מאמרים / CISO AS A SERVICE

כמה עולה CISO as a Service?

התשובה הישירה, הגורמים שקובעים את המחיר, מודלי ההתקשרות הנפוצים — ואיך לדעת שאתם משלמים על מה שהעסק באמת צריך.

ARTICLES / CISO AS A SERVICE

How much does CISO as a Service cost?

The direct answer, the factors that set the price, the common engagement models, and how to make sure you pay for what your business actually needs.

אין מחיר אחיד ל-CISO as a Service. העלות נקבעת לפי ארבעה גורמים: גודל הארגון, רמת הסיכון, הרגולציה שחלה עליו והיקף הליווי הנדרש. לכן ב-Art of Cyber אנחנו לא מפרסמים מחירון אחיד: אחרי שיחת מיפוי קצרה אנחנו מגדירים היקף מדויק ונותנים הצעה שמשקפת את הצורך האמיתי של העסק — לא פחות ולא יותר. אפשר להתחיל בפרויקט ממוקד או בליווי שוטף, ולשנות את ההיקף כשהצורך משתנה.

ארבעה גורמים שקובעים את המחיר

  1. גודל ומורכבות הארגון. מספר עובדים, מערכות, סניפים וספקים. חברה של 30 עובדים עם מערכת ענן אחת היא לא חברת פינטק עם מאות עובדים ותשתית מורכבת.
  2. רגולציה ודרישות לקוחות. ISO 27001, SOC 2, תיקון 13 לחוק הגנת הפרטיות, GDPR ושאלוני אבטחה של לקוחות גדולים מעמיקים את העבודה: מדיניות, בקרות, ראיות וביקורות.
  3. רמת הבשלות הנוכחית. ארגון שמתחיל מאפס צריך לבנות תשתית ניהול שלמה. ארגון עם תוכנית קיימת צריך בעיקר הובלה, כיוון ומעקב.
  4. היקף האחריות. יש הבדל מהותי בין בדיקה נקודתית (סקר, ייעוץ) לבין הנהגה מתמשכת: תוכנית עבודה, דיווח להנהלה, ניהול סיכונים וספקים ומעקב אחרי ביצוע.

שלושה מודלים נפוצים של התקשרות

מודלמתי זה מתאיםאיך משלמים
פרויקט ממוקדסקר פערים, הכנה להסמכת ISO 27001, מיפוי פרטיות, מוכנות לאירועמחיר קבוע לפרויקט עם תוצר מוגדר
ליווי שוטףהנהגת אבטחה מתמשכת בלי לגייס CISO במשרה מלאהתשלום חודשי עבור היקף ימי עבודה מוגדר
שילובלבנות יסוד ואז לשמור על הרמה לאורך זמןפרויקט פתיחה ואחריו ליווי חודשי מצומצם

מה מקבלים ב-CISO as a Service של Art of Cyber

  • תוכנית אבטחה עם סדרי עדיפויות, בעלים ולוחות זמנים
  • דיווח שוטף להנהלה ולדירקטוריון, בשפה עסקית
  • ניהול סיכונים ובחינת ספקים
  • ליווי תקינה: ISO 27001, SOC 2, תיקון 13 ו-GDPR
  • מוכנות לאירועי סייבר ותרגילי התאוששות
  • אבטחת AI: אסטרטגיה, ממשל ובדיקות למערכות AI

אלו חלק מהשירותים המלאים של Art of Cyber — ייעוץ אסטרטגי, ליווי תקינה ואבטחת AI, לצד שירותי פרטיות ו-DPO.

כמה עולה לא להוביל אבטחה

מאז כניסתו של תיקון 13 לתוקף, הרשות להגנת הפרטיות יכולה להטיל עיצומים כספיים משמעותיים: 150,000 ₪ על הפרות רישום מאגרים והודעה לרשות, ועל עיבוד שלא כדין — סכומים לפי נושא מידע עם מינימום של 200,000 ₪. מעבר לקנסות, לקוחות ארגוניים דורשים תשובות אבטחה מסודרות בשאלוני ספקים, ועסקאות נתקעות כשאין למי לענות. הובלה מקצועית עולה פחות מהאירוע הראשון.

