NIS2 · DORA · GDPR Ready

The AI Co-Pilot for
Cyber Risk Leaders

vCDRO — virtual Chief Digital Risk Officer

Built for European operating companies

Why vCDRO is different

Everything connects to this single vCDRO platform.

vCDRO

Autonomous NACE Pipeline

Every vulnerability and asset is automatically linked to European NACE business processes — no manual mapping required.

The value of every layer

From a CVSS score to business risk in euros

Same vulnerability, four lenses. Watch how each vCDRO layer turns an abstract CVE into a decision-grade, owned, quantified business risk — autonomously.

CVE-2024-3400·Firewall VPN RCE
Every scannerCVSSCritical
Every scanner

Raw CVSS

Output

10.0

Critical

  • Technical severity
  • Exploit metrics
  • Nothing about your business

Context-free. Where ~95% of the market stops.

The value delta

Every tool you own says "10.0 Critical". vCDRO says it’s a €2.4M risk to your invoicing process — owned, quantified, and ready to route to the person who can fix it.

Autonomous

Re-scored on every new scan, every control change, every framework update — no manual mapping, no spreadsheets, no consultant in the loop.

Industry Scenarios

How vCDRO serves your sector

Every industry has a different risk profile. vCDRO bootstraps from your NACE code to generate a sector-specific risk programme — here’s what that looks like for four common sectors.

These are sector capability illustrations, not customer case studies. Each scenario reflects what vCDRO generates during bootstrap for that NACE code.

Continuous Threat Exposure Management

One loop - Five phases - vCDRO at the centre

Armis, Hadrian, Qualys, PassGuard and Horizon3 each do their part. vCDRO turns their signals into one continuous, business-aware exposure programme — the Gartner CTEM loop, running itself.

ArmisAssetsHadrianExternalQualysVMDRPassGuardInfostealersHorizon3InternalvCDROCTEM engine

Phase 1 / 5

Scoping

vCDRO anchors every exposure to your business — NACE processes and TOGAF architecture define what actually matters before a single scan runs.

Suppliers active

vCDRO

Continuous loop

Every new scan re-runs the loop — scoping, discovery, prioritisation, validation and mobilisation happen without a human in the middle.

Regulatory Coverage Matrix

vCDRO covers ~85% of the Dutch Cybersecurity Act (Cbw) and Critical Entities Resilience Act (Wwke) obligations — everything from risk analysis to incident reporting and board accountability.

82%

vCDRO Coverage Matrix

Cbw + Wwke

7 of 9 obligations fully covered by vCDRO modules. 2 obligation(s) have external final steps.

Covered
Partial
External

Registration Obligation

Cbw
60%

Data & checklist prepared; actual registration via mijn.ncsc.nl is external

2 vCDRO modules

Duty of Care

Cbw
95%

Risk analysis, vulnerability management, compliance frameworks and asset inventory

5 vCDRO modules

Incident Reporting Obligation

Cbw
90%

IR playbooks, live incident mode, MTTD/MTTR metrics and real-time alerting

5 vCDRO modules

Board Accountability

Cbw
85%

Board memos, governance review and dashboard — training is external

4 vCDRO modules

Supervision & Enforcement

Cbw
90%

Audit trail, evidence locker, governance review and NIS2 dashboard

4 vCDRO modules

Critical Entity Risk Analysis

Wwke
85%

CRR, BIA and FAIR-based quantitative risk analysis

3 vCDRO modules

Resilience Measures

Wwke
70%

Cyber resilience fully covered; physical security is external

4 vCDRO modules

Disruption Reporting Obligation

Wwke
85%

IR hub with live incident mode and lessons learned

3 vCDRO modules

Supplier Resilience

Wwke
80%

Vendor risk management and supply chain compliance controls

2 vCDRO modules

vCDRO provides data, checklists and preparation for external processes (NCSC registration, board training, physical Wwke security). The final action takes place outside the platform.

Download our whitepapers

Seven resources that articulate the vCDRO philosophy, the autonomous architecture, the quantified business case, a candid competitive analysis, and the Horizon3 + vCDRO CTEM combination.

