Strategic advisory · self-serve toolkit

vCISO Starter Kit

A governance pack for businesses too small or too early for a full vCISO retainer. Templates you can actually operate — risk, policy, incident response, vendors, board reporting, and a POPIA-lite safeguards checklist. Not a finished compliance programme, and not a substitute for a qualified professional.

Basic

R950 once-off, no VAT
  • Cyber risk register + scoring guide
  • ISO 27001-aligned policy pack (8 policies)
  • Incident response runbook and tabletop
  • Vendor risk questionnaire and register
  • Board / exco reporting template
  • POPIA s19 safeguards checklist

Plus

R3,500 once-off, no VAT
  • Everything in Standard
  • One 30-minute clarifying call
  • Priority route to a vCISO / vCIO retainer if you outgrow the templates

What is in the pack

Risk register

Scored register, worked SME examples (Microsoft 365, edge firewall, accounting system), and a treatment log you can take to exco.

Policy pack

Eight adopt-and-edit policies mapped to ISO 27001:2022 themes. Written for a business that already has an MSP or internal IT, not a greenfield ISMS project.

Incident response

Severity matrix, contain-and-recover steps, POPIA s22 decision path, contacts sheet, and a tabletop (ransomware, mailbox compromise, lost laptop).

Vendors, board, POPIA

Third-party questionnaire, quarterly exco one-pager, and a safeguards checklist tied to POPIA s19 — not a binder nobody operates.

Sold by Impact Elements (Pty) Ltd, reg 2017/531020/07. Payments processed by PayFast; we never see or store card details. We are not a registered VAT vendor — no VAT is charged. Licence is for internal use by the purchasing organisation. Templates are a starting point, not legal advice, and do not constitute ISO 27001 certification.