Capability walkthrough

Every stage of the engagement, in one platform

From the first onboarding call to the board briefing — evidenced as it goes. Every capability built for advisory outcomes, not service-desk throughput.

Deliberately not a PSA

Autotask and ConnectWise optimise for service desk throughput. vCISOHub optimises for maturity movement, risk posture, board-ready narrative, and reusable intellectual property.

MSP PSA platformvCISOHub
Optimised forTicket throughput and technician utilisationMaturity movement and advisory outcomes
Unit of workThe ticketThe programme, the action plan, and the artefact
FrameworksBolt-on or spreadsheetNIST CSF 2.0 and CIS v8 in a shared control library
Output to the boardTicket volume reportsGovernance health score and QBR narrative
The client seesA ticket queueA nav-less executive snapshot
vcisohub.app / workspace / onboarding

Setup progress

72%

5 of 7 steps complete

Tier

Practice

Flat monthly, 11–30 clients

Security Programme
AI Governance
Risk Register
Business Resilience
Practice profile and brandingDone
Invite practice usersDone
Adopt a programme packIn progress

Partner onboarding and account management

Guided partner workspace creation: company, tier, branding, enabled modules.

  • Flat monthly Solo and Practice tiers, with client allowances matched to practice size.
  • Suspend, reinstate, or hard-delete a partner with full workspace cleanup.
  • Onboarding checklist that reads live data — progress is real, not self-reported.
  • Editable partner profile: branding, contacts, address, practice details.
  • Seat management and invite claiming for partner users.
Client workspace / snapshot

Client roster and relationship management

Roster with avatars, sector, headcount, tier, and live delivery signals.

  • Full client record editing, plus create and delete with workspace cleanup.
  • Contacts, activities, notes, and tasks per client — the useful half of a CRM.
  • Delivery signals: open and overdue actions, plan completion, narrative health.
vcisohub.app / programmes / builder
DefinitionPhasesTasksControls
NIST CSF 2.014/22 mapped
CIS Controls v811/18 mapped
Phase 1 · Baseline6 tasks
Phase 2 · Policy stack9 tasks
Phase 3 · Assurance5 tasks

Programme catalogue and programme builder

Adopt ready-made programme content packs or author your own from scratch.

  • Four-step builder: definition, phases, tasks, control mapping.
  • Shared control library seeded with NIST CSF 2.0 and CIS Controls v8.
  • Control mapping means a bespoke programme still benchmarks against recognised frameworks.
  • Version control on programmes, plus delete and clean-up of partner-authored content.
vcisohub.app / clients / action-plan

Open

27

Across the plan

Overdue

3

Needs attention

Complete

64%

Plan progress

Access review — privileged accountsDelivered
Incident response plan refreshIn progress
Vendor risk assessment — payrollIn progress
Backup restore test evidenceOverdue
Security awareness campaignNot started

Universal action plan engine

One engine drives both packaged content and partner-authored programmes.

  • Task lifecycle with owners, due dates, status, and evidence attachments.
  • Automatic policy-to-task linking — a delivered policy closes the matching action.
  • Expected-deliverables model flags which artefacts are still missing.
  • Assessment importer ingests existing roadmap exports to migrate live engagements in.
Practice / time & billing

Bill from your calendar, not your memory

Pull Outlook entries into one review queue so advisory time does not disappear between meetings.

  • Assign each entry to a client and rate, then review what is ready to bill.
  • Close out the month with a clear record of time, retainer effort, and invoiceable work.
Library / policy library

A maintained policy library, not a shared drive

Curated policy sets — Business Resilience, Enterprise and SMB Information Security suites, and AI Governance suites — kept current for you.

  • Assign from library to any client in one action: multi-file, multi-set.
  • Clients download, edit, and re-upload organization-specific versions; revert to the master at any time.
  • Upload your own documents alongside the library.
  • Sector addendums for legal, accounting, health, non-profit, and First Nations clients.

Governance and risk modules

Modules are granted by the platform operator to the partner, and by the partner to individual clients — a two-level entitlement model that doubles as your packaging and upsell path.

AI Governance Essentials / Professional / Enterprise

One engine, scaled per client: structured intake with manager pre-approval, the AI Register, vendor AI assessments, privacy impact assessments, and Shadow AI Discovery.

Security Business Assessment

Business-aligned security assessment in three depths — Light, SMB, and Full — so the assessment matches what the client can afford.

Business Resilience Program

Phase-based resilience planning with phase plans and documents, structured and repeatable.

SMB Resilience Program

A right-sized resilience and security program for small and mid-sized clients.

Scorecards and roadmaps

Per-client posture scorecards, benchmarked across your book, with prioritized improvement roadmaps.

AI governance / client programme

AI governance depth

The differentiator: a complete AI governance practice in a box — intake, the AI Register, vendor assessments, privacy impact assessments, and policy suites.

  • Three tiers on one engine: AI Governance Essentials, Professional, and Enterprise.
  • Shadow AI Discovery scans the client's Microsoft 365 environment for unmanaged AI use — a report you deliver.
  • Tool-request intake with automated manager pre-approval emails.
  • Microsoft Teams-native Q&A bot answering staff questions with citations and escalation.
  • Sector overlays for legal, accounting, healthcare, not-for-profit, and First Nations.
  • Policy library with version control, acknowledgements, and branded PDF generation.
Explore the module
Executive reporting / generated QBR

Executive reporting

QBR generator assembling governance status, coverage, risk movement, and narrative.

  • Governance health scoring that turns delivery data into one defensible score.
  • Cross-client coverage benchmarking across your whole book of business.
  • Branded PDF and document export throughout.
Library / resources & enablement

Resources and enablement

Practice resource hub with onboarding guides, templates, and playbooks.

  • Policy library pre-load, auto-assigned when a module is enabled for a client.
  • In-portal document reader and per-client artefact sharing.
  • Guided product tours for first-time users.
Client view / programme snapshot

A branded Client Portal

Nav-less single-page executive snapshot — not another dashboard to learn.

  • Governance status, recent accomplishments, current priorities, progress tiles.
  • Document download section for policies and deliverables.
  • Magic-link invitations — no password friction for client staff.
  • Clients submit tool requests and project proposals and complete checklist items themselves.
  • Automated email journeys for invites, approvals, and nudges.