Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

How to Run a Virtual CISO Engagement

A virtual CISO (vCISO) engagement runs in four phases: a 30-day assessment, a 90-day remediation sprint, ongoing program management (policies, vendor risk, audits), and monthly board or executive reporting. Most Canadian companies see the first material shift, questionnaires answered same-day, a real risk register, in the first quarter, with the vCISO acting as a fractional executive rather than a one-off consultant.

What a Virtual CISO Engagement Actually Covers

A fractional or virtual CISO is not a security tool subscription with a human attached. It is a part-time executive who owns your security program the way a full-time CISO would, just without the full-time salary. That means the person is accountable for the risk register, the policy set, the incident response plan, vendor due diligence, and the story you tell auditors, investors, and enterprise customers.

For companies in Toronto, Waterloo, and Ottawa selling into US enterprise accounts, the vCISO is often the first person who can answer a 200-line security questionnaire without pulling three engineers off a sprint. That single capability, credible, fast answers to buyer diligence, is usually what justifies the retainer.

Phase One: The 30-Day Security Assessment

Every credible engagement starts with a baseline. In the first 30 days, expect the vCISO to:

  • Inventory your systems, data flows, and third-party vendors
  • Interview engineering, ops, and leadership to map how decisions actually get made
  • Score gaps against a recognized framework, SOC 2 or ISO 27001
  • Deliver a prioritized risk register, not a 40-page PDF nobody reads

The deliverable that matters here is prioritization. A vendor selling a scanning tool will hand you a list of 300 findings. A vCISO tells you which five actually move the needle on a deal or an audit, and which 295 can wait.

Phase Two: The 90-Day Remediation Sprint

This is where most DIY security efforts stall, because remediation requires someone with the authority and the calendar time to chase down owners across engineering, HR, and IT. A realistic 90-day sprint covers:

  • Access control cleanup (offboarding gaps, shared credentials, excessive admin rights)
  • Written policies that match what the company actually does, not a boilerplate template
  • MDM and endpoint controls rolled out across the team
  • A tested incident response plan, not just a document that says one exists

Ninety days is aggressive but achievable for a company under roughly 150 people, provided the vCISO has direct access to engineering leadership and a mandate to make decisions, not just recommendations. This is the phase where our fractional CISO service earns its retainer: the work only moves as fast as someone with real authority pushes it.

Phase Three: Ongoing Program Management

Once the initial gaps close, the engagement shifts from sprint mode to steady-state ownership. This is the part companies underestimate when they think of a vCISO as a project rather than a role. Ongoing work includes:

  • Security questionnaire responses, usually turned around within 24 to 48 hours
  • Vendor risk reviews before new tools get onboarded
  • Quarterly policy updates as the business and headcount change
  • Audit prep and evidence collection for SOC 2 or ISO surveillance audits

Companies handling Quebec residents' personal information also need this phase to track Law 25 obligations continuously, not just at renewal time.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire. Fractional CISO

Phase Four: Board and Executive Reporting

A vCISO who cannot translate technical risk into business language is not doing the job. Monthly or quarterly reporting to the board or leadership team should cover:

  • Risk register movement, what closed, what's new, what's overdue
  • Metrics tied to business outcomes: deals unblocked, audit readiness, incident count
  • Budget and headcount recommendations backed by actual data, not fear

This reporting cadence is often what separates a real vCISO relationship from a compliance checkbox. Boards and investors in Vancouver and Calgary tech companies increasingly ask for this level of visibility before a Series B or an enterprise renewal, and a fractional CISO who has done it before knows how to keep the report short enough that people actually read it.

Realistic Timelines: What to Expect Month by Month

Set expectations early so nobody is surprised when security work doesn't fit into a two-week sprint:

  • Month 1: assessment, risk register, quick wins on access control
  • Months 2 to 3: policy rollout, MDM deployment, incident response plan drafted and tested
  • Months 4 to 6: audit readiness work if pursuing SOC 2 or ISO 27001, first round of vendor risk reviews
  • Ongoing: questionnaire response, board reporting, continuous monitoring, policy maintenance

Companies chasing a SOC 2 report on a tight sales deadline should plan for at least six months from kickoff to a clean Type I, longer for Type II, which requires an observation window. A vCISO who has run this before will tell you that timeline honestly instead of promising a faster result to close the deal.