מקור: מדריך משרד המשפטים לתיקון 13 לחוק הגנת הפרטיות, פרק העיצומים הכספיים.

איך להשוות בין הצעות מחיר

  • בקשו היקף כתוב. מה בדיוק כלול, ומה לא. מחיר בלי היקף הוא לא מחיר.
  • מי עובד איתכם בפועל. איש צוות בכיר עם ניסיון הנהגתי, או יועץ זוטר.
  • תוצרים מדידים. תוכנית עבודה, דיווחים, מדדים — לא רק זמינות בטלפון.
  • גמישות. אפשרות להתחיל קטן ולהגדיל את ההיקף כשהצורך גדל.

השורה התחתונה

המחיר הנכון של CISO as a Service הוא המחיר של ההיקף שהעסק שלכם באמת צריך — ואת זה אפשר לדעת רק אחרי מיפוי קצר. שיחה של חצי שעה מספיקה כדי להגדיר היקף ולתת מספר. דברו איתנו ונחזור אליכם עם הצעה מדויקת.

There is no single price for CISO as a Service. The cost is set by four factors: company size, risk level, applicable regulation, and the scope of engagement required. That is why Art of Cyber does not publish one fixed price list: after a short scoping call we define an exact scope and quote a price that reflects the real need, no more and no less. You can start with a focused project or ongoing support, and change the scope as the need changes.

Four factors that set the price

  1. Company size and complexity. Headcount, systems, sites, and vendors. A 30-person company with one cloud system is not a fintech with hundreds of employees and complex infrastructure.
  2. Regulation and customer requirements. ISO 27001, SOC 2, Israel's Privacy Protection Law Amendment 13, GDPR, and security questionnaires from enterprise customers deepen the work: policies, controls, evidence, audits.
  3. Current maturity. A company starting from zero needs a full management foundation built. A company with an existing program mainly needs leadership, direction, and follow-through.
  4. Scope of responsibility. There is a fundamental difference between a point assessment (survey, advice) and ongoing leadership: a work plan, management reporting, risk and vendor oversight, and execution follow-up.

Three common engagement models

ModelWhen it fitsHow you pay
Focused projectGap assessment, ISO 27001 readiness, privacy mapping, incident preparednessFixed price for a defined deliverable
Ongoing retainerContinuous security leadership without hiring a full-time CISOMonthly fee for a defined number of work days
CombinedBuild the foundation, then maintain the level over timeAn opening project followed by a lighter monthly retainer

What Art of Cyber's CISO as a Service includes

  • A security program with priorities, owners, and timelines
  • Regular reporting to management and the board, in business language
  • Risk management and vendor review
  • Compliance support: ISO 27001, SOC 2, Amendment 13, and GDPR
  • Cyber incident readiness and recovery exercises
  • AI security: strategy, governance, and testing of AI systems

These are part of Art of Cyber's full services - strategic consulting, compliance support, and AI security, alongside privacy and DPO services.

The cost of not leading security

Since Amendment 13 took effect, Israel's Privacy Protection Authority can impose significant financial sanctions: 150,000 ILS for database registration and notification violations, and per-data-subject amounts with a 200,000 ILS minimum for unlawful processing. Beyond fines, enterprise customers demand structured security answers in vendor questionnaires, and deals stall when there is no one to answer them. Professional leadership costs less than the first incident.

Source: Israel Ministry of Justice guide to Amendment 13 of the Privacy Protection Law, financial sanctions chapter.

How to compare proposals

  • Ask for a written scope. What exactly is included, and what is not. A price without a scope is not a price.
  • Who actually works with you. A senior with leadership experience, or a junior consultant.
  • Measurable deliverables. A work plan, reports, metrics, not only phone availability.
  • Flexibility. The option to start small and grow the scope as the need grows.

The bottom line

The right price for CISO as a Service is the price of the scope your business actually needs, and that can only be known after a short mapping. A 30-minute call is enough to define a scope and give you a number. Talk to us and we will come back with a precise proposal.

רוצים מספר מדויק?

Want an exact number?

נדבר על זה ←Let's discuss it →