CISO Advisory:
From Someone Who Has Been in the Seat

Advisory from consultants who have never run a security organization looks very different from advisory rooted in real CISO experience. I have sat in the CISO chair at one of the world's most targeted organizations. I know what the pressure feels like from the inside.

Asaf's Perspective

The CISO role is one of the most isolated positions in the C-suite. You're expected to speak business to the board, speak technical to the engineers, and speak regulatory to the legal team - simultaneously, under pressure, with incomplete information. What I offer is not a methodology. It's a thinking partner who has navigated those conversations from the inside - and can help you do the same more effectively.

Two Types of Engagement

Virtual CISO (vCISO)

For companies that need executive-level security leadership but cannot justify a full-time CISO hire. I embed into your leadership team, own the security strategy, manage your security roadmap, and ensure you're audit-ready.

CEOs and founders without a dedicated CISO

CISO Advisory Retainer

For enterprise CISOs who need a strategic sparring partner. Board communication, regulatory strategy, budget prioritization, M&A security due diligence - whatever you're facing.

Enterprise CISOs facing complex decisions

What I Actually Work On

The questions I hear most from CISOs and CEOs are consistent across organization sizes and sectors:

"How do I communicate cyber risk to the board without losing them in the first five minutes?"

The answer is translating technical exposure into business impact: revenue at risk, regulatory consequence, and reputational cost. I help CISOs build that language and the reporting cadence to sustain it.

"We're growing fast. What security foundations do we need before we become a target?"

Early-stage companies get attacked too. The foundations are identity, endpoint, data classification, and incident response - in that order. Everything else is optimization.

"We have too many vendors and not enough visibility. How do we prioritize?"

Visibility before tools. Most organizations are buying products to solve problems they can't see clearly. I start with exposure mapping, then rationalize the vendor stack.

"Our compliance team says we need ISO 27001 / SOC 2 / NIS2 by next year. Where do we start?"

Gap analysis, then a sequenced roadmap. Compliance certifications are achievable on any reasonable timeline if you understand what you're actually being measured on.

What Makes This Different

I am not a framework consultant. I do not arrive with a playbook and leave you with a slide deck. I have run security organizations under real pressure - aviation security after geopolitical incidents, protecting systems that are targeted by nation-state actors, managing teams through breaches and near-misses.

What I bring to every advisory engagement is that lived experience, combined with current market intelligence from working across multiple industries at the same time. The best advice for your situation often comes from having seen the same situation play out differently elsewhere.

Frequently Asked Questions

What is a vCISO?

A virtual CISO (vCISO) is an experienced cybersecurity executive who works with your organization on a part-time or fractional basis. They provide the same strategic security leadership as a full-time CISO - roadmap, board reporting, vendor oversight, incident response planning - without the cost of a full-time hire.

Who needs a vCISO?

Companies that need executive-level security leadership but cannot justify a full-time CISO salary - typically growth-stage companies, SMEs, or organizations undergoing rapid digital transformation or facing compliance requirements for the first time.

What does CISO Advisory include?

CISO Advisory is a strategic retainer for enterprise security leaders. It covers board-level communication, budget prioritization, regulatory navigation (GDPR, NIS2, ISO 27001), M&A security due diligence, and serving as a trusted sparring partner for complex security decisions.

How is this different from a consulting firm?

Most consultants have never sat in the CISO seat. Asaf Levy served as CISO of El Al Airlines - one of the world's most targeted organizations - and brings 30+ years of real operational experience, not framework methodology.

Sources & Further Reading

Last reviewed: July 2026

Let's Talk About What You're Facing

Whether you're a CEO who needs a vCISO or a CISO who needs a strategic partner - 30 minutes is enough to understand if there's a fit.

Start a Conversation