Where a Partner Actually Adds Value

The honest answer is that a lot of the framework mapping, questionnaire logic, and policy templates are commoditized now. Automated compliance platforms handle evidence collection well. What they cannot do is show up to a board meeting, argue with an auditor over a scoping decision, or make the judgment call on whether a finding is a five-alarm fire or a next-quarter fix. That judgment is what a published security researcher brings to the table: someone who has found real vulnerabilities in production systems, not just read about them in a framework document, is better positioned to tell you which of your gaps an actual attacker would exploit first. If your company is also building out a broader compliance program alongside the security work, having one team own both threads keeps the story consistent for auditors and enterprise buyers alike.

Choosing Between a Full-Time Hire and a Fractional CISO

Most companies under 200 employees do not need, or cannot justify, a full-time CISO salary. A fractional arrangement gives you executive-level ownership at a fraction of the cost, and it scales down when the intense remediation phase ends and steady-state maintenance begins. The trade-off is availability: a fractional CISO is not in your Slack all day, so the engagement only works if reporting lines and escalation paths are clear from day one.

For Canadian companies weighing that trade-off, especially SaaS businesses selling into the US where SOC 2 is a deal-blocker, a fractional CISO from a Canadian firm also means someone who already understands PIPEDA and provincial privacy law alongside the US frameworks your buyers expect.

Getting Started

If you're evaluating whether a virtual CISO engagement makes sense for your stage and budget, get in touch and we'll walk through your current risk posture, what a realistic 90-day plan looks like, and where traztech can plug in as your fractional security executive.

What the contract needs to say before day one

Most vCISO engagements that fail do so because the contract described a person's time instead of the company's outcomes. Hours per month is a useful budgeting unit and a terrible scoping unit, because it tells nobody what the engagement is responsible for. The agreements that work name four things explicitly.

First, the decision rights. Can the vCISO reject a vendor, block a production change, or veto a control exception, or can they only advise while an internal VP decides? Both models work, but the company has to pick one and tell the engineering team which it is. Second, the escalation path and response expectation. A fractional executive is not in your Slack at 11pm on a Friday by default, so define what constitutes an urgent call, who can make it, and what response time is committed. Third, the artifact list. Name the deliverables that must exist at 30, 90, and 180 days, with owners: risk register, policy set, incident response plan with a tested tabletop, vendor inventory, and a control matrix mapped to whichever framework the buyers are asking about. Fourth, the exit terms. Every fractional arrangement ends eventually, and the handover clause is worth writing while everyone is still friendly.

Add one more clause if you can: a conflict disclosure. If the same firm that runs your vCISO program also sells you the penetration test, the readiness work, and the tooling, someone should say out loud how that is priced and where the independent opinion comes from. We disclose it because clients ask, and because a security leader whose recommendations always happen to point at their own service lines stops being useful quickly.

The first ten days set the ceiling on everything after

The 30-day assessment is only as good as the access granted in the first week. A vCISO who spends three weeks chasing read-only credentials has burned a quarter of the phase on procurement friction. Before kickoff, prepare read access to the cloud console, the identity provider, the code repositories, the ticketing system, the HR system for joiner and leaver records, and the finance system's vendor list. That last one is the most useful and the least offered. The vendor payments ledger is usually a more honest inventory of your third-party exposure than any tool inventory anyone maintains, because every SaaS subscription somebody expensed shows up in it.

Book the interviews in the first week too. Engineering leadership, whoever runs IT or does it accidentally, the person who signs contracts, and one or two senior engineers who have been there longest. The last group tells you what actually happens, which is frequently different from what the org chart implies. If a company cannot get its own leadership into four half-hour conversations inside two weeks, that is itself a finding, and it predicts how the remediation phase will go.

Cost drivers, and what changes the number

Fractional CISO work at traztech starts at $3,000 per month, and the variables that move a quote up are fairly predictable. Regulated data raises it, because health or payment data pulls in specific control sets and specific regulator expectations. Multiple frameworks running at once raises it, since a company chasing SOC 2 and ISO 27001 simultaneously is running two evidence programs even when the controls overlap. Headcount matters less than you would think, but the number of distinct engineering teams matters a lot, because each one has its own change process to reconcile. Volume of inbound security questionnaires matters, especially for companies selling into financial services, where a single enterprise buyer can generate forty hours of diligence response on its own.

