives before a big contract. We answer it, truthfully, and tell you in advance which answers are going to be weak so you can fix them first.
Cyber Essentials readiness
Cyber Essentials and Cyber Essentials Plus. We get you to the point where you would pass, and support you through the assessment.
ISO 27001 groundwork
The risk register, the policies and the evidence trail a certification body will want. We cannot certify you — nobody can except a UKAS-accredited body — but this is most of the work they will ask for.
Insurance renewal support
The cyber insurance form, answered accurately, with evidence behind it. Wrong answers on that form are how claims get refused.

How you reach us

Committed, planned and reported on
A direct security line
Phone and email, straight to James, in business hours. “Should we be worried about this?” is a perfectly good reason to ring.
Committed days each month
A day and a half, two and a half, four, five or six, depending on your size. Committed, planned, and reported on — not “as needed”, which always means “when there is time”.

What is not in here matters as much. There is no monitoring, no software and no IT support in this price — this is the leadership half of security, not the technology half. The next section lists every one of those removals by name, with the reason for each.

What QuantumCare CISO does not include

This is a leadership service. It is deliberately not a technology service, and the two get confused often enough that it is worth being blunt.

Any monitoring, protection or software
This is the one to read twice. Nothing gets installed. There is no antivirus, no threat detection, no patching, no backup and no web filtering in this price, and nobody is watching your systems overnight. If you already have those, we will assess them and tell you honestly whether they are any good. If you don’t, that is what the QuantumCare monitoring packages are for, and they are priced separately on their own pages. Buying a CISO and assuming you are now defended is the most expensive mistake available on this page.
IT support
Not on this service, and not on any of them. QuantumCare is a cyber security business. We don’t fix printers, set up laptops, recover forgotten passwords or answer “why is it running slowly”. Keep whoever does that for you — we work alongside them, and it goes better when we do.
Not what this is
Hands-on engineering
We decide what needs doing and specify it properly. We don’t log into your firewall and change it. Your IT provider implements; we own the decision and check it landed. Keeping those two apart is a feature rather than a limitation — it is how you get an honest opinion about work somebody else did, which you cannot get from the person who did it.
Your IT provider
The ISO 27001 certificate itself
Certification comes from a UKAS-accredited certification body, and it has to, or it is worth nothing to the customer asking for it. We do the groundwork — the register, the policies, the evidence — and sit with you through the audit. We can’t award it, and anybody offering to sell you the certificate directly should be treated with suspicion.
Groundwork only
Being your Data Protection Officer
The DPO under UK GDPR is a defined role with independence requirements attached to it, and it is not the same job as a CISO. There is real overlap and we will work with whoever holds it — but appointing us to that role is not what this buys, and anybody telling you the two are interchangeable has not read the regulation.
Different role
24/7 incident response
A CISO works business hours. If something happens at 2am, this service does not put somebody on the phone at 2am. What it does is make sure the plan exists, the numbers are known and somebody has thought about it before the night it matters. Round-the-clock detection and containment is a different product, and we sell it.
Penetration testing
Testing your systems the way an attacker would is specialist, chargeable work, and we will quote it separately when it is genuinely warranted. It is also, more often than not, not the thing you need first — most businesses at this stage get more from fixing what a scan has already found than from paying somebody to find more.
Chargeable
Legal advice
We will tell you what a regulation requires you to do about your systems. We will not tell you what your legal exposure is, what to put in a contract, or what to say to a regulator. If you need that, you need a solicitor, and we would rather point you at one than guess.
Not what this is
On-site presence as standard
We work remote-first, and the quarterly review can be in person or on a call — your choice, no charge either way. Anything beyond that is charged separately: £240 for a short visit of up to two hours, £400 for a half day, £760 for a full day. Travel and accommodation are added at cost and never marked up, and the whole figure is agreed with you before anything is booked. Short visits are for sites within reach of us in West Sussex; further afield starts at a half day.
Chargeable
Unlimited time
The days are committed and they are counted. If a month runs over — and some will, particularly during a certification push — we will tell you at the time and agree what happens, rather than quietly doing less somewhere else. Unused days do not roll over. We would rather print that than have you find it out in month two.
Named limit

None of this is a trap. Everything above is out on purpose, listed rather than buried, and priced separately where it can be bought at all. The most common reason a fractional CISO arrangement fails is that nobody agreed at the start what the person was actually for. This list is that agreement, written down before you pay anything.

