מאת בוריס פוסטילניק, מייסד Art of Cyberפורסם 19 בספטמבר 2026זמן קריאה: 5 דקות אין מחיר אחיד ל-CISO as a Service. העלות נקבעת לפי ארבעה גורמים: גודל הארגון, רמת הסיכון, הרגולציה שחלה עליו והיקף הליווי הנדרש. לכן ב-Art of Cyber אנחנו לא מפרסמים מחירון אחיד: אחרי שיחת מיפוי קצרה אנחנו מגדירים היקף מדויק ונותנים הצעה שמשקפת את הצורך האמיתי של העסק — לא פחות ולא יותר. אפשר להתחיל בפרויקט ממוקד או בליווי שוטף, ולשנות את ההיקף כשהצורך משתנה.
ארבעה גורמים שקובעים את המחיר
- גודל ומורכבות הארגון. מספר עובדים, מערכות, סניפים וספקים. חברה של 30 עובדים עם מערכת ענן אחת היא לא חברת פינטק עם מאות עובדים ותשתית מורכבת.
- רגולציה ודרישות לקוחות. ISO 27001, SOC 2, תיקון 13 לחוק הגנת הפרטיות, GDPR ושאלוני אבטחה של לקוחות גדולים מעמיקים את העבודה: מדיניות, בקרות, ראיות וביקורות.
- רמת הבשלות הנוכחית. ארגון שמתחיל מאפס צריך לבנות תשתית ניהול שלמה. ארגון עם תוכנית קיימת צריך בעיקר הובלה, כיוון ומעקב.
- היקף האחריות. יש הבדל מהותי בין בדיקה נקודתית (סקר, ייעוץ) לבין הנהגה מתמשכת: תוכנית עבודה, דיווח להנהלה, ניהול סיכונים וספקים ומעקב אחרי ביצוע.
שלושה מודלים נפוצים של התקשרות
| מודל | מתי זה מתאים | איך משלמים |
|---|
| פרויקט ממוקד | סקר פערים, הכנה להסמכת ISO 27001, מיפוי פרטיות, מוכנות לאירוע | מחיר קבוע לפרויקט עם תוצר מוגדר |
| ליווי שוטף | הנהגת אבטחה מתמשכת בלי לגייס CISO במשרה מלאה | תשלום חודשי עבור היקף ימי עבודה מוגדר |
| שילוב | לבנות יסוד ואז לשמור על הרמה לאורך זמן | פרויקט פתיחה ואחריו ליווי חודשי מצומצם |
מה מקבלים ב-CISO as a Service של Art of Cyber
- תוכנית אבטחה עם סדרי עדיפויות, בעלים ולוחות זמנים
- דיווח שוטף להנהלה ולדירקטוריון, בשפה עסקית
- ניהול סיכונים ובחינת ספקים
- ליווי תקינה: ISO 27001, SOC 2, תיקון 13 ו-GDPR
- מוכנות לאירועי סייבר ותרגילי התאוששות
- אבטחת AI: אסטרטגיה, ממשל ובדיקות למערכות AI
אלו חלק מהשירותים המלאים של Art of Cyber — ייעוץ אסטרטגי, ליווי תקינה ואבטחת AI, לצד שירותי פרטיות ו-DPO.
כמה עולה לא להוביל אבטחה
מאז כניסתו של תיקון 13 לתוקף, הרשות להגנת הפרטיות יכולה להטיל עיצומים כספיים משמעותיים: 150,000 ₪ על הפרות רישום מאגרים והודעה לרשות, ועל עיבוד שלא כדין — סכומים לפי נושא מידע עם מינימום של 200,000 ₪. מעבר לקנסות, לקוחות ארגוניים דורשים תשובות אבטחה מסודרות בשאלוני ספקים, ועסקאות נתקעות כשאין למי לענות. הובלה מקצועית עולה פחות מהאירוע הראשון.
מקור: מדריך משרד המשפטים לתיקון 13 לחוק הגנת הפרטיות, פרק העיצומים הכספיים.