What lowers the number is a company that already has an identity provider with SSO enforced, endpoint management deployed, and a ticketing system where work is actually tracked. Those three things are the substrate everything else is built on, and a vCISO who has to establish them first is doing IT work at executive rates. If you are shopping and the quotes vary wildly, ask each firm which of those they assumed you had. The published shape of our retainers is on the pricing page, and the ongoing model, including incident response coverage, is described under engage.

Failure modes we see repeatedly

The advisory trap. The vCISO produces excellent recommendations that nobody implements, and six months later the risk register looks identical to month one with different dates. The cause is almost always that no internal person owns execution. A fractional executive can drive work but cannot do all of it, so every remediation item needs an internal owner with a name, not a team.

Framework drift. A company starts toward SOC 2, a European prospect asks for ISO 27001, and the program fractures into two half-built efforts. The fix is to pick the primary framework based on where the revenue actually is, build the control set once, and treat the other as a mapping rather than a parallel project.

The questionnaire treadmill. Answering buyer questionnaires feels productive and consumes the entire retainer. If more than about a quarter of the monthly hours go to questionnaire response, something is wrong with the answer library. Build a maintained set of canonical answers with evidence links, keep it in one place, and the same volume of questionnaires takes a fraction of the time. The free traztech Workspace exists partly for this reason.

Undocumented authority. The engineering team was never told the vCISO can make binding calls, so every decision gets relitigated. Announce the arrangement internally on day one with a short note from the CEO or CTO stating what the vCISO owns. This costs nothing and prevents months of friction.

Silent scope creep into IT. Laptop provisioning, password resets, and Google Workspace admin quietly migrate to the security retainer because the vCISO is the only person paying attention. Watch for it, and hire or outsource IT separately when it starts.

Measuring whether it is working

Six months in, someone on the executive team should be able to answer whether the retainer is earning its cost. Time to answer an enterprise security questionnaire is the most legible metric, and moving from two weeks to two days is a change the sales team feels directly. Percentage of overdue risk register items is the second, because a register where everything is perpetually in progress is a register nobody is working. Mean time from employee departure to full access revocation is the third, and it is worth measuring because it is one of the few controls that maps cleanly to real breach risk and is trivially verifiable.

Avoid vanity metrics. Number of policies written measures nothing. Number of vulnerabilities detected measures your scanner's license tier. If the reporting pack going to the board is mostly counts of things that increased, it is not a security report, it is a tool export with a cover page.

What the board pack should contain

Keep it to two pages. Page one carries the risk picture: the top five risks in plain business language, what moved since last quarter, and what is overdue with the reason. Page two carries decisions requested, because a board meeting where security asks for nothing produces nothing. Include the specific budget or headcount ask, the deal impact if it is declined, and a recommendation. Directors of Canadian companies increasingly ask about breach notification obligations under PIPEDA and Quebec Law 25 by name, so keep the notification clocks and the last tabletop date on the page rather than reciting them from memory when asked.

When a virtual CISO is the wrong purchase

There are companies we tell to wait, and the pattern is consistent enough to describe.

If you have fewer than about fifteen people, no regulated data, and no enterprise buyer asking questions, you do not need a fractional executive. You need MFA enforced everywhere, managed laptops, a backup you have restored from at least once, and a documented process for removing access when someone leaves. That is a few weeks of focused work by a competent senior engineer, and paying $3,000 a month for someone to supervise it is poor value.

If your actual problem is a single audit with a fixed end date, buy the fixed-scope readiness work instead of a retainer. A defined compliance engagement with a deliverable and a completion date is cheaper and clearer than an open-ended arrangement, and you can convert to a retainer afterwards if the maintenance burden justifies it.

If your real gap is technical assurance rather than governance, buy a penetration test. Companies sometimes hire a vCISO hoping to find out whether their product is secure, which is not what the role does. Testing starts at $1,000 and answers that question directly. Our security services cover that side, and the two engagements are genuinely different purchases.

If you already have a capable head of engineering with security depth and enough calendar space to own the program, give them the mandate and a budget for specialist help instead. Internal ownership beats fractional ownership when it exists, every time. The fractional model exists because most companies at this stage do not have it, not because it is inherently superior. If any of the above describes you, say so on the first call and we will tell you the same thing. The engagements that go badly are usually the ones that should never have started.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.

Fractional CISOOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.