How it works

Four steps from first conversation to a security programme that is actually running. No long procurement, no surprise costs.

1

Consultation

A conversation, not a pitch. Half an hour on where you are, what is being asked of you, and whether this is the right thing to buy at all. If it isn’t, we’ll say so.

2

The first ninety days

We build the risk register, review what you already have, write the policy pack and produce the roadmap. By the end you have a document that answers “how exposed are we?” and a plan with costs and dates on it.

3

The work

Your committed days, every month, spent on whatever the roadmap says matters. Policies landed, suppliers reviewed, questionnaires answered, your IT provider briefed and checked.

4

The quarter

A written report and a meeting: what changed, what it cost, what is next, and what is still on the risk register and why. In language a board can act on.

The first quarter is the one that changes things. Most of what a CISO is worth arrives in the first ninety days, because that is when the guessing stops. If after one quarter you have the register, the roadmap and the policies and you would rather take it from there yourself — that is a fine outcome, and the documents are yours.

What it costs

Priced by headcount, published in full, and the same figure whoever asks. No quote, and no discovery call before you are allowed to know.

people

— or pick your band below.

All prices exclude VAT. Rolling monthly, 30 days’ notice, no setup fee and nothing to pay upfront.

Why headcount?

Because more people means more accounts, more suppliers, more policies that have to actually land, and more of the risk being about human behaviour.

It is not a perfect measure and we will not pretend it is — a fifteen-person fintech is more work than a fifteen-person builder. The band sets the starting price. If yours is genuinely heavier we will say so on the first call, before you sign anything, rather than after.

The comparison worth making. A full-time Chief Information Security Officer in the UK commands a six-figure salary, and that is before employer’s National Insurance, pension, recruitment fees and the six months you spend hiring. This service costs £1,200 a month — £14,400 a year, for the fraction of the role a business your size genuinely uses.

Already a QuantumCare Business Pro client?

Then some of this is already yours. Business Pro includes a named person who is accountable for your security, an information security policy pack and a quarterly review, as part of the £710.

QuantumCare CISO is the same person doing substantially more of it: committed days rather than access, a live risk register reviewed every month, board reporting, supplier review, questionnaires answered for you, and audit support carried all the way through.

Pro clients pay the difference between the two rather than paying twice. Ask, and we will show you the actual figure for your business. We would rather write that down than let you find it out.

Straight dealing

A fractional CISO should leave
something behind

The reason fractional CISO arrangements get a bad name is that too many of them are a slide deck and an invoice — somebody who arrives, tells you what is wrong, and leaves you with a list you cannot act on. This is built the other way round. The days are counted, the output is written down, the price is published, and everything it does not cover is on this page rather than in a contract.

You get a person, not a framework

The same named individual every month, who by the third month knows your suppliers, your systems and which of your people click things. Not a methodology delivered by whoever was free that week.

Everything is written down, and it’s yours

The risk register, the policies, the roadmap, the incident plan. If you leave, you keep all of it. We don’t hold your documentation hostage and we don’t build it in a system only we can open.

No lock-in

Rolling monthly, 30 days’ notice, no setup fee and nothing upfront. If it isn’t earning its keep you leave, and we won’t make it difficult.

We’ll tell you when you don’t need us

Past about two hundred and fifty people, or when security becomes a full-time job on its own, you should be hiring rather than renting. We’ll say so — and help you write the job description if you want.

Who you’ll be working with

Add photo here

James Batt

Founder, Systems Secure Ltd · CISSP, C|CISO

I spent twenty-one years in the oil and gas industry, doing IT, networks and cyber security for global corporations. I led multi-million dollar projects that spanned the globe and spent a good deal of those years travelling across America and Europe designing and implementing them. Big budgets, long timescales, and no forgiveness for anything that didn’t work.

