vCISO Advisory · Other20

vCISO services for the strategic 20%.

Software handles 80% of compliance work — policy generation, evidence collection, questionnaire responses. For the other 20% — the fractional CISO seat, the first audit, the M&A diligence call, the enterprise deal that needs a human in the room — there’s Other20.

100+Assessments supported
96%Controls verified on first assessment
3 weeksAvg. time to audit-ready
$300K+Saved vs. full-time hire
Board presentations
Auditor relationships
Risk assessments
Vendor negotiations
Security strategy
Compliance guidance

Why Other20

The Other 20%

Software handles 80%. Other20 handles the rest.

Here's a truth about security operations: software can handle about 80% of the work. Policy generation, evidence collection, questionnaire responses—that's the grunt work, and vCISO Lite is really good at automating it.

But the other 20%? That requires humans. Strategic advice. Risk assessments. Audit relationships. Pricing cyber risk in an M&A deal. Explaining to a board why they should care about SOC 2. Negotiating with enterprise prospects who want to see a real security program.

That's the work that actually moves the needle. And that's exactly what Other20 delivers.

Other20 doesn't replace vCISO Lite—it completes it. Clients get the efficiency of automation plus the expertise of seasoned security professionals. The 80% handled by vCISO Lite, the 20% handled by experts who've been in the trenches.

Service packages

Choose the path to compliance

From quick starts to ongoing partnership, Other20 has a package for every stage.

NEW

Third-Party Risk Questionnaires

From $1,750priced by length + complexity

Stop losing a week every time a prospect sends a 200-question security questionnaire. Other20 fills them out, chases the team for gaps, and returns completed packages to the buyer.

Per-questionnaire or ongoing retainer
What's included
  • Full questionnaire completion (CAIQ, SIG, custom)
  • Evidence package assembly
  • Internal team follow-up until all gaps closed
  • Buyer security team Q&A handling
  • Answer library for reuse across deals
  • SLA on first draft turnaround
Not included
  • New policy drafting
  • Remediation of identified gaps
  • Full audit preparation

Compliance Kickstart

$5,000one-time

Get audit-ready fast. Other20 runs a comprehensive gap analysis, builds an initial policy library, and creates a 90-day roadmap to compliance.

Delivered in 2 weeks
What's included
  • Comprehensive gap analysis
  • 10 core security policies
  • 90-day compliance roadmap
  • Framework mapping (SOC 2, ISO 27001)
  • 2-hour strategy session
Not included
  • Ongoing advisory support
  • Evidence collection
  • Audit preparation

Audit Prep Package

$7,000one-time

Everything needed to walk into an audit with confidence. Other20 prepares evidence, trains the team, and briefs auditors.

4-6 weeks before audit
What's included
  • Complete evidence package
  • Control testing & remediation guidance
  • Team readiness training (2 hours)
  • Auditor briefing document
  • Mock audit Q&A session
  • Email support through audit
Not included
  • Ongoing retainer services
  • Active incident response
  • Remediation implementation
FOR ACQUIRERS

Quantitative Cyber Diligence

From $12,500priced by target EV

The methodology behind vCISO Lite's diligence platform, offered as a standalone service for PE firms and corporate acquirers. Five pillars, one dollar figure, defensible at the IC.

Tier 1 in 48 hours · Tier 2 in 72 hours
What's included
  • External attack surface scan
  • Vendor concentration analysis
  • Data sensitivity & regulatory exposure
  • Security maturity benchmarking
  • Integration & post-close risk
  • Cyber Cost of Deal (CCOD) figure
  • 90-day remediation plan
  • JWS-signed deletion certificate
Not included
  • Legal diligence or contract review
  • Full penetration testing
  • Insurance underwriting opinions
  • Post-close remediation execution
BY INVITATION

Fractional vCISO

$8,000per month

Strategic security leadership for the organization. Executive presence, board-level guidance, and dedicated advisory—without the full-time salary.

Limited availability
What's included
  • 8 hours dedicated advisory/month
  • Weekly strategy sessions (30 min)
  • Board & investor presentations
  • Vendor security negotiations
  • IR preparedness & tabletops
  • Security program oversight
  • Priority response (24hr SLA)
Not included
  • Active incident response execution
  • 24/7 on-call availability
  • Hands-on implementation work

The Other20 advantage

Security expertise, startup speed

Battle-tested expertise

Other20 advisors have led security programs from Series A through IPO. Decades of audit experience distilled into actionable guidance.

