Focused Entry Engagement

Establish the baseline before you commit to the roadmap.

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

What the Assessment Is Built to Produce

The goal is not another inventory of problems. It is a defensible view of what is known, what remains uncertain, what matters most, and what leadership should do next.

Defined decision and scope

The assessment begins with the leadership decision it must support, the systems and obligations in scope, the available evidence, and the limitations that must be stated.

Technical and governance review

Architecture, controls, policies, compliance requirements, resilience, dependencies, and material scenarios reviewed at the depth the evidence allows.

Prioritized roadmap

Findings sequenced into practical work with owners, dependencies, and the next decisions leadership needs to make.

Executive-ready summary

A concise view of exposure, evidence confidence, priorities, accountability, and the questions that remain open.

Engagement model: A time-bound project with scope and timing confirmed after reviewing source access, evidence quality, stakeholders, and the decision deadline.

Theodolite decision overview showing control implementation, financial risk context, top priorities, and environment evidence

Current Product Support

Use Theodolite where it fits. State the gaps where it does not.

Theodolite can organize verified environment evidence, control implementation, findings, and priorities when the current source coverage fits the engagement.

The assessment does not depend on pretending every source is automated. Documents, interviews, specialist testing, and explicit evidence limitations remain part of responsible assessment work.

Review current source coverage →

How It Works

  1. Define scope and the decision

    Identify the systems, data, obligations, business services, and leadership decision the assessment must support, then confirm which evidence can actually be reviewed.

  2. Review technical and governance evidence

    Assess the available technical posture, policies, controls, compliance requirements, dependencies, and material scenarios. State evidence gaps and assumptions explicitly.

  3. Prioritize and brief leadership

    Deliver the findings, an executive summary, and a sequenced roadmap with owners and next decisions so the organization knows what to do first.

Who This Is For

Built for organizations that need an independent baseline and a decision-ready sequence of work before committing to a broader program.

  • Leadership Teams Establishing a Baseline

    New executives, boards, or security leaders who need an independent view before funding or reorganizing the program.

  • Growth-Stage Companies

    Organizations facing enterprise customers, audits, or investor scrutiny with fragmented findings but no shared sequence of work.

  • PE and VC Portfolio Companies

    Portfolio leaders who need to understand inherited security debt, post-close priorities, or pre-exit readiness.

  • Regulated and High-Consequence Operators

    Organizations that need technical, resilience, policy, and compliance evidence translated into executive decisions.

Leadership You Can Trust

Most advisors diagnose. Operators prescribe.

vCSO.ai is led by Nick Shevelyov, former CSO and CIO of Silicon Valley Bank and author of Cyber War and Peace. The assessment method is designed to connect technical depth with the governance altitude executives and boards need.

Nick Shevelyov

Achievements

  • Defended Silicon Valley Bank’s cyber posture for 15 years (2007-2021), through every major crisis from the 2008 financial collapse to SolarWinds.
  • Design partner and advisor to category-defining cybersecurity companies including Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium.
  • Forbes Technology Council member, NASDAQ board director (AuthID), author of Cyber War…and Peace.
  • Founder of the CISO Supper Club, convening Bay Area cybersecurity executives twice a year.
Contact our team

Who You’ll Work With

The team combines executive judgment, program management, GRC, technical assessment, and product support according to the agreed scope.

Mike Korsak

Mike Korsak

Senior Program Management Advisor

Berk Algan

Berk Algan

Governance, Risk & Compliance

Andrej Bosanac

Andrej Bosanac

Technical Assessments & Pen Testing

Nicholas Carlson

Nicholas Carlson

Product & Assessment Platform

Trusted by security leaders

What CISOs, founders, and risk leaders say about working with Nick.

“Nick has been an invaluable partner in elevating Audubon's cybersecurity strategy. His ability to provide clear, level-headed advice has been instrumental during tough moments, and his executive-level communication skills have been particularly effective for the org to plan for right-sized investments in cybersecurity.”
Marco Carbone
CTO, National Audubon Society
“Nick and team have been amazing partners to Pixee. Their knowledge, relationships, and industry experience have been a core part of our go-to-market strategy and refinement.”
Surag Patel
CEO, Pixee
“Nick and team provide a unique value blending cultural enablement and a risk-focused cyber risk management strategy. Their approach helped our team rapidly improve the effectiveness of our cyber risk program with quantifiable results.”
Alexander Trafton
SVP Technology Risk and Compliance, G42

FAQ

Questions about the assessment.

How long does a cyber risk assessment take?

Timing depends on scope, source access, and the decision the work must support. We confirm a time-bound plan after reviewing the environment, evidence available, and required stakeholders rather than advertising the same timeline for every organization.

What is included in the assessment?

The typical output is a technical and governance assessment, an executive summary, and a prioritized roadmap. Exact coverage may include architecture, controls, policies, compliance obligations, resilience, third parties, and material scenarios based on the agreed scope.

Is this the same as a vulnerability scan, penetration test, or audit?

No. Those activities can provide evidence, but they answer narrower questions. A cyber risk assessment connects the available evidence to critical services, business consequences, ownership, priorities, and treatment decisions.

Will Theodolite be used?

Theodolite may support the assessment when the environment and current source coverage fit. It is not required for every engagement, and unsupported sources are handled through documents, interviews, specialist testing, or a clearly stated evidence limitation.

Can the findings be presented to our board?

Yes. The assessment includes an executive-level summary focused on the exposure, evidence confidence, priorities, accountability, and decisions appropriate for leadership or board oversight.

What happens after the assessment?

The organization can execute the roadmap internally, engage specific specialists, or continue into Strategic Oversight for program direction, GRC, project management, incident readiness, and board reporting.

What decision should the assessment support?

Tell us what changed, what evidence already exists, and what leadership needs to decide. We will define a responsible scope, the sources required, and the limitations that should be visible from the start.