In 2016 I sat the Certified Ethical Hacker exam — the opposite discipline, a formal qualification in breaking into systems rather than defending them. What it showed me was that the doors standing open belonged to the small firms, not the global corporations. I had got very good at protecting organisations that could afford to be protected, while the eight-person firm down the road faced the same attackers with none of the same defences — and wouldn’t still be trading six months after a bad week.

So I changed what the company did. Systems Secure has been trading since 2010, the last ten of those years full time, and cyber security is now all it does.

When you ring, you get me.

The two certifications this service rests on

Security letters after a name are close to meaningless unless you know what somebody had to do to get them. So here is what these two actually required — both published by the awarding bodies, and both checkable without taking my word for anything.

CISSP

Certified Information Systems Security Professional

Awarded by ISC2. It cannot be sat on reading alone: it requires five years of paid, full-time security experience across at least two of its eight domains, documented, and then endorsed by somebody who already holds it.

What it tells you The person advising you has done the work, not just studied it.

C|CISO

Certified Chief Information Security Officer

Awarded by EC-Council. It requires five years of experience in three of its five domains — and the fifth domain is Strategic Planning, Finance, Procurement and Third-Party Management. That is not a technical subject. It is budgets, suppliers and the board.

What it tells you The person advising you has run a security programme, not just secured a network.

Neither of them is framed and forgotten

Both awarding bodies require 120 hours of documented continuing education every three years — ISC2 for the CISSP, EC-Council for the C|CISO and the C|EH. Miss it and the certificate is suspended. Let it lapse far enough and you sit the exam again.

That is not a promise I am making about myself. It is a condition somebody else enforces, and it is the reason the advice you get in year three will not be the advice from year one.

They are doing two different jobs, and this service needs both.

The CISSP side is what makes a risk register worth reading. Knowing which of a hundred findings actually matters — and which three are worth spending money on this quarter — takes somebody who has fixed them before, and who has been formally trained in how they get exploited. A scanner will hand you a hundred red lines. Ranking them honestly is a judgement about what an attacker would really do first, and that judgement is the difference between a plan and a to-do list.

The C|CISO side is what turns that into a roadmap with costs on it, a supplier review, an answer to the customer’s questionnaire and a report your board can act on.

Somebody with only the first gives you a list of problems. Somebody with only the second gives you a framework. Neither is what you are trying to buy.

Also holds

  • C|EH — Certified Ethical Hacker, 2016. The qualification that changed what this company does. It informs how risks get ranked here; it does not mean penetration testing is included, and the section above says so plainly.
  • NCSP Practitioner — qualified to build and run a security programme against the NIST framework, which is the structure insurers and larger customers increasingly expect to see behind your answers.
  • CompTIA Security+ — a common baseline requirement in government and defence supply chains.

Recognition

Cybersecurity Company of the Year Winner — West Sussex Business Awards 2025
Security Solution Specialists of the Year Winner — E2 Media Awards 2025

Systems Secure Ltd · trading since 2010 · company registration 7295869 · Copthorne, West Sussex

STILL NOT SURE?

Questions you're probably asking

The main ones that come up on almost every call, answered here so you don’t have to book one to find out.

Cost and Contracts

How much does QuantumCare CISO cost?

QuantumCare CISO is priced by headcount, in five published bands. For a business of 10–20 employees it is £1,200 a month. For 21–50 employees it is £2,000. For 51–100 employees it is £3,200. For 101–150 employees it is £4,000. For 151–250 employees it is £4,800.

Each band buys a committed number of days of a named, CISSP and C|CISO certified Chief Information Security Officer: a day and a half a month at 10–20 people, two and a half days at 21–50, four days at 51–100, five days at 101–150 and six days at 151–250.

There is no band above 250. Past that size the honest advice is to employ a CISO rather than rent one, and we will tell you so.

All prices exclude VAT. It is rolling monthly with 30 days' notice, there is no setup fee and nothing to pay upfront. The prices are published in full on this page — there is no quote to request and no discovery call before you are allowed to know.

