vCISOOne (stylized as vCISO.One) has launched a tiered Virtual CISO service (vCISO) for Operational Technology (OT) environments.

The services are specifically tailored to OT environments, including SCADA, ICS, and telemetry systems, focused on councils, utilities, and infrastructure operators managing cyber risk and resilience.

The Australian cybersecurity consultancy claims the vCISO offering means firms can do away with the need for a full-time CISO, with the service aligned with frameworks like IEC 62443, ACSC OT Principles, and the ISM.

The offering can potentially assist organizations without the need for in-house expertise to manage secure network architectures, engineering-focused policies, and readiness for audits, grants, and SoCI reporting.

vCISO reports it has already supported firms across Australia and the US, in one case helping a regional utility uncover remote access paths that “hadn’t been reviewed in years”, according to Andrew Egoroff, founder of vCISOOne. “In another, we standardized OT visibility across multiple departments.”

Egoroff continued: “Traditional IT approaches don’t work in the OT world. Patching, scanning, and cloud-first strategies often break things.

"This service was created to give engineers and operators practical, risk-based cyber leadership that respects uptime, safety, and legacy constraints.”

Virtual CISO programs focus on incident response preparation, and operating as an incident manager in the event of a ransomware attack.

SDxCentral previously reported concerns that vCISOs run the risk of being “only partially invested” in an organization's security program.

But for many small-sized enterprises with limited resources, finding and retaining a qualified CISO can be particularly challenging - running the greater risk of having no investment in security overall.