Your security programme, owned
ChangTech provides experienced security expertise on-demand — without the cost or commitment of a full-time hire. vCISO, compliance, and engineering, delivered by practitioners who've built this before.
Why businesses choose a vCISO
Full-time CISOs are a luxury most growing businesses can't justify — or don't need at full capacity. A fractional vCISO gives you the expertise on your timeline.
Instant senior expertise
No months of recruiting. No expensive full-time hire. Get seasoned security leadership within days, not months.
Cost predictable
Fixed monthly retainer. No surprise invoices. Compare: one full-time CISO costs £180k+ per year. We start at £1,500/mo.
Scale as you grow
From startup to scale-up. Adjust scope monthly. Add coverage for new regulations, products, or markets — no re-hiring required.
Compliance covered
FCA, NCSC, DORA, NIS2, ISO 27001. We map controls to frameworks you need, not frameworks you don't.
Technical depth
We engineer, not just advise. Cloud security, DevSecOps, threat modelling — embedded delivery, not slide decks.
Board-level reporting
Executive summaries your board understands. Risk registers, materiality assessments, and informed Go/No-Go decisions.
Fractional vCISO
Senior security leadership on-demand. We embed as your virtual CISO — setting strategy, running risk assessments, and presenting to the board. You get the expertise without the full-time cost.
- Quarterly security strategy & roadmap
- Risk register & materiality assessment
- Board reporting & executive communication
- Vendor & third-party security reviews
- Incident response planning & retainer
Security Engineering
We build security into your stack, not bolt it on afterwards. Cloud security architecture, DevSecOps pipeline, threat modelling, and penetration testing coordination — delivered by engineers who've done this at scale.
- Cloud security architecture (AWS, Azure, GCP)
- DevSecOps pipeline implementation
- Threat modelling & security design review
- Penetration testing coordination
- Security tooling & automation
Compliance Programmes
Navigate complex regulatory requirements without the consultant theatre. We map your existing controls to the frameworks you actually need — FCA, NCSC, DORA, NIS2, ISO 27001 — and automate evidence collection.
- Regulatory gap analysis & remediation plan
- ISO 27001, SOC 2, Cyber Essentials certification
- FCA & DORA compliance programmes
- Automated compliance monitoring
- Audit preparation & stakeholder management
Transparent pricing
No hidden fees. No surprise invoices. All plans include our core security framework and onboarding at no extra cost.
Starter
Essential security coverage for growing businesses that need senior guidance without the full-time overhead.
- 4 hours/month dedicated vCISO
- Quarterly security review
- Risk register maintenance
- Policy & procedure documents
- Email & Slack support (48h response)
- One regulatory framework coverage
- Cyber Essentials certification support
Growth
Comprehensive security programme for scale-ups with complex compliance needs and board-level reporting requirements.
- 12 hours/month dedicated vCISO
- Monthly security reviews
- Real-time risk dashboard
- Board reporting & material risk
- Priority support (24h response)
- Unlimited regulatory frameworks
- ISO 27001 / SOC 2 support
- CAISO — Chief AI Security Officer
- Incident response retainer
All prices exclude VAT. Minimum 3-month commitment. Annual discount available.
Free compliance calculators
Instant estimates for your compliance investment. No forms, no sales pitches.
Compliance ROI
Calculate the return on investment for your compliance programme.
CalculateGDPR Fine
Estimate potential fines under UK GDPR based on turnover.
CalculateISO 27001
Estimate the cost and timeline for ISO 27001 certification.
CalculateEU AI Act
Assess your AI systems against the EU AI Act requirements.
CalculateISO 42001
Calculate investment needed for AI management system certification.
CalculateWhat clients say
Real businesses. Real security outcomes. No cherry-picked testimonials from logo lists.
"ChangTech transformed our security posture in weeks. We went from 'hope for the best' to having a proper risk register, board reporting, and confidence that we're actually prepared. Worth every penny."
"We needed ISO 27001 certification for a major enterprise contract. ChangTech had us certified in 3 months — not the 12 months our previous consultant estimated. Their process was efficient, practical, and genuinely helpful."
"As a startup with limited budget, hiring a full-time CISO was impossible. ChangTech gave us senior leadership we could actually afford. The ROI was obvious within the first month when they caught a critical vulnerability our previous 'security review' missed."
Frequently asked questions
Can't find what you're looking for? Get in touch.
A fractional vCISO is a senior security executive who works part-time for your business. Instead of a full-time hire (costing £180k+ per year), you get equivalent expertise on a monthly retainer. We typically spend 4–12 hours per month embedded with your team, covering strategy, risk, compliance, and incident response.
Most clients are fully operational within 5 business days. We start with a security baseline assessment (usually 2–4 hours), then produce a 90-day roadmap. You're not waiting months for value — you'll see output in the first week.
Our typical clients are growth-stage companies (10–200 employees) with some regulatory exposure — fintech, healthcare, professional services, or B2B SaaS. If you're regulated by the FCA, or handling significant personal data, we're a natural fit. Early-stage startups with minimal compliance needs may not need the full programme yet.
Fixed monthly retainer. No surprise invoices. Starter is £1,500/month for essential coverage. Growth is £8,000/month for comprehensive security programmes. All prices exclude VAT. We require a minimum 3-month commitment to ensure continuity.
Yes. While our regulatory expertise is strongest in UK/EU frameworks (FCA, NCSC, DORA, NIS2, ISO 27001), we've worked with companies across Europe, the Middle East, and North America. GDPR work in particular crosses borders regularly.
For Growth clients, our retainer covers: a named incident contact (always available during business hours, 24h for critical), a defined response SLA (critical incidents: 2-hour initial response), and access to our incident response playbook template and tabletop exercise. For actual breach scenarios, we coordinate with your legal team and forensics partners.
Yes. Both plans include Cyber Essentials certification support. For Starter clients, we handle the submission and basic evidence collection. For Growth clients, we manage the full process including the penetration testing requirement.
Most consultancies sell projects: a penetration test, a gap analysis, a report. We sell outcomes: ongoing security posture improvement, sustained compliance, and a senior leader who knows your business. We embed, we don't just deliver. Think of us as your security department, without the headcount overhead.
Ready to get started?
Tell us about your security needs. We'll match you with the right plan and have you operational within 5 business days.
Response time
We respond to all enquiries within 24 hours on business days.
Location
London, UK — working globally with remote-first clients.