White papers

Seven introduction resources that articulate the vCDRO philosophy, the autonomous architecture, the quantified business case, a simple slide deck for SMEs, a detailed external analysis of the 10-stage pipeline, a candid competitive analysis against the broader vCISO market, and a brief on the Horizon3 + vCDRO autonomous CTEM combination. Download as PDF.

8-slide introduction

Scanner + vCDRO: What It Means for Your SME

A plain-language introduction for SMEs — how vCDRO turns your scanner’s wall of red into prioritised, financially-quantified business decisions. Simple enough to share with non-technical stakeholders.

8 slides, plain languageScanner output → business impactBefore vs after comparison
2-page executive brief

The vCDRO Approach

A punchy executive brief for boards and decision-makers — why business-first, financially-quantified risk management leaves every existing tool behind.

Board-language framingTool-by-tool differentiationRead in 3 minutes
3-page strategic white paper

From Vulnerability Noise to Boardroom Clarity

A deep strategic white paper on the autonomous NACE pipeline, FAIR financial quantification, and the closed-loop architecture that makes vCDRO self-maintaining.

Full market analysisCapability comparison tableFAIR & autonomy deep-dive
Business case paper

The vCDRO Business Case

A quantified breakdown of time, cost and risk savings by role — from SOC analyst to audit committee — showing exactly what the platform delivers and what it replaces.

Per-role savings table€530K+ annual capacity recoveredCost-of-inaction analysis
Pipeline architecture paper

The vCDRO Unique Pipeline Approach

An external view on how powerful the vCDRO approach really is — a 10-stage pipeline from CVE ingestion to board report, with core strengths, challenges, and an overall maturity assessment.

10-stage pipeline sequenceCore strengths & challengesExternal maturity assessment
Competitive analysis paper

How vCDRO Compares to the vCISO Market

A candid competitive analysis — where vCDRO genuinely outperforms compliance automation, enterprise GRC, and consultant vCISO services, and where established competitors still lead.

8 differentiators identified4 areas competitors leadFull positioning matrix
CTEM brief

Autonomous CTEM: Horizon3 + vCDRO

A focused brief on the Horizon3 NodeZero + vCDRO combination — a near-fully-autonomous CTEM programme for organisations that cannot staff a 24/7 SOC.

The two halves, one loopPer-phase responsibility tableWhy autonomy matters for the mid-market

Pricing that scales with your organisation

Transparent per-month pricing based on organisation size. Every tier includes the autonomous NACE pipeline and AI co-pilot.

Starter

Essential

€•••
per month

Up to 25 employees

  • Security Posture Dashboard
  • Asset Inventory
  • Vulnerability Management
  • NACE Business Intelligence
  • Patch Prioritisation

Growth

Growing

€•••
per month

26 – 50 employees

  • Everything in Starter
  • Compliance Hub (all frameworks)
  • Board Reports
Most Popular

Scale

Scaling

€•••
per month

51 – 100 employees

  • Everything in Growth
  • IR Hub
  • Human Risk Hub
  • Business Impact Analysis
  • Vendor Risk Management

Professional

Professional

€•••
per month

101 – 250 employees

  • Everything in Scale
  • FAIR Risk Quantification
  • Full Resilience Hub (CRR, BCM, Gap Tracking, Strategic Mapping)
  • TOGAF Architecture View
  • Financial Risk Modelling

Enterprise

Enterprise

€•••
per month

251 – 2,000+ employees

  • Everything in Professional
  • Dedicated vCDRO Advisor
  • Custom NACE Integrations
  • Tabletop Exercises
  • SLA Guarantee

All prices in EUR · Annual billing available · MSSP white-label options on request

Get in Touch

Contact Us

Reach out to our team — we’re happy to answer your questions about vCDRO and NetBoss services.

Email

Contact us by emailing without obligation to:

Phone

Our experts are also available by phone to answer all your questions:

Our Office

Our offices are located at the following addresses:

Vingerhoekhof 6A
3401 DX IJsselstein
Nieuwegracht 4-04
3763 LB Soest
View on map

Websites

Visit our websites for more information about our services and security insights:

Powered byNetBoss
AboutContactSign inGet Started
© 2026 vCDRO (Virtual Chief Digital Risk Officer). All rights reserved. · European-first cybersecurity.