Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

Virtual CISO vs Full-Time CISO: Which Does Your Startup Need?

Every growing startup eventually hits the same wall: a customer asks for a SOC 2 report, an investor wants to see a security program, or a prospect's procurement team sends over a vendor security questionnaire nobody on the team knows how to answer. The reflex is to go hire a CISO. But a full-time Chief Information Security Officer is one of the most expensive hires a startup can make, and most early-stage companies do not have enough security work to fill that role forty hours a week. This is where the virtual CISO, also called a fractional CISO or vCISO, comes in.

The question is not whether you need security leadership. If you are selling into mid-market or enterprise B2B accounts, you do. The real question is which model fits your stage: virtual or full-time. Here is how to think it through.

What a Virtual CISO Actually Does

A virtual CISO is a senior security leader who works with your company on a part-time, contracted basis, typically a set number of hours per week or month. They do the same job a full-time CISO does: build and run your security program, own risk management, prepare you for audits like SOC 2 or ISO 27001, brief your board and investors, and answer customer security questionnaires. The difference is cost structure and time allocation, not scope of responsibility.

For most startups under 100 employees, a vCISO engagement covers everything a security program needs without the overhead of a full salary, benefits, and equity grant. You can read more about how this works in practice on our fractional CISO page.

The Cost Comparison

A full-time CISO in Canada typically commands a base salary well into six figures, before you add benefits, equity, bonus, and the recruiting cost of filling a role that can take months to hire for correctly. Security leadership is a specialized skill set, and good candidates are not sitting on the sidelines.

A virtual CISO engagement is priced as a monthly retainer or a fixed scope of hours, and it scales with what you actually need. Early on, that might be a few hours a week to stand up policies and get audit-ready. As you grow, the engagement can expand. You are paying for outcomes and expertise, not for a full calendar of someone's time when your security workload does not yet require it.

The math is simple: if your company does not generate enough security work to occupy a person full time, a full-time hire is money spent on idle capacity. A vCISO lets you buy exactly the coverage you need this quarter, and adjust next quarter.

Coverage: What You Actually Get

A common misconception is that a virtual CISO is a lesser version of a full-time one, someone who shows up occasionally and skims the surface. In practice, a good vCISO engagement gives you access to more experience than most startups could afford to hire full time. Fractional security leaders often work across several industries and have seen a wider range of audits, incidents, and buyer requirements than a single in-house hire would encounter in years at one company.

Where a virtual CISO model has real limits is in day-to-day presence. If you need someone in Slack every hour, sitting in on every engineering standup, or physically present for incident response at 2am, part-time hours will not cover it. A vCISO is built for programmatic work: policy, risk assessment, audit readiness, vendor reviews, board reporting, and questionnaire response. It is not built to be your only line of defence during an active breach, though a competent vCISO will have an incident response plan and escalation path ready before that ever happens.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire. Fractional CISO

When Does It Make Sense to Switch to Full-Time?

There is no fixed headcount or revenue number that triggers the switch. What matters is workload and risk exposure. A few signals that a startup has outgrown the fractional model:

  • Security work has become a full-time job. If your vCISO's hours keep expanding month over month and you are consistently asking for more time than the retainer covers, that is a market signal, not a scheduling problem.
  • You are running multiple concurrent compliance programs. A company juggling SOC 2, ISO 27001, and industry-specific frameworks like PCI DSS at the same time needs someone embedded daily.
  • Security touches product decisions constantly. Once security review is a required step in every sprint or release cycle, you need someone in the room, not someone joining twice a month.
  • You have a dedicated security or IT team to manage. A vCISO can direct a small team, but once you have several security hires reporting up, a full-time leader usually makes more sense operationally.
  • Regulatory or contractual obligations require a named, in-house executive. Some enterprise contracts and regulated sectors expect a full-time, employed security officer as a condition of doing business.

Many companies never fully leave the fractional model behind. A common pattern is a full-time CISO supported by a fractional advisor for specialized needs, or a fractional CISO who stays on in an advisory capacity after handing operational duties to an internal hire.

A Practical Starting Point

If you are a Canadian B2B SaaS company trying to close a deal that is blocked on a SOC 2 report, or fielding your first serious vendor security questionnaires, a virtual CISO is almost always the right starting point. It gets a real security program in place fast, without a multi-month executive search and without committing to a full salary before you know how much ongoing security work your company actually generates.

From there, treat the full-time decision as a capacity question you revisit every two quarters, not a one-time choice. Track the hours your vCISO is actually using, watch how often compliance and security work is blocking deals or product launches, and let that data tell you when it is time to bring the role in-house. If you want a clearer picture of what a compliance program costs at each stage, our compliance services page breaks down how audit readiness work is scoped.

Get a Clear Recommendation for Your Stage

The right model depends on your customer commitments, your current headcount, and how fast you are growing. Talk to us and we will give you a straight answer on whether a virtual CISO or a full-time hire fits where your company is right now, no upsell, just a recommendation based on your actual risk and workload. Contact traztech to start the conversation.

What the First Ninety Days of a vCISO Engagement Actually Look Like

The retainer conversation gets abstract fast, so it helps to look at what the work is in calendar terms. In the first two or three weeks, a competent fractional CISO is doing discovery: reading your cloud account structure, pulling the list of SaaS tools with production access, asking who can merge to main and who can reach the production database, and collecting whatever policies already exist even if they were copied from a template in 2023. The output of that stage is a written gap list tied to whatever framework your buyers are asking for, not a slide deck of maturity scores.

Weeks four through eight are usually the heaviest and the least glamorous. Policies get written or rewritten so they describe what your company genuinely does, access reviews get run for the first time, offboarding gets a checklist, and the risk register stops being a hypothetical document. This is also when the unