Saltar al contenido
01 · Consultoría01 · Consulting

Oficina de Seguridad Virtual (vCISO)Virtual Security Office (vCISO)

CISO externalizado para organizaciones sin un director dedicado.Outsourced CISO for organisations without a dedicated security director.

Reuniones periódicas + informesRegular meetings and reporting 1.1 · Consultoría Estratégica de Seguridad1.1 · Strategic Security Consulting

¿Qué es este servicio?What is this service?

Es un CISO externo: la dirección de seguridad ejercida por un tercero con dedicación parcial, en vez de contratar a alguien de planta. Funciona con reuniones periódicas, disponibilidad para consultas e informes de estado a la dirección.

An external CISO: security leadership provided part-time by a third party instead of hiring a full-time executive. It runs on regular meetings, availability for consultation and status reporting to management.

¿Para qué se usa?What is it used for?

Sirve para las organizaciones que necesitan criterio de seguridad al nivel de dirección pero no tienen volumen para justificar una plaza. El vCISO define la estrategia, prioriza el presupuesto, gobierna a los proveedores de seguridad, representa el tema ante la junta y acompaña cuando hay un incidente.

It suits organisations that need executive-level security judgement but lack the volume to justify a full-time role. The vCISO sets strategy, prioritises budget, governs security vendors, represents the topic to the board and provides cover during an incident.

Qué beneficios traeBenefits it delivers

  • Cuesta una fracción de un CISO de planta, un perfil caro y difícil de retener.
  • Aporta experiencia de varias organizaciones y sectores, que un CISO interno no acumula.
  • Arranca en semanas y no en los meses que toma reclutar el perfil.
  • Permite escalar la dedicación: más horas durante una certificación o un incidente, menos en operación normal.
  • Da independencia para plantear lo incómodo, porque el rol no depende internamente de aquellos a quienes debe decir que no.
  • Costs a fraction of a full-time CISO, an expensive profile that is hard to retain.
  • Brings experience from several organisations and sectors that an internal CISO never accumulates.
  • Starts in weeks rather than the months it takes to recruit the role.
  • Allows scaling the commitment: more hours during a certification or an incident, fewer in normal operation.
  • Provides the independence to raise uncomfortable issues, since the role does not report internally to the people it must sometimes refuse.

¿En qué momentos es obligatorio?When is it mandatory?

Costa RicaCosta Rica

  • Ninguna norma costarricense obliga a tener un CISO con ese título.
  • El Acuerdo CONASSIF 5-24 sí exige funciones de ciberseguridad identificadas y revelables, que ahora se reportan en el perfil tecnológico: alguien tiene que ejercerlas y estar nombrado.
  • Los clientes corporativos y los cuestionarios de proveedores suelen pedir un responsable de seguridad identificable con nombre y apellido.
  • No Costa Rican rule requires a CISO by that title.
  • CONASSIF Agreement 5-24 does require identified and disclosable cybersecurity functions, now reported in the technology profile: somebody has to perform them and be formally appointed.
  • Corporate clients and supplier questionnaires usually ask for a named, identifiable security lead.

InternacionalInternational

  • ISO 27001 exige asignar responsabilidades de seguridad, aunque no impone un título concreto.
  • DORA y NIS2 exigen una función de gestión de riesgos de TIC claramente asignada dentro de la entidad.
  • PCI-DSS asigna responsabilidades formales de programa de seguridad a un rol ejecutivo.
  • ISO 27001 requires security responsibilities to be assigned, though it does not mandate a specific title.
  • DORA and NIS2 require a clearly assigned ICT risk management function within the entity.
  • PCI-DSS assigns formal security programme responsibility to an executive role.

Requisitos mínimosMinimum requirements

  • Un punto de contacto interno con capacidad de ejecutar lo que se decida; el vCISO dirige, no opera.
  • Acceso real a la dirección: si el vCISO no llega a quien decide el presupuesto, el servicio se diluye.
  • Definir la dedicación mensual y qué queda dentro y fuera del alcance.
  • Visibilidad de los contratos con proveedores de tecnología y seguridad.
  • An internal counterpart able to execute what gets decided; the vCISO directs, it does not operate.
  • Real access to senior management: if the vCISO cannot reach whoever controls the budget, the service dilutes.
  • A defined monthly commitment and clarity on what is in and out of scope.
  • Visibility of contracts with technology and security vendors.

Plazo típico de entregaTypical delivery time

Servicio continuo Ongoing service rango habitual del mercado usual market range

No es un proyecto sino un servicio continuo, normalmente contratado por doce meses con una dedicación mensual acordada. Lo que sí tiene plazo es el arranque: entre cuatro y seis semanas para entender el entorno, levantar el estado de la seguridad y presentar las primeras prioridades a la dirección.

This is not a project but an ongoing service, usually contracted for twelve months with an agreed monthly commitment. What does have a deadline is the ramp-up: four to six weeks to understand the environment, assess the security posture and present the first priorities to management.

NomenclaturaTerminology

Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.

vCISOvCISO
Virtual CISO: la función de dirección de seguridad prestada por un externo con dedicación parcial. Virtual CISO: the security leadership function provided by an external party on a part-time basis.
DedicaciónAllocation
Las horas mensuales comprometidas. Es la variable que define el costo y el alcance realista del servicio. The committed monthly hours. This is the variable that sets the cost and the realistic scope of the service.
Gobierno de proveedoresVendor governance
Supervisar que quienes prestan servicios de seguridad cumplan lo contratado y reporten lo que deben. Overseeing that security service providers deliver what was contracted and report what they should.