לא כל חברה צריכה CISO במשרה מלאה. כל חברה שמחזיקה מידע רגיש, מוכרת לארגונים גדולים או נדרשת לעמוד ברגולציה צריכה שמישהו בכיר יוביל את אבטחת המידע שלה.
CISO as a Service של Art of Cyber נותן לעסק הנהגת אבטחת מידע בהיקף שמתאים לו: מיפוי הסיכון, תוכנית עבודה, טיפול בדרישות לקוחות ורגולציה, דיווח להנהלה ומעקב עד לביצוע. לא מסמך שנשאר במגירה ולא רשימת המלצות בלי בעלים.
מתי עסק קטן או בינוני צריך CISO חיצוני?
בדרך כלל הצורך עולה באחד המצבים האלה:
- לקוח גדול שולח שאלון אבטחה או דורש ISO/IEC 27001 או SOC 2
- החברה מחזיקה מידע אישי, רפואי, פיננסי או עסקי רגיש
- אין בארגון בעל תפקיד שמחבר בין הנהלה, IT, פיתוח, משפטי וספקים
- אירוע, ביקורת או עסקה חשפו שאין תוכנית מסודרת
- הארגון גדל, אבל ניהול האבטחה נשאר נקודתי וטכני
- משתמשים במערכות AI ורוצים לשלוט בדליפת מידע, ספקים ו-Prompt Injection
אם הארגון צריך החלטות, סדרי עדיפויות ואחריות מתמשכת - הוא צריך הנהגת אבטחה. מספר העובדים לבדו לא קובע.
מה השירות כולל?
ההיקף נקבע לפי הסיכון והצורך, ויכול לכלול:
- מיפוי מצב קיים וסקר פערים
- תוכנית אבטחה עם סדרי עדיפויות, בעלים ולוחות זמנים
- ניהול סיכונים ומעקב אחר תוכנית הטיפול
- מדיניות, נהלים ובקרות שמתאימים לפעילות בפועל
- מענה לשאלוני אבטחה ודרישות של לקוחות ושותפים
- ליווי ISO/IEC 27001, SOC 2, תיקון 13 ו-GDPR
- הערכת ספקים ושירותי ענן
- מוכנות לאירועים, תרגילים ותוכנית התאוששות
- דיווח להנהלה ולדירקטוריון בשפה עסקית
- אסטרטגיה, ממשל ובדיקות אבטחה למערכות AI
איך מתחילים?
1. מיפוי קצר
מבינים את הפעילות, המידע, הלקוחות, הספקים והדרישות שכבר קיימות.
2. תמונת מצב וסדרי עדיפויות
מבדילים בין מה שחייב טיפול עכשיו, מה שחשוב בהמשך ומה שלא מצדיק השקעה כרגע.
3. תוכנית עבודה
מגדירים תוצרים, בעלי אחריות ולוחות זמנים. כל משימה צריכה בעלים ותוצאה שאפשר לבדוק.
4. הנהגה ומעקב
עובדים עם ההנהלה והצוותים עד לסגירת הפערים, ומעדכנים את התוכנית כשהעסק משתנה.
כמה עולה CISO as a Service?
אין מחיר אחיד. המחיר נקבע לפי גודל ומורכבות הארגון, רמת הסיכון, הרגולציה והיקף האחריות.
יש שלושה מודלים נפוצים:
- פרויקט ממוקד: למשל סקר פערים, מוכנות ללקוח גדול או הכנה לתקן. מחיר קבוע לתוצר מוגדר.
- ליווי שוטף: מספר מוגדר של ימי עבודה בחודש, בהתאם להיקף האחריות.
- שילוב: פרויקט פתיחה לבניית היסוד, ואחריו ליווי חודשי מצומצם.
אחרי שיחת מיפוי של כחצי שעה אפשר להגדיר היקף ולתת הצעה מדויקת. מחיר בלי היקף כתוב הוא לא באמת מחיר. הסבר מפורט על המודלים והגורמים שקובעים את המחיר נמצא במאמר כמה עולה CISO as a Service?.
למה Art of Cyber?
העבודה מתבצעת בהובלה ישירה של בוריס פוסטילניק, CISO ויועץ אבטחת מידע בכיר. המטרה היא לא לייצר עוד ניירת, אלא לחבר בין הסיכון, דרישות הלקוחות והעבודה שהצוות באמת מסוגל לבצע.
Art of Cyber מלווה חברות קטנות ובינוניות בישראל בתחומי CISO as a Service, פרטיות, ISO/IEC 27001, SOC 2, ניהול סיכונים ואבטחת AI.
