Empire Protection
Two consultants working through a document on a laptop between them.

Service

Security Officer and CSO as a Service

An experienced security officer on retainer: accountable, not advisory.

Most organisations that need a Chief Security Officer cannot justify one full time. This is that role, delivered on retainer: someone who owns the security program rather than reviewing it once a year.

The engagement covers the security program and its roadmap, policy and governance, monthly reporting, and the board or committee papers that go with it. Where you are a DISP member, it covers the Security Officer duties that membership requires.

What separates this from advisory work is accountability. There is a named person, a standing report, and a program that moves between meetings.

Common questions

What is a CSO as a Service, or a virtual CSO?

An experienced Chief Security Officer on retainer rather than on payroll. The engagement owns the security program: its roadmap, policy, governance, monthly reporting and the board papers that go with it, for organisations that need the role but cannot justify it as a full time executive position.

How is this different from a security consultant?

Accountability. A consultant delivers a report and leaves; this is a named person who owns the program, reports on it on a standing cycle, and is answerable for whether it moved between meetings.

Can you act as our DISP Security Officer?

Yes. Where you are a DISP member, the engagement covers the Security Officer duties that membership requires, which is the most common reason organisations take this on.

What do we actually receive each month?

A standing report on the security program, the risk and control position, progress against the roadmap, and the papers your board or security committee needs. What is in it is agreed at the start, so the report answers your governance obligations rather than describing our activity.

Is there a minimum term?

This is a retainer, and security programs move on a quarterly and annual cycle rather than a weekly one, so the engagement is scoped over a period long enough to be worth having. The specific term is part of the quote.

Check this against the source

Everything on this page describes a regulated activity. These are the bodies that set the rules, so you can read them rather than take Empire’s word for it.

What the retainer actually runs

What separates this from advisory work is accountability: a named person, a standing report, and a program that moves between meetings.

  1. Program and roadmap

    Owned rather than reviewed once a year. The roadmap is the thing the standing report reports against.

  2. Policy and governance

    The policy set and the governance around it, kept current rather than written once and left to age.

  3. Monthly report

    The security program, the risk and control position, and progress against the roadmap. What is in it is agreed at the start, so it answers your governance obligations rather than describing our activity.

  4. Board papers

    The papers your board or security committee needs, on their cycle rather than assembled the week before.

  5. DISP Security Officer duties

    Where you are a DISP member, the engagement covers the Security Officer duties membership requires, the most common reason organisations take this on.

Want the risk register, controls and evidence held in a system rather than assembled the week before an audit?

Governance, Risk and Compliance Software

Empire Executive Protection Pty Ltd · ABN 30 622 627 034 · trading as Empire Protection