£1,200 a month sounds like a lot

It is a lot, and it should be — you are buying a day and a half of a senior person, every month, for as long as you want it.

The comparison that matters is not with a piece of software. It is with the alternative, which is hiring somebody to do this job full time. A Chief Information Security Officer in the UK is a six-figure salary before National Insurance, pension, recruitment fees and the months you spend looking. £1,200 a month is a fraction of that, for the fraction of the role a business your size genuinely uses.

The other comparison is with doing nothing, which is what most businesses your size are doing. That is free right up until the contract you lose on the security questionnaire, or the insurance claim that gets refused because the form was answered wrongly.

If the number is genuinely out of reach, say so on the call. There are cheaper things worth doing first and we will tell you what they are.

What counts as an employee for the pricing?

Everybody on your payroll, full-time or part-time, plus any long-term contractor who works in your systems as though they were staff.

We count heads rather than full-time equivalents, because the security work follows people, not hours. Two people at half time are two sets of logins, two laptops and two people who can click something.

We take your number in good faith. Nobody is audited, and if you are near a band edge we will talk about it rather than push you up one.

Do part-timers, contractors and freelancers count?

Part-timers count. Long-term contractors who work in your systems count. Someone you use twice a year who never touches your data doesn't.

The test is simple: does this person have access to your systems in a way that would matter if their account were taken over? If yes, they are part of the security problem and part of the count.

We're near the top of a band and growing. What happens when we cross it?

We tell you before you cross rather than after, and the change lands on the next invoice.

This is a real step — £1,200 to £2,000 is not a rounding — so nobody should be surprised by it. In practice the conversation happens at a quarterly review, with enough notice to plan for it. And if you have crossed the line by one person, we will use judgement rather than a spreadsheet.

Can we change bands, or pause?

Bands change when your headcount changes, and it lands on the next invoice — up or down. If you shrink, the price comes down. That is not something you have to ask for.

Pausing is not something we offer, because a paused CISO is just an ended one with extra paperwork. If you need to stop, give 30 days' notice and stop. Coming back later is easy and there is no penalty for having left.

Is there a contract?

Yes, a simple written agreement setting out what is included, what isn't, and the notice period. Nothing in it will contradict what is on this page.

It is rolling monthly with 30 days' notice. There is no twelve-month tie-in on this service, deliberately — a CISO relationship that has to be locked in to survive is not one that is working.

Is there a minimum term?

No. Rolling monthly from the first month.

Worth being honest about what that means in practice, though: the first ninety days are where most of the value lands, because that is when the guessing stops. Leaving after one month is allowed, and it is unlikely to have been worth your money.

Is there a setup fee?

No. Nothing to pay upfront, and the first ninety days of work — the register, the review, the policies, the roadmap — are part of the monthly fee rather than a separate onboarding charge.

What if it doesn't work out?

Then you leave. Rolling monthly means 30 days' notice and no penalty.

There is no minimum term, no setup fee and nothing to pay upfront, so the most you can be out of pocket is a month you have already had.

You also keep everything written during it — the risk register, the policies, the roadmap, the incident plan. None of it is held back.

What if we don't use all the days?

They don't roll over, and we would rather print that than have you discover it in month two.

The reason is that the retainer buys availability as much as it buys hours. The month you use half a day is what makes the month you need three days possible, and a rollover system quietly ends up being a bank of hours that nobody can ever schedule.

The other side of it is the same promise in reverse: if a month runs over — and some will, particularly during a certification push — we tell you at the time and agree what happens, rather than quietly doing less somewhere else to make the numbers work.

What's covered — and what isn't

Does this include monitoring, antivirus or backup?

No. None of it. Nothing gets installed and nobody is watching your systems overnight.

This is the leadership half of security, not the technology half. If you already have monitoring and backup, part of the job is assessing whether they are any good. If you don't, that is what the QuantumCare monitoring packages are for and they are priced separately on their own pages.

Buying a CISO and believing you are therefore defended is the single most expensive misunderstanding available, which is why it is written on the page in as many words rather than left to be inferred.

Will you actually implement anything, or just tell us what to do?

