Senior security leadership — on demand

Your security programme, owned

ChangTech provides experienced security expertise on-demand — without the cost or commitment of a full-time hire. vCISO, compliance, and engineering, delivered by practitioners who've built this before.

Trusted by businesses regulated by:
NCSC Cyber Essentials ISO 27001 FCA

Why businesses choose a vCISO

Full-time CISOs are a luxury most growing businesses can't justify — or don't need at full capacity. A fractional vCISO gives you the expertise on your timeline.

Instant senior expertise

No months of recruiting. No expensive full-time hire. Get seasoned security leadership within days, not months.

Cost predictable

Fixed monthly retainer. No surprise invoices. Compare: one full-time CISO costs £180k+ per year. We start at £1,500/mo.

Scale as you grow

From startup to scale-up. Adjust scope monthly. Add coverage for new regulations, products, or markets — no re-hiring required.

Compliance covered

FCA, NCSC, DORA, NIS2, ISO 27001. We map controls to frameworks you need, not frameworks you don't.

Technical depth

We engineer, not just advise. Cloud security, DevSecOps, threat modelling — embedded delivery, not slide decks.

Board-level reporting

Executive summaries your board understands. Risk registers, materiality assessments, and informed Go/No-Go decisions.

Strategic Leadership

Fractional vCISO

Senior security leadership on-demand. We embed as your virtual CISO — setting strategy, running risk assessments, and presenting to the board. You get the expertise without the full-time cost.

  • Quarterly security strategy & roadmap
  • Risk register & materiality assessment
  • Board reporting & executive communication
  • Vendor & third-party security reviews
  • Incident response planning & retainer
Technical Delivery

Security Engineering

We build security into your stack, not bolt it on afterwards. Cloud security architecture, DevSecOps pipeline, threat modelling, and penetration testing coordination — delivered by engineers who've done this at scale.

  • Cloud security architecture (AWS, Azure, GCP)
  • DevSecOps pipeline implementation
  • Threat modelling & security design review
  • Penetration testing coordination
  • Security tooling & automation
Compliance Automation

Compliance Programmes

Navigate complex regulatory requirements without the consultant theatre. We map your existing controls to the frameworks you actually need — FCA, NCSC, DORA, NIS2, ISO 27001 — and automate evidence collection.

  • Regulatory gap analysis & remediation plan
  • ISO 27001, SOC 2, Cyber Essentials certification
  • FCA & DORA compliance programmes
  • Automated compliance monitoring
  • Audit preparation & stakeholder management
Operator playbook

Judgments, anonymised

Each entry is a call we made on a real engagement — what we chose, what we rejected, and why. Clients are not named; the reasoning is.

  1. Q3 2026

    Chose NIS2 over DORA for a Series A fintech

    Their payments stack is UK-domiciled only — DORA's ICT third-party concentration requirements would have produced artefacts the regulator couldn't act on. NIS2 gave them a framework their actual supervisor can enforce.

    Not DORA

  2. Q2 2026

    Refused a SOC 2 Type II scope that included the marketing site

    The prospect's customer data never touched it. Adding the marketing site to the audit would have doubled their evidence-collection cost for a control that protects nothing the customer cares about.

    Not Trust Service Criteria + marketing site

  3. Q1 2026

    Recommended a £400/month MDR over a £40k/year SIEM

    They had two engineers and no SOC. A SIEM they can't staff is a SIEM that produces alerts nobody reads. MDR buys outcomes; SIEM buys dashboards.

    Not Self-hosted SIEM + on-call rotation

  4. Q4 2025

    Drew the CISO reporting line through Finance, not Engineering

    Their material risk was contractual — regulators and enterprise procurement asked for attestation documents the finance team already owned. Putting the CISO there meant attestation was a one-step process, not a translation exercise.

Transparent pricing

No hidden fees. No surprise invoices. All plans include our core security framework and onboarding at no extra cost.

Starter

£1,500 /month

Essential security coverage for growing businesses that need senior guidance without the full-time overhead.

  • 4 hours/month dedicated vCISO
  • Quarterly security review
  • Risk register maintenance
  • Policy & procedure documents
  • Email & Slack support (48h response)
  • One regulatory framework coverage
  • Cyber Essentials certification support
Get Started

All prices exclude VAT. Minimum 3-month commitment. Annual discount available.

What clients say

Real businesses. Real security outcomes. No cherry-picked testimonials from logo lists.

"ChangTech transformed our security posture in weeks. We went from 'hope for the best' to having a proper risk register, board reporting, and confidence that we're actually prepared. Worth every penny."

SC
Sarah Chen CEO, FintechScale Ltd

"As a startup with limited budget, hiring a full-time CISO was impossible. ChangTech gave us senior leadership we could actually afford. The ROI was obvious within the first month when they caught a critical vulnerability our previous 'security review' missed."

PS
Priya Sharma Founder, CloudNest

Frequently asked questions

Can't find what you're looking for? Get in touch.

Ready to get started?

Tell us about your security needs. We'll match you with the right plan and have you operational within 5 business days.

Response time

We respond to all enquiries within 24 hours on business days.

Location

London, UK — working globally with remote-first clients.

Trust signals

NCSC Assured Cyber Essentials ISO 27001

Send us a message