-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
The Practice
Pick the conversation you need to have.
One advisory practice, organized around three conversations: operating the business, building a cybersecurity product, or evaluating a transaction.
-
For operators
Strategic Oversight
Executive cybersecurity leadership without adding another full-time seat.
Board reporting, risk governance, resilience, GRC, and program leadership shaped around the decisions your executive team needs to make.
- Executive advisory and board-ready reporting
- Cyber, resilience, and risk governance
- GRC and project or program leadership
-
For builders
Product Advisory
Buyer-side judgment for cybersecurity founders and product teams.
Seven practical playbooks help teams sharpen positioning, validate product and roadmap choices, build design-partner programs, and sell credibly to enterprise buyers.
- Positioning, ICP, and buyer-map development
- Product validation and roadmap reviews
- Design-partner and enterprise-positioning programs
-
For deal teams
M&A Due Diligence
Decision-ready cyber diligence for investors and acquirers.
Evidence, exposure, and remediation requirements translated for the investment committee, with an initial risk review and a practical path through the first 100 days.
- 5-day Initial Risk Review
- Investment committee reporting and insurance guidance
- Post-close 100-day security plan
Why VCSO.ai
Why Organizations Choose vCSO.ai
Executive Insight
Led by former CSOs with Fortune 500 experience.
Flexible Engagements
Advisory, Projects, or Retainers.
Compliance-Ready Frameworks
Aligning with SOC2, NIST, and ISO.
Proven Results
Risk reduced, audits passed, value protected.
Not sure which practice fits?
Request a 30-minute intro and we’ll scope it together. No obligation — most conversations end with a clear next step, not a contract.