Both, but the line is worth being clear about, because getting it wrong is how these arrangements sour.

We do: the risk register, the policies, the roadmap, the incident response plan, the questionnaires, the supplier review, the specification of what needs changing and why, and the checking that it actually got changed.

We don't: log into your firewall and reconfigure it, rebuild your Microsoft 365 tenancy, or deploy software. That is hands-on engineering and it belongs with whoever runs your IT.

Specifying properly is most of the work. "Turn on multi-factor authentication" is not a plan; a written change with a scope, an order, a rollback and a date is. You get the second one.

What do we actually get in the first ninety days?

Four things, all written down and all yours:

A risk register — every risk in business language, with an owner, a decision and a date. This is the document that answers "how exposed are we?", and most businesses have never had one.

A review of what you already have — the tooling, the settings, the suppliers, and an honest verdict on each.

An information security policy pack — written for your business, in language your people will read, not a template with your logo dropped on it.

A costed roadmap — twelve months, in priority order, with prices attached so it can go in a budget rather than a wish list.

If you took those four documents and walked away at the end of the quarter, you would have had your money's worth. Some people do, and that is a fine outcome.

Do you help with Cyber Essentials?

Yes, and it is one of the most common reasons people arrive here.

We get you to the point where you would genuinely pass — Cyber Essentials or Cyber Essentials Plus — and support you through the assessment itself. What we will not do is help you answer a question in a way that isn't true. The certificate is worth exactly as much as the honesty behind it, and a customer who later discovers otherwise is a worse problem than not having it.

The certification body's own fee is separate and paid by you directly.

Can you get us ISO 27001?

We can do most of the work. We cannot award the certificate, and neither can anybody else selling you one directly — certification comes from a UKAS-accredited certification body, and it has to, or it is worth nothing to the customer asking for it.

What we do is the groundwork: the risk register, the statement of applicability, the policies, the evidence trail, and sitting with you through the audit itself. That is the large majority of the effort.

Be realistic about the timescale. For a business coming from a standing start, ISO 27001 is a twelve to eighteen month piece of work, not a quarter. Anyone promising it faster is either not doing it properly or you were most of the way there already.

Are you our Data Protection Officer?

No. The DPO under UK GDPR is a defined role with independence requirements attached to it, and it is not the same job as a CISO — a point that gets blurred often enough to be worth stating plainly.

There is genuine overlap and we will work closely with whoever holds it. But appointing us to that role is not what this service buys, and anybody telling you the two are interchangeable has not read the regulation.

Do we need to be on Microsoft 365, or any particular systems?

No. This service has no software in it at all, so there is nothing that needs to be compatible with anything.

We work with what you have — Microsoft, Google, something bespoke, or a mixture, which is what most businesses actually are. Part of the first ninety days is establishing what "what you have" even means, which is more often a surprise than it should be.

Risk and threats

We've never had a breach

Neither had any of our clients, until the ones who did.

The businesses that get hit aren't targeted for being interesting — they're targeted for being reachable. The question isn't whether you've been unlucky yet.

We already have security software.

Then you are ahead of most, and part of the first ninety days is finding out how good it actually is.

But software is not the gap this fills. Nobody's antivirus decides which risk the business accepts and which it spends money on. Nobody's firewall answers a customer's security questionnaire, writes the incident response plan, reviews what your suppliers can reach, or explains to your board where you stand.

Those are decisions and they need an owner. That is the job.

Do you guarantee we won't ever be hacked?

No. Nobody credible can promise that — and you should be wary of anyone who does.

What this commits to is that the decisions get made by somebody qualified, written down, and reviewed. That when something does happen, there is a plan rather than a scramble. And that when somebody asks you to prove your position, the answer is true and the evidence exists.

The goal is simple — fewer incidents, smaller impact, faster recovery, and no nasty surprises on a form.

Do you guarantee I won't ever be hacked?

No. Nobody credible can promise that — and you should be wary of anyone who does.

What we do commit to is fast action: quick detection, rapid containment, and telling you straight away and in plain English when something has happened.

The goal is simple — fewer incidents, smaller impact, faster recovery.