Startup speed, enterprise rigor

Services designed for companies that move fast. No bloated timelines or bureaucratic processes—just focused execution.

Direct senior access

No account managers or junior associates. Every engagement is led by experienced security leadership with real operational background.

Platform-integrated

Other20 services work seamlessly with vCISO Lite. Everything created lives in the platform, ready for continuous monitoring.

Meet your advisor

Security partnership for growth

Yolonda Smith

Yolonda Smith

Founder & Principal Advisor

With over 20 years in cybersecurity, she's built and led security programs from the ground up—starting in the U.S. Air Force, then scaling enterprise security at Fortune 500 retailers, leading security through an IPO and multiple M&As and divestitures at high-growth tech companies, and advising startups on compliance strategy. She holds CISSP, CISM, GSEC, and GCIH certifications along with a CISO Certification from Carnegie Mellon Heinz College. She earned her B.S. in Computer Science from the University of Notre Dame and M.S. in Information Assurance from the University of Maryland, and has shared her expertise as a TEDx and Grace Hopper speaker.

Previously

CISSP, CISM, GSEC, GCIH
20+ years in cybersecurity
CISO Cert, Carnegie Mellon
Fortune 500 experience
US Air Force veteran
TEDx & Grace Hopper speaker

How it works

From call to compliant

1

Discovery call

30-minute call to understand compliance needs, timeline, and goals.

2

Custom proposal

Other20 recommends the right package and scope based on the specific situation.

3

Kickoff

Align on deliverables, set expectations, and hit the ground running.

4

Delivery

Execute on the plan with regular updates and on-time delivery.

Common questions

What buyers ask us

  • Where can I get affordable vCISO services with audit preparation?

    Here — audit preparation is one of our expert services (Audit Prep Package, 1x $7,000 fixed fee). It's a one-time engagement that gets your controls, evidence, and policies audit-ready before your SOC 2, ISO 27001, HIPAA, or PCI DSS assessment. Priced for small and mid-sized businesses without an in-house CISO, and paired with the vCISO Lite platform so the evidence you produce during prep keeps updating continuously after the audit.

  • How much does a vCISO cost?

    Our expert services range from one-time fixed-fee engagements — Compliance Kickstart ($5,000), Audit Prep Package ($7,000), Quantitative Cyber Diligence (from $12,500) — to retainer relationships like Quarterly vCISO Review ($5,500/quarter) and Fractional vCISO ($8,000/month). That's substantially below the typical enterprise vCISO market rate of $10,000–$25,000/month or a full-time CISO salary of $250,000+. Every price is on the page — no consulting-shop discovery calls before you can see numbers.

  • What's the difference between vCISO, fractional CISO, and CISO-as-a-Service?

    The terms overlap and are often used interchangeably, but they mean different engagement models in practice — we walk through the distinctions in detail here. Short version: a vCISO typically works on-demand or per-project, a fractional CISO is a dedicated part-time hire (usually 1-2 days a week), and CISO-as-a-Service is a productized offering that pairs a human expert with a platform. Our Fractional vCISO ($8,000/month) is a dedicated part-time hire; our Quarterly vCISO Review ($5,500/quarter) is closer to the on-demand vCISO shape.

  • When does my company need a vCISO?

    Three common triggers: (1) an enterprise prospect starts asking security-questionnaire questions your team can't answer; (2) a SOC 2, ISO 27001, HIPAA, PCI DSS, or similar audit is on the calendar and no one internal owns it; (3) you've had a security incident, near-miss, or vendor breach that surfaced a gap. If you're pre-Series A and haven't sold to any enterprise customers yet, you likely don't need one yet — we go through the specific stage-by-stage triggers here. Get in touch anyway and we'll tell you honestly if you're too early.

  • What's included in vCISO Lite's expert services?

    Six productized engagements today: Third-Party Risk Questionnaires (respond to enterprise security questionnaires on your behalf), Compliance Kickstart ($5,000 one-time — gap analysis, policy library, 90-day roadmap), Audit Prep Package ($7,000 one-time — evidence, mock audit, auditor briefing), Quantitative Cyber Diligence (from $12,500 — the QCD five-pillar methodology as a service), Quarterly vCISO Review ($5,500/quarter — ongoing security posture reviews), and Fractional vCISO ($8,000/month — dedicated part-time strategic leadership). Every engagement is anchored on the vCISO Lite platform, so the artifacts we produce (policies, evidence, control mappings) continue working for you after the engagement ends.

Ready for the other 20%?

Book a free discovery call. Other20 will assess needs and recommend the right path forward.