Skip to main content
Category: Incident Response

Preparation

Also known as: Preparing, Readiness (informal usage)
Simply put

Preparation is the act or process of getting something ready for use, service, or a future occasion. It involves planning, organizing, or taking actions in advance so that a person or organization is ready when a given situation arrives.

Formal definition

Preparation refers to the action or process of making something ready for use or consideration, or of getting ready for a specific occasion or objective. In practice it encompasses deliberate advance activities such as planning, training, studying, or organizing resources, undertaken with a defined goal in mind. As a general term, its specific scope and rigor depend on the context in which it is applied.

Why it matters

Preparation is the connective concept behind nearly every effective security leadership engagement, because the value of a virtual or fractional CISO is realized largely through advance planning rather than reactive scrambling. Getting ready for use, service, or a future occasion is precisely what distinguishes a governance-oriented security program from an improvised response to incidents. When an organization has prepared deliberately, decisions during pressure moments are informed by prior planning, defined roles, and organized resources rather than by guesswork.

The absence of preparation tends to surface at the worst possible time. Organizations that treat readiness as an afterthought often find that plans exist only on paper, stakeholders have not been engaged, and resources have not been organized in advance. Because preparation is fundamentally about taking action ahead of a given situation, its benefit is only available to those who invest before the situation arrives. This is why security leadership consistently frames preparation as a governance and risk activity, not merely a technical one.

It is worth noting a limitation that experienced practitioners insist upon: preparation reduces uncertainty and improves readiness, but it does not guarantee any specific outcome. Advance planning makes an organization more ready for a future occasion; it does not eliminate the occasion itself or its potential consequences. Preparation should be understood as improving the odds and the quality of response, not as a promise of prevention.

Who it's relevant to

Security and Business Leaders
Leaders responsible for organizational readiness rely on preparation to ensure that plans, resources, and people are organized in advance of foreseeable situations. Because preparation is a planning and governance activity, its value depends on stakeholder engagement and clearly defined goals rather than on technical execution alone.
Virtual and Fractional CISOs
Advisory security leaders often direct preparation efforts by helping organizations plan, organize, and get ready in advance. Their role is typically to guide and structure readiness activities, while accountability for acting on that preparation generally remains with the client organization and its officers.
Teams Executing Advance Activities
Individuals engaged in planning, training, studying, or organizing resources apply preparation directly in their day-to-day work. The rigor of their efforts should be matched to the context and the specific occasion or objective they are preparing for.

Inside Preparation

Scope Definition
Documented agreement on what the engagement covers, such as strategy, governance, risk management, and program development, and what falls outside it, such as hands-on SOC monitoring, tool administration, or incident response execution unless explicitly contracted.
Stakeholder Access Planning
Arrangements for reaching executives, IT owners, and business unit leaders, since engagement value often depends heavily on client cooperation and access to decision-makers.
Current-State Assessment
An initial review of the organization's existing security posture, policies, and maturity to establish a baseline; the depth of this work typically varies by engagement type and organizational maturity.
Framework Selection
Identifying which frameworks or standards are relevant to the organization, such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, GDPR, or CMMC, and clarifying that preparation supports readiness rather than guaranteeing certification or compliance.
Accountability Clarification
Explicit agreement that a virtual, fractional, or interim CISO advises and directs, while legal and organizational accountability for security decisions generally remains with the client organization and its officers unless a contract specifies otherwise.
Engagement Type Alignment
Confirmation of the model being used, since a vCISO is typically a remote part-time engagement often delivered through a firm, a fractional CISO shares time across multiple clients, and an interim CISO fills a temporary full-time gap, though these terms can overlap in practice.

Common questions

Answers to the questions practitioners most commonly ask about Preparation.