What happens if something goes wrong at 2am?

Honestly? On this service, not much, and you should know that before you buy rather than after.

A CISO works business hours. What this buys you is that the incident response plan exists, the numbers are in it, your people know who to ring, and somebody has thought about the decision before the night it has to be made. That is worth a great deal more than most people expect.

What it does not buy is somebody detecting the problem and containing it while you sleep. That is round-the-clock monitoring, it runs through a security operations centre rather than through a person, and it is a different product that we also sell.

If 2am is your actual worry, buy the monitoring first and the CISO second. We will tell you that on the call.

Do I still need cyber insurance?

Yes. Insurance and security do different jobs — one reduces the chance of something happening, the other pays for the consequences when it does. Neither replaces the other.

What changes is that the proposal form gets answered accurately, with evidence behind it. That matters more than the premium does: inaccurate answers on a proposal form are one of the main reasons cyber claims get refused, and that is not something anybody wants to discover on the worst day of their year.

Working with your IT

I already have someone who does my IT.

Good — keep them. This works alongside your IT provider, not instead of them. They keep the business running; we own the security decisions and give them a clear brief.

Most IT providers are relieved. Security is the part of the job they are most exposed on and least equipped for, and being quietly expected to have thought of everything is an uncomfortable place to sit. A defined brief is easier than an unspoken expectation.

It also means the person checking that security work landed properly isn't the same person who did it. That independence is worth something on its own.

Do you replace our IT provider?

No, and you should be suspicious of anyone who says they do. Somebody still has to run the network, manage the devices and fix things when they break. That is not this job.

What changes is that the security decisions stop being their problem by default. They get a written brief and someone to escalate to; you get someone independent checking the work landed.

Choosing the right package

Aren't we too small to need a CISO?

You are almost certainly too small to need a full-time one. That is the entire reason this exists.

The role is not really about size. It is about whether anyone owns the security decisions, and in most businesses this side of two hundred and fifty people, nobody does — it lands on the IT manager, the operations director or the founder, on top of a full job, and it gets the attention that leaves.

If you employ fewer than ten people we will usually tell you that your money goes further on protection than on leadership, and point you at QuantumCare Micro Business instead.

Is this the same as what's already included in Business Pro?

No, and this is the question most worth reading carefully.

Business Pro includes, as part of the £710, a named person who is accountable for your security, an information security policy pack, and a quarterly review. That is real and it is not being taken away.

QuantumCare CISO is the same person doing substantially more of it: committed days rather than access, a live risk register reviewed every month, board-level reporting, supplier and third-party review, customer questionnaires answered for you, and audit support carried all the way through rather than pointed at.

If you are already a Business Pro client you pay the difference between the two, not both. Ask and we will show you the actual figure for your business.

What happens when we outgrow this?

We tell you, and we help.

Past roughly two hundred and fifty people — or sooner if security becomes a full-time job on its own, which happens in regulated sectors — you should be employing somebody rather than renting one. At that point the honest advice is to hire, and we will say so, help you write the job description, and hand over the register, the roadmap and the policies to whoever takes it on.

Losing a client that way is a good outcome. It is what the service is for.

What does "vCISO" actually mean?

CISO stands for Chief Information Security Officer — the person in a large company who owns security at board level. The "v" is for virtual, and it means you rent a share of that person rather than employing one.

The reason the term exists is that the role is genuinely needed well below the size at which the salary makes sense. A hundred-person business has the same questionnaires, the same insurers and the same suppliers as a thousand-person one — it just has a fraction of the budget.

In plain terms: somebody senior enough to make the call, accountable for having made it, for a day or two a month.

Is QuantumCare CISO capped, like Business Pro?

Yes, and much more tightly.

Business Pro caps at twenty clients. This cannot be anywhere near that number, because it is committed days rather than shared attention.

The cap here is on the days rather than the clients: no more than ten days a month committed across every CISO client. A business of 10–20 people takes a day and a half of that; one of 151–250 takes six. So in practice it is somewhere between two and five clients at a time, depending on their size.

When those days are gone I say so on the first call rather than stretching and doing it badly.

