Antares
All insights
Case studySecurity Leadership & vCISOJune 5, 2026·7 min read

vCISO Engagement — Specialty Services Company

How vCISO advisory support rebuilt security decision-making across a complex specialty services company following CISO departure and organizational restructuring.

Client Profile

A specialty commercial services company with a complex organizational structure and a distributed third-party delivery model was managing acquisition integration across multiple business units, a workforce reduction that included IT security staff, and fragmented security ownership across a broad vendor network.

An Antares principal led the vCISO advisory engagement, working alongside the client's internal audit and finance functions to rebuild security governance following the departure of the internal CISO.

Governance Challenge

The company's internal CISO had departed. Security responsibility was divided among internal IT, a security function, and multiple third parties, none with a clear mandate over the others. The fragmentation created accountability gaps that were not visible from any single team's vantage point.

The core challenge was the decision structure behind security. Multiple leadership teams were making conflicting decisions on core security issues. There was no consistent governance structure for cross-functional security decisions. Leadership held a prevailing belief that the organization was not a material target. Fundamental controls, including MFA, faced active resistance without a clear owner responsible for driving adoption. The third-party delivery network, spanning 32 vendors, carried security exposure without a formal risk management program.

Baseline Assessment

The engagement opened with a structured assessment of how security decisions were actually being made across technology assets, staff capability, policies, and organizational culture.

The organization had little existing policy infrastructure to build from, which allowed the engagement to establish a clean governance foundation rather than remediate a legacy framework. Before recommending a path forward, existing policies and procedures were evaluated against actual security posture and operational pressure, not just audit readiness. An incident response tabletop exercise was led with the security committee and technical teams once that committee was in place.

The tabletop surfaced significant gaps between documented response procedures and the organization's actual capacity to execute them. The gaps existed not because the procedures were wrong, but because ownership and coordination had never been tested under realistic conditions.

Key Findings and Risk Classification

The findings were organized around the decision and execution risks they exposed:

  • Decision authority: Conflicting decision-making among multiple leadership teams on core security issues.
  • Governance: No consistent structure for cross-functional security decisions.
  • Control adoption: Active resistance to fundamental controls, including MFA, without a clear owner responsible for driving adoption.
  • Third-party risk: Security exposure across a 32-vendor delivery network without a formal risk management program.
  • Response readiness: A gap between documented response procedures and the organization's actual capacity to execute them.

The breakdown was happening at the formation layer, before execution could begin.

Governance Roadmap

The advisory work focused on clarifying how security decisions would be made, owned, and held across the organization rather than adding controls in isolation. The work moved through three connected layers, delivered within an initial 90-day engagement.

Decision Formation

The engagement assessed how decisions were actually being formed across technology assets, staff capability, policies, and organizational culture. This established where conflicting authority, unclear ownership, and the absence of a consistent cross-functional governance structure were preventing execution.

A security governance charter was drafted by day 30, standing up a committee with direct representation from the CISO, internal audit, and finance. The committee held its first formal meeting the following week, with a recurring reporting cadence established from that point forward.

Decision Integrity

The engagement evaluated whether decisions already on paper would hold up under real operational pressure, not just audit review. A roughly two-and-a-half-week incident response tabletop process with the newly-formed security committee and technical teams tested the relationship between documented procedures, ownership, and actual capacity to execute, closing with a formal lessons-learned review.

Working with the client's auditors, the resulting corrective action plan (POA&M) set a 90-day remediation window for the findings, down from an unmanaged timeline that could have stretched to 6 months. The accelerated timeline was driven by a contractual requirement the client's own customer had in place, giving the engagement a hard external deadline rather than an internally negotiated one.

Operational Execution

The advisory work translated the findings into operating changes:

  • Stood up a cross-functional security committee with direct representation from the CISO, internal audit, and finance, chartered within 30 days of the baseline assessment.
  • Developed and implemented a third-party cyber risk management program covering all 32 vendors in the delivery network, including tiering, risk questionnaires, and ongoing monitoring protocols.
  • Built and formalized a 12-policy, 10-procedure information security library from the ground up, covering access control, data classification, and related domains (business continuity and incident response were developed separately and fed directly into the tabletop exercise).
  • Supported the client's CIO-led vendor and tooling review, consolidating security tooling to 9 trusted tools, down from a larger set with significant overlap and expiring contracts, as part of a broader cost and overlap reduction effort.
  • Established a prioritized threat detection and response strategy based on the organization's specific risk profile.
  • Led an incident response tabletop simulation that produced actionable insights and drove a measurable shift in leadership posture.

Representation on the reconstituted committee spanned 5 business units, with representation weighted by unit size, some contributing a single leader, others contributing multiple.

Outcomes

The engagement produced a security program structured around the actual decision-making requirements of the organization, not a generic controls framework applied without context.

  • Security ownership was clarified through a chartered, cross-functional governance committee operating on a defined cadence within 37 days of engagement start.
  • All 32 third-party vendors were brought under active, ongoing risk management rather than periodic acknowledgment.
  • A 22-document policy and procedure library was formalized where little had previously existed.
  • The incident response function was tested through tabletop simulation and produced a prioritized remediation path, formalized into a 90-day corrective action plan against findings that could otherwise have taken up to 6 months to resolve.
  • Vendor security reviews conducted alongside the client's tooling consolidation effort simplified the vendor security review process for the client's operations team.
  • A subsequent third-party audit, conducted as the client pursued SOC 2 and ISO 27001, reflected the strength of the governance program built during the engagement.

Following the initial 90-day engagement, Antares transitioned into an ongoing vCISO retainer at the client's request, continuing to run the governance cadence, oversee the vendor risk program, and support the client's broader compliance roadmap.

Lessons Learned and Next Steps

The organization's documentation said one thing. Its operational reality said another. The engagement showed that fragmented ownership, unclear decision authority, and controls that are technically present but operationally unsupported are structural problems. Resolving them required correction in how security decisions were made, enforced, and observed.

The challenge this organization faced is common in mid-market environments. That's the gap Antares operates inside.

About the author
Branden Rowe, Founder and Managing Director of Antares Security

Branden Rowe

Founder & Managing Director, Antares Security

Branden Rowe is the Founder and Managing Director of Antares Security, a cybersecurity advisory practice focused on helping organizations make better security, risk, and governance decisions. His work spans security leadership, cyber risk, governance, and operational security across regulated and complex enterprise environments.

Need a senior advisory perspective on your security program?

A 30–45 minute advisory call covers operating context, current posture, and the decisions forcing the work. If a fit exists, we propose scope.