
Virtual CISO & advisory services.
Security leadership on demand, from a practicing CISO.
What the seat actually covers.
You do not have to know cybersecurity to buy it well. You have to know what a real security leader would own, then check that every line is owned. That is what this list is. Seven domains, each one open for inspection: what we run, what you hold at the end, and what it looks like in practice. If something you are carrying is not on this list, bring it to the call and we will tell you honestly whether it belongs here.
Bring the domain that worries you to the callA security strategy sized to your company, not a framework poster. Where you stand today, what actually threatens the business, what gets fixed first and why. Priorities are set against revenue, customers, and the deals in your pipeline, so security spend follows business risk instead of vendor noise.
A concrete risk roadmap your leadership can read without a translator.
Set inside the first 90 days, then kept honest as the company changes.
The operating system of the program. Policies people actually follow, a risk register with named owners, decision rights, and exceptions handled on the record. Security stops being one heroic engineer and becomes a system the company runs.
A governance baseline that auditors and enterprise customers can walk through.
Built from what you already have. Nothing gets rewritten for the sake of rewriting.
Compliance readiness for SOC 2, ISO 27001, and HIPAA. Gap assessment, control mapping, evidence discipline, and auditor management, sequenced against the deadline that actually matters, which is usually the enterprise deal waiting on your report.
A readiness picture per framework: what passes today, what will not, and the shortest path between the two.
The deal-blocking security questionnaire stops being a fire drill.
Board and investor reporting from someone who briefs boards as part of the job. Posture, risk, spend, and progress translated into the language a board votes on.
A reporting rhythm and the deck that carries it. Not a slide tour of the firewall.
Your next board meeting is the deadline. We have sat on the presenting side of that table.
Tabletop exercises and incident response leadership. The plan, the roles, the call order, and the rehearsal, so that when something breaks the seat runs the response instead of watching it. Penetration testing, incident and breach response, and 24x7 managed SOC through vetted partners, with one accountable seat in front of all of it.
An incident plan your team has actually run once, not a template with your logo on it.
Readiness first, so response is execution instead of improvisation.
The vendor layer: what you buy, what your vendors can touch, and what happens at renewal. This is the domain where the firm has an unfair advantage. We sit on the buyer's side of security deals every week, and that leverage comes with the seat.
A vendor picture your customers' security teams will recognize, and negotiating position you did not have last renewal.
When a tool needs to be bought, consolidated, or killed, the same firm runs that too.
The hiring plan for the security function: what to hire, in what order, and what can stay fractional. Mentoring for the security leaders you already have. And when a seat needs filling, candidates come from the network that already knows who is good.
A team plan, and a bench behind it: vetted security engineers, analysts, and fractional specialists, every one vetted by a practicing CISO before you see them.
Your first security hire stops being a guess.
The first 90 days, already mapped.
You should know what happens after the paperwork before you sign it. The first quarter runs in three moves. Each one ends with an artifact you hold, not a meeting you attended.
Access, listening, and a straight read. We inventory what exists: systems, policies, vendors, gaps, and the risks nobody has written down. No rip-and-replace in month one. You cannot prioritize what you have not seen.
Candid. You get the honest picture, including the uncomfortable parts.
The baseline, in writing. Where you actually stand, said plainly.
The posture becomes a story your leadership can carry: to the board, to investors, to the enterprise customer whose questionnaire is sitting in your inbox. Reporting starts here, not at the end.
Board and investor aware. Everything is written knowing it will be presented upward.
An updated security story for boards and buyers, and the reporting rhythm that keeps it current.
The roadmap lands. What gets fixed first, what it costs, who does it, and what can wait. Sequenced against your deals and deadlines, not against a framework's table of contents.
Concrete. Owners and order, not themes.
The risk roadmap. The quarter after this one is already scoped before this one ends.
Embedded in your rhythm, not just on steering calls.
Advisory means a document and a monthly meeting. This is the other thing: a working seat inside your company. Every engagement runs through a senior operator who has held the seat. No juniors learning on your dime. The market has three names for this, CISO as a Service, fractional CISO, vCISO, and they all buy the same thing here: the seat, sized to what your company actually needs.
Answers between meetings, not scheduled around them. When the security questionnaire lands on a Tuesday, you do not wait for Friday's call.
Work you can hold: roadmaps, reports, registers, plans. If it was decided, it exists in writing.
The honest read, every time. Comfort is not the deliverable.
Security decisions made with the people they affect, so the program helps deals close instead of blocking them.
Everything is built knowing it will be presented upward. No translation layer needed later.
Your people learn the seat is there and start using it. That is when it is working.
The seat is real.
Anand Thangaraju
Alchemy Cyber is led by Anand Thangaraju, a practicing Field CISO with years across enterprise security, financial services, and the vendor side, including Ernst & Young and Silicon Valley Bank. The person advising your company holds the seat today, somewhere real.
Meet the operatorWhen fractional is right, and when it is not.
The seat is not for everyone, and pretending otherwise would be a strange way to open a trust relationship. Here is the straight version, both sides.
Ask which side you are on, in 30 minutesYou need CISO judgment now and cannot justify the full-time hire yet.
Compliance has a deadline attached to a real deal.
A board member or investor started asking security questions you do not want to improvise.
Customer security reviews are slowing your sales cycle.
You are building your first security function and want the plan before the headcount.
The work is real, but it is not yet a full-time week.
If most of that list sounds familiar, the seat fits. Bring the sharpest item to the call.
Security is your product, not a supporting function.
Your regulators expect a named, dedicated owner in the building.
The program is large enough to need a daily operator and an internal team behind it.
Then hire the seat outright, and do it well. When the answer is full-time, this practice does not vanish: the search runs through Implementation & Managed Services, and the network that already knows who is good runs the hire.
Staff the full-time seatThe same seat sees both sides.
We hold the CISO seat and we run the GTM motion. When we harden your security program, we know what auditors and attackers actually probe. When we take your product to market, we know what security buyers actually sign. That vantage is the firm. Nothing we recommend is theoretical. The same negotiation leverage we use on our own renewals goes into every procurement engagement.
Three practices that sit on your side of the table.
Virtual CISO and advisory, the page you are on. Security procurement and resale: we buy security for a living. Implementation & managed services: security designed, run and staffed from the network that already knows who is good.
One engine for the vendors who sell to CISOs.
The GTM Engine takes security vendors to market through the buyer network itself. If you sell security, that is your page.
Start with the 30-minute call.
Bring the problem. Leave with a path. A 30-minute call, a straight read on where you stand, and a one-page proposal. No decks about our decks.
30 minutes with a practicing CISO. Prepare nothing. Bring the problem as it actually is.
One page. What we would run, in what order, and what the first 90 days produce.
Retainer from $5k/month, quarterly terms.