Focused Entry Engagement
Establish the baseline before you commit to the roadmap.
-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
-
15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy
-
$200B+ in assets defended at enterprise scale
-
Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium
-
Author of Cyber War and Peace; board member, Bay Area CSO Council
-
Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards
What the Assessment Is Built to Produce
The goal is not another inventory of problems. It is a defensible view of what is known, what remains uncertain, what matters most, and what leadership should do next.
Defined decision and scope
The assessment begins with the leadership decision it must support, the systems and obligations in scope, the available evidence, and the limitations that must be stated.
Technical and governance review
Architecture, controls, policies, compliance requirements, resilience, dependencies, and material scenarios reviewed at the depth the evidence allows.
Prioritized roadmap
Findings sequenced into practical work with owners, dependencies, and the next decisions leadership needs to make.
Executive-ready summary
A concise view of exposure, evidence confidence, priorities, accountability, and the questions that remain open.
Engagement model: A time-bound project with scope and timing confirmed after reviewing source access, evidence quality, stakeholders, and the decision deadline.
Current Product Support
Use Theodolite where it fits. State the gaps where it does not.
Theodolite can organize verified environment evidence, control implementation, findings, and priorities when the current source coverage fits the engagement.
The assessment does not depend on pretending every source is automated. Documents, interviews, specialist testing, and explicit evidence limitations remain part of responsible assessment work.
Review current source coverage →How It Works
-
Define scope and the decision
Identify the systems, data, obligations, business services, and leadership decision the assessment must support, then confirm which evidence can actually be reviewed.
-
Review technical and governance evidence
Assess the available technical posture, policies, controls, compliance requirements, dependencies, and material scenarios. State evidence gaps and assumptions explicitly.
-
Prioritize and brief leadership
Deliver the findings, an executive summary, and a sequenced roadmap with owners and next decisions so the organization knows what to do first.
Who This Is For
Built for organizations that need an independent baseline and a decision-ready sequence of work before committing to a broader program.
-
Leadership Teams Establishing a Baseline
New executives, boards, or security leaders who need an independent view before funding or reorganizing the program.
-
Growth-Stage Companies
Organizations facing enterprise customers, audits, or investor scrutiny with fragmented findings but no shared sequence of work.
-
PE and VC Portfolio Companies
Portfolio leaders who need to understand inherited security debt, post-close priorities, or pre-exit readiness.
-
Regulated and High-Consequence Operators
Organizations that need technical, resilience, policy, and compliance evidence translated into executive decisions.
Leadership You Can Trust
Most advisors diagnose. Operators prescribe.
vCSO.ai is led by Nick Shevelyov, former CSO and CIO of Silicon Valley Bank and author of Cyber War and Peace. The assessment method is designed to connect technical depth with the governance altitude executives and boards need.
Achievements
- Defended Silicon Valley Bank’s cyber posture for 15 years (2007-2021), through every major crisis from the 2008 financial collapse to SolarWinds.
- Design partner and advisor to category-defining cybersecurity companies including Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium.
- Forbes Technology Council member, NASDAQ board director (AuthID), author of Cyber War…and Peace.
- Founder of the CISO Supper Club, convening Bay Area cybersecurity executives twice a year.
Who You’ll Work With
The team combines executive judgment, program management, GRC, technical assessment, and product support according to the agreed scope.
Mike Korsak
Senior Program Management Advisor
Berk Algan
Governance, Risk & Compliance
Andrej Bosanac
Technical Assessments & Pen Testing
Nicholas Carlson
Product & Assessment Platform
Trusted by security leaders
What CISOs, founders, and risk leaders say about working with Nick.
“Nick has been an invaluable partner in elevating Audubon's cybersecurity strategy. His ability to provide clear, level-headed advice has been instrumental during tough moments, and his executive-level communication skills have been particularly effective for the org to plan for right-sized investments in cybersecurity.”
CTO, National Audubon Society
“Nick and team have been amazing partners to Pixee. Their knowledge, relationships, and industry experience have been a core part of our go-to-market strategy and refinement.”
Surag PatelCEO, Pixee
“Nick and team provide a unique value blending cultural enablement and a risk-focused cyber risk management strategy. Their approach helped our team rapidly improve the effectiveness of our cyber risk program with quantifiable results.”
Alexander TraftonSVP Technology Risk and Compliance, G42
FAQ
Questions about the assessment.
How long does a cyber risk assessment take?
Timing depends on scope, source access, and the decision the work must support. We confirm a time-bound plan after reviewing the environment, evidence available, and required stakeholders rather than advertising the same timeline for every organization.
What is included in the assessment?
The typical output is a technical and governance assessment, an executive summary, and a prioritized roadmap. Exact coverage may include architecture, controls, policies, compliance obligations, resilience, third parties, and material scenarios based on the agreed scope.
Is this the same as a vulnerability scan, penetration test, or audit?
No. Those activities can provide evidence, but they answer narrower questions. A cyber risk assessment connects the available evidence to critical services, business consequences, ownership, priorities, and treatment decisions.
Will Theodolite be used?
Theodolite may support the assessment when the environment and current source coverage fit. It is not required for every engagement, and unsupported sources are handled through documents, interviews, specialist testing, or a clearly stated evidence limitation.
Can the findings be presented to our board?
Yes. The assessment includes an executive-level summary focused on the exposure, evidence confidence, priorities, accountability, and decisions appropriate for leadership or board oversight.
What happens after the assessment?
The organization can execute the roadmap internally, engage specific specialists, or continue into Strategic Oversight for program direction, GRC, project management, incident readiness, and board reporting.
What decision should the assessment support?
Tell us what changed, what evidence already exists, and what leadership needs to decide. We will define a responsible scope, the sources required, and the limitations that should be visible from the start.