Strategic Oversight

Executive cybersecurity judgment, without adding the full-time seat.

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

  • 15 years as CSO at Silicon Valley Bank (2007–2021), the bank of the innovation economy

  • $200B+ in assets defended at enterprise scale

  • Design partner to Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium

  • Author of Cyber War and Peace; board member, Bay Area CSO Council

  • Trusted advisor to PE/VC firms, cyber product companies, and enterprise boards

What Strategic Oversight Can Own

This is the executive layer above the individual workstreams: the judgment, governance, and program leadership that keeps cybersecurity connected to the decisions the business is making.

Executive and board advisory

Security strategy, decision support, board reporting, material-event communication, and an experienced operator in the room when the stakes rise.

Risk, GRC, and compliance

Governance structure, risk decisions, policy and control programs, audit readiness, and compliance work connected to the business rather than managed as isolated checklists.

Program and project leadership

Roadmaps, workstreams, owners, dependencies, vendors, and executive follow-through for security initiatives that cross technology, risk, legal, and operations.

Incident readiness and resilience

Incident response, tabletop exercises, business continuity, disaster recovery, and leadership support during critical moments.

Engagement model: Retained or time-bound executive leadership, scoped around the mandate, operating cadence, and decisions that need an experienced owner.

Theodolite decision overview showing control implementation, financial risk context, top priorities, and environment evidence

Evidence When It Helps

Theodolite supports the work. Operator judgment leads it.

When an engagement needs a fresh technical baseline, Theodolite can organize verified environment evidence, control implementation, findings, and priorities into one decision view.

It is not a substitute for governance, GRC, program leadership, or board communication. Those remain advisory work led by experienced operators, and not every Strategic Oversight engagement depends on the platform.

See the current Theodolite product →

How It Works

  1. Define the mandate and current state

    Agree on the decisions that need an experienced security owner, review the evidence already available, and establish the priorities leadership needs addressed first.

  2. Run the governance and program cadence

    Lead the roadmap, board reporting, risk and compliance work, resilience planning, vendor decisions, and cross-functional program management with clear owners and follow-through.

  3. Scale, transition, or respond

    Adjust the engagement as the company grows, prepares for a transaction, navigates an incident or regulatory event, or becomes ready for a full-time security leader.

Who This Is For

Built for organizations that need senior cybersecurity leadership tied to real business decisions, not another disconnected assessment or tool.

  • CEOs, CROs, CIOs, and CTOs

    Leaders who need experienced cybersecurity judgment and a clear owner for the program without adding a full-time executive immediately.

  • Boards and Audit Committees

    Directors who need decision-ready reporting, clear accountability, and an honest view of what management is doing next.

  • Growth-Stage and Regulated Companies

    Organizations facing enterprise customers, audits, regulators, or rapid change before the internal leadership model has caught up.

  • PE and VC Portfolio Companies

    Portfolio leaders working through inherited security debt, post-close priorities, pre-exit readiness, or a security leadership gap.

Leadership You Can Trust

Most advisors diagnose. Operators prescribe.

vCSO.ai is led by Nick Shevelyov, former CSO and CIO of Silicon Valley Bank, author of Cyber War and Peace, a NASDAQ public-company board director, and a member of the Bay Area CSO Council.

Nick Shevelyov

Achievements

  • Defended Silicon Valley Bank’s cyber posture for 15 years (2007-2021), through every major crisis from the 2008 financial collapse to SolarWinds.
  • Design partner and advisor to category-defining cybersecurity companies including Palo Alto Networks, Zscaler, CrowdStrike, FireEye, and Eclypsium.
  • Forbes Technology Council member, NASDAQ board director (AuthID), author of Cyber War…and Peace.
  • Founder of the CISO Supper Club, convening Bay Area cybersecurity executives twice a year.
Contact our team

Who You’ll Work With

Nick leads the executive relationship. The supporting team brings program management, GRC, technical assessment, and product capabilities when the mandate requires them.

Mike Korsak

Mike Korsak

Senior Program Management Advisor

Berk Algan

Berk Algan

Governance, Risk & Compliance

Andrej Bosanac

Andrej Bosanac

Technical Assessments & Pen Testing

Nicholas Carlson

Nicholas Carlson

Product & Assessment Platform

Trusted by security leaders

What CISOs, founders, and risk leaders say about working with Nick.

“Nick has been an invaluable partner in elevating Audubon's cybersecurity strategy. His ability to provide clear, level-headed advice has been instrumental during tough moments, and his executive-level communication skills have been particularly effective for the org to plan for right-sized investments in cybersecurity.”
Marco Carbone
CTO, National Audubon Society
“Nick and team have been amazing partners to Pixee. Their knowledge, relationships, and industry experience have been a core part of our go-to-market strategy and refinement.”
Surag Patel
CEO, Pixee
“Nick and team provide a unique value blending cultural enablement and a risk-focused cyber risk management strategy. Their approach helped our team rapidly improve the effectiveness of our cyber risk program with quantifiable results.”
Alexander Trafton
SVP Technology Risk and Compliance, G42

FAQ

Questions leaders ask about the engagement.

What is Strategic Oversight?

Strategic Oversight is a retained executive cybersecurity advisory relationship. It gives leadership access to an experienced security operator who can set direction, report to the board, govern risk and compliance, coordinate delivery, and stay with the work as conditions change.

Is this a virtual CISO or fractional CISO service?

It can fill that role. Virtual CISO and fractional CISO are common market terms for part-time executive security leadership. We use Strategic Oversight because the scope may include board advisory, interim leadership, governance, program management, and specialist coordination as well as the traditional vCISO responsibilities. See what a fractional CISO does.

Do you provide GRC and project or program management?

Yes. Governance, risk, compliance, business continuity, and cybersecurity program management sit inside Strategic Oversight. The work is connected to the executive mandate and roadmap rather than sold as disconnected documentation or staff augmentation.

Does every engagement begin with a 30-day assessment?

No. Some companies need a focused cyber risk assessment first; others already have credible evidence and need leadership, governance, or a specific program taken forward. The starting scope is set around the decision and operating need.

Do you work with our existing team or replace them?

We work with the existing security, IT, engineering, legal, risk, and operations teams. Strategic Oversight provides executive direction and coordination; it does not replace the people already responsible for day-to-day execution.

What if we need capabilities beyond advisory?

When the roadmap calls for penetration testing, audit support, forensics, managed detection, or another specialist capability, we help select and coordinate the right partner while keeping the work connected to the broader program.

Can you help us transition to a full-time CISO?

Yes. Strategic Oversight can stabilize the program, clarify the role the company actually needs, and support a clean handoff when the organization is ready to hire permanent leadership.

What needs an experienced owner right now?

Tell us the decision, program, or leadership gap you are working through. We will tell you whether Strategic Oversight fits, whether a focused assessment should come first, or whether a different specialist is the better next step.

Contact us We’ll be in touch →