איך להשוות בין הצעות מחיר
- בקשו היקף כתוב. מה בדיוק כלול, ומה לא. מחיר בלי היקף הוא לא מחיר.
- מי עובד איתכם בפועל. איש צוות בכיר עם ניסיון הנהגתי, או יועץ זוטר.
- תוצרים מדידים. תוכנית עבודה, דיווחים, מדדים — לא רק זמינות בטלפון.
- גמישות. אפשרות להתחיל קטן ולהגדיל את ההיקף כשהצורך גדל.
השורה התחתונה
המחיר הנכון של CISO as a Service הוא המחיר של ההיקף שהעסק שלכם באמת צריך — ואת זה אפשר לדעת רק אחרי מיפוי קצר. שיחה של חצי שעה מספיקה כדי להגדיר היקף ולתת מספר. דברו איתנו ונחזור אליכם עם הצעה מדויקת.
By Boris Pustilnik, founder of Art of CyberPublished September 19, 20265 min read There is no single price for CISO as a Service. The cost is set by four factors: company size, risk level, applicable regulation, and the scope of engagement required. That is why Art of Cyber does not publish one fixed price list: after a short scoping call we define an exact scope and quote a price that reflects the real need, no more and no less. You can start with a focused project or ongoing support, and change the scope as the need changes.
Four factors that set the price
- Company size and complexity. Headcount, systems, sites, and vendors. A 30-person company with one cloud system is not a fintech with hundreds of employees and complex infrastructure.
- Regulation and customer requirements. ISO 27001, SOC 2, Israel's Privacy Protection Law Amendment 13, GDPR, and security questionnaires from enterprise customers deepen the work: policies, controls, evidence, audits.
- Current maturity. A company starting from zero needs a full management foundation built. A company with an existing program mainly needs leadership, direction, and follow-through.
- Scope of responsibility. There is a fundamental difference between a point assessment (survey, advice) and ongoing leadership: a work plan, management reporting, risk and vendor oversight, and execution follow-up.
Three common engagement models
| Model | When it fits | How you pay |
|---|
| Focused project | Gap assessment, ISO 27001 readiness, privacy mapping, incident preparedness | Fixed price for a defined deliverable |
| Ongoing retainer | Continuous security leadership without hiring a full-time CISO | Monthly fee for a defined number of work days |
| Combined | Build the foundation, then maintain the level over time | An opening project followed by a lighter monthly retainer |
What Art of Cyber's CISO as a Service includes
- A security program with priorities, owners, and timelines
- Regular reporting to management and the board, in business language
- Risk management and vendor review
- Compliance support: ISO 27001, SOC 2, Amendment 13, and GDPR
- Cyber incident readiness and recovery exercises
- AI security: strategy, governance, and testing of AI systems
These are part of Art of Cyber's full services - strategic consulting, compliance support, and AI security, alongside privacy and DPO services.
The cost of not leading security
Since Amendment 13 took effect, Israel's Privacy Protection Authority can impose significant financial sanctions: 150,000 ILS for database registration and notification violations, and per-data-subject amounts with a 200,000 ILS minimum for unlawful processing. Beyond fines, enterprise customers demand structured security answers in vendor questionnaires, and deals stall when there is no one to answer them. Professional leadership costs less than the first incident.
Source: Israel Ministry of Justice guide to Amendment 13 of the Privacy Protection Law, financial sanctions chapter.
How to compare proposals
- Ask for a written scope. What exactly is included, and what is not. A price without a scope is not a price.
- Who actually works with you. A senior with leadership experience, or a junior consultant.
- Measurable deliverables. A work plan, reports, metrics, not only phone availability.
- Flexibility. The option to start small and grow the scope as the need grows.
The bottom line
The right price for CISO as a Service is the price of the scope your business actually needs, and that can only be known after a short mapping. A 30-minute call is enough to define a scope and give you a number. Talk to us and we will come back with a precise proposal.