Does a virtual CISO handle incident response execution as part of preparation?
Typically no. A virtual CISO focuses on preparation at the strategy and governance level, such as helping develop an incident response plan, defining roles and escalation paths, and ensuring readiness activities are in place. The hands-on execution of incident response, including containment, forensics, and remediation, generally falls outside the standard scope unless it is explicitly contracted. In many engagements this operational work is performed by an internal team, a managed security service provider, or a dedicated incident response firm. Confusing a vCISO's preparation role with operational execution is a common mistake that experienced buyers work to avoid.
If a vCISO leads preparation efforts, do they become accountable for the outcome of a security event?
Not usually. A virtual CISO advises on and directs preparation activities, but legal and organizational accountability for security decisions typically remains with the client organization and its officers. Preparation work such as building plans, guiding tabletop exercises, or shaping governance does not transfer liability or regulatory accountability to the vCISO unless a contract specifically states otherwise. It is important to separate the advisory responsibility a vCISO carries from the accountability that stays with the client.
How should an organization scope preparation work with a virtual CISO?
Scope is often defined at the outset of the engagement and may vary by provider. In many cases, preparation work is bounded by what strategic and governance activities are included, such as plan development, policy design, or readiness assessments, versus operational tasks that are excluded. Clearly documenting which preparation deliverables are in scope, what remains the client's responsibility, and what would require additional agreement helps set realistic expectations. The value of the work frequently depends on the organization's maturity, the access the vCISO has to stakeholders, and the level of client cooperation.
What does preparation typically look like in the early phase of a vCISO engagement?
In many engagements, early preparation focuses on understanding the current state before building anything new. This can include reviewing existing policies, assessing the organization's risk posture, identifying stakeholders, and clarifying business objectives and constraints. From there, a virtual CISO often prioritizes preparation activities based on risk and organizational maturity. The depth and speed of this phase can vary depending on how readily the client provides access to information, systems documentation, and decision-makers.
How does preparation relate to compliance readiness for frameworks like SOC 2 or ISO 27001?
A virtual CISO can support preparation and readiness for frameworks such as SOC 2 or ISO 27001 by helping identify gaps, shaping policies, and organizing evidence and processes toward the framework's requirements. It is important to distinguish supporting readiness from asserting certification. A vCISO engagement generally does not guarantee certification or a passing audit, since those outcomes depend on independent assessors, the organization's execution, and factors outside the advisor's control. Preparation improves the likelihood of a smoother assessment but does not assure a specific result.
Who should be involved from the client side to make preparation effective?
Effective preparation typically depends on access to the right stakeholders, since security leadership is a governance and business risk function rather than a purely technical one. In many engagements this includes executives or officers who own accountability, IT and operations staff who understand the environment, and business owners who can speak to priorities and constraints. When key stakeholders are unavailable or client cooperation is limited, the quality and pace of preparation often suffer, which is why defined access and engagement are frequently treated as prerequisites for meaningful outcomes.

Common misconceptions

A virtual CISO engagement includes hands-on operational work like monitoring and incident response.
A virtual CISO generally provides strategy, governance, and executive-level guidance and does not perform operational tasks such as SOC monitoring, tool administration, or incident response execution unless those are explicitly contracted.
Preparing a compliance-focused engagement means the vCISO will deliver certification or guaranteed compliance.
A virtual CISO can support readiness toward frameworks such as ISO 27001, SOC 2, or PCI DSS, but preparation and support differ from asserting certification, which typically depends on external audits and the client's own actions.
Engaging a vCISO is the same as hiring a managed security service provider or replacing an entire security team.
A virtual CISO is a leadership and governance function focused on business risk, not a managed service provider or a substitute for a full operational team; security leadership is not a purely technical role.

Best practices

Document engagement scope in writing at the outset, explicitly stating what is included and what is out of scope, such as operational tasks that require separate contracting.
Confirm the engagement model early, distinguishing whether the need is for a virtual, fractional, or interim CISO, since coverage and time commitments may vary by provider.
Clarify accountability boundaries in the contract, noting that the client organization and its officers typically retain legal and organizational accountability for security decisions.
Secure committed stakeholder access before work begins, since outcomes often depend on client cooperation and reaching relevant executives and business owners.
Set realistic expectations around frameworks and compliance, distinguishing support for readiness from any assertion of certification or guaranteed breach prevention.
Assess organizational maturity before defining deliverables so that goals and timelines reflect the client's actual starting point.