Who you're dealing with

Who will I actually be dealing with?

James Batt. Every conversation, every quarter, every time you pick up the phone. Not an account manager, not a rota, and not a different consultant each quarter who needs your business explained to them again.

By month three you have somebody who knows your suppliers, your systems and which of your people click things. That familiarity is most of the value, and it is the thing a rotating team can never give you.

Is QuantumCare just one person?

The advice and the relationship are one person, deliberately. At this price that is what you are buying — a named, accountable individual rather than a methodology delivered by whoever was free that week.

Where QuantumCare's other packages are concerned, the protection behind them is not one person: monitoring, detection and containment run around the clock through a dedicated security operations centre. But that is the monitoring packages, and it is not part of this service.

For QuantumCare CISO, the honest answer is yes — it is one person, on purpose, and that is what makes it worth buying.

What happens if James is away or unwell?

Planned leave is a few times a year and you will know well ahead of it. The quarterly review moves; the work does not disappear.

Be straight with yourself about what this means, though: this is a leadership retainer from a named individual, so if that individual is away for a fortnight, your CISO is away for a fortnight. Anything genuinely urgent still reaches me. Routine work waits.

If you need cover that never pauses, what you need is monitoring, and that is a different product that runs through a security operations centre rather than through me.

Would you take on one of my competitors?

Not without telling you first. On Business Pro that is a formal promise; here it is simpler than a policy — a CISO who knows both sides of a competitive market is in an impossible position, and I would rather turn the work down than be in it.

If it ever came close, you would hear about it from me before you heard about it anywhere else.

Getting started

How quickly can we start?

Usually within two weeks of agreement, and the first ninety days start from the first working session rather than from the invoice.

There is nothing to install, so there is no deployment to schedule. What there is instead is a handful of conversations with the people who know how things actually work, which is the part that sets the pace.

Do you work on-site?

We work remote-first, and that is a large part of how the price stays where it is.

The quarterly review can be in person or on a call — your choice, and there is no fee for either. Being far away does not change the service: the work is remote, so a client in Inverness gets exactly what a client in Crawley gets.

Two things do change with distance, and both are said out loud rather than discovered later.

Travel and accommodation are charged at cost. Never marked up, itemised, and agreed with you before anything is booked. Locally that is usually nothing at all.

And the travel time comes out of your committed days. A day spent getting to you and back is a day not spent on your risk register, your policies or your suppliers. That is not a penalty — it is just what the days are. It means most clients further afield take three of the four reviews on a call and save the visit for the one that matters, which is generally the right call anyway.

Any other visit is charged separately: £240 for a short visit of up to two hours, £400 for a half day, £760 for a full day, on the same basis. Short visits are for sites within reach of us in West Sussex; further afield starts at a half day.

What this actually changes

Beyond the paperwork, here is what having somebody own it actually buys you.

You stop losing contracts on the security form

The questionnaire that arrives before a big deal stops being a scramble across three people who all think it belongs to somebody else. Someone owns the answer, the answers are true, and the weak ones get fixed before the form arrives rather than after it has cost you the work.

Insurance renewal stops being a guess

The form gets answered accurately, with evidence behind it. That matters more than the premium does — inaccurate answers on a proposal form are one of the main reasons cyber claims get refused, and nobody discovers that on a good day.

The board gets an answer

“How exposed are we?” stops being met with a shrug, or with a technical explanation nobody in the room follows. It gets a document, a number, a plan with costs on it, and a person who will stand behind all three.

Your IT provider gets easier to manage

They get a clear security brief instead of being quietly expected to have thought of everything. You get somebody independent checking the work landed. Both of those make the relationship better rather than worse, which surprises people.

The next step

One conversation, and you’ll know where you actually stand

You don’t have to decide anything on the call. We tell you what’s exposed, and you keep the findings either way — even if we’re not the right fit.

No obligation · No sales script · You keep the findings either way

James Batt · CISSP, C|CISO Founder, Systems Secure Ltd

Image

Innovation

Fresh, creative solutions.

Excellence

Excellence

Copyright 2026. Systems Secure. All Rights Reserved.