השורה התחתונה
אם לקוחות שואלים מי אחראי על אבטחת המידע, אם דרישה רגולטורית מתקרבת, או אם ההנהלה לא מקבלת תמונת מצב ברורה - צריך בעל תפקיד בכיר שייקח אחריות על התוכנית.
השאירו פרטים לשיחת מיפוי. נבדוק מה באמת נדרש, מה אפשר לדחות ואיזה היקף מתאים לעסק.
שאלות נפוצות
האם עסק קטן באמת צריך CISO?
כן, כאשר הוא מחזיק מידע רגיש, עובד עם לקוחות גדולים, כפוף לרגולציה או תלוי במערכות קריטיות. אפשר לקבל הנהגה מקצועית בהיקף חלקי במקום לגייס משרה מלאה.
מה ההבדל בין CISO as a Service ליועץ אבטחת מידע?
יועץ יכול לבצע בדיקה או לתת המלצה נקודתית. CISO as a Service מוביל תוכנית מתמשכת: סדרי עדיפויות, בעלי אחריות, דיווח להנהלה ומעקב אחרי ביצוע.
האם השירות כולל עבודה מול לקוחות ומבקרים?
כן, אם זה חלק מההיקף: שאלוני אבטחה, דרישות חוזיות, ראיות, הכנה לביקורת ותיאום עם גורמים פנימיים וחיצוניים.
אפשר להתחיל בפרויקט ולא בליווי חודשי?
כן. אפשר להתחיל בסקר פערים או בפרויקט מוכנות, ואז להחליט אם נדרש ליווי שוטף.
Not every company needs a full-time CISO. Every company that holds sensitive data, sells to enterprise customers, or faces regulatory requirements needs senior security leadership.
CISO as a Service from Art of Cyber gives the business security leadership at a scope that fits it: risk mapping, a work plan, handling customer and compliance requirements, management reporting, and follow-through. Not a document in a drawer, and not a list of recommendations with no owner.
When does a small or mid-sized company need an external CISO?
The need usually shows up in one of these situations:
- A large customer sends a security questionnaire or requires ISO/IEC 27001 or SOC 2
- The company holds personal, medical, financial or sensitive business data
- No one in the organization connects leadership, IT, development, legal and vendors
- An incident, audit or deal exposed that there is no structured program
- The organization grew, but security management stayed ad hoc and technical
- AI systems are in use and you need control over data leakage, vendors and prompt injection
If the organization needs decisions, priorities and ongoing accountability, it needs security leadership. Headcount alone does not decide that.
What does the service include?
Scope is set by risk and need, and can include:
- Current-state mapping and a gap assessment
- A security program with priorities, owners and timelines
- Risk management and remediation tracking
- Policies, procedures and controls that fit actual operations
- Answers to security questionnaires and customer requirements
- ISO/IEC 27001, SOC 2, Amendment 13 and GDPR support
- Vendor and cloud-service assessments
- Incident readiness, exercises and a recovery plan
- Management and board reporting in business language
- Strategy, governance and security testing for AI systems
How does it start?
1. Short mapping
We understand the activity, the data, the customers, the vendors and the requirements that already exist.
2. Status and priorities
We separate what must be handled now, what matters later, and what does not justify spend right now.
3. Work plan
Deliverables, owners and timelines. Every task needs an owner and a checkable result.
4. Leadership and tracking
We work with management and teams until gaps close, and update the plan as the business changes.
How much does CISO as a Service cost?
There is no single price. Cost is set by the size and complexity of the organization, the risk level, the regulation and the scope of responsibility.
The three common models:
- Focused project: for example a gap assessment, readiness for a major customer, or certification preparation. A fixed price for a defined deliverable.
- Ongoing retainer: a defined number of work days per month, matching the scope of responsibility.
- Combined: an opening project to build the foundation, then a lighter monthly retainer.
After a short scoping call we can define the scope and give a precise proposal. A price without a written scope is not really a price. A detailed guide to the models and pricing factors is in the article How much does CISO as a Service cost?.
Why Art of Cyber?
The work is led directly by Boris Pustilnik, a senior CISO and information-security consultant with more than 12 years of experience. The goal is not more paperwork. It is connecting risk, customer requirements and the work your team can actually carry out.
Art of Cyber supports small and mid-sized companies in Israel across CISO as a Service, privacy, ISO/IEC 27001, SOC 2, risk management and AI security.
Bottom line
If customers are asking who owns security, if a regulatory requirement is approaching, or if management is not getting a clear status picture, you need a senior owner for the program.
Book a scoping call and we will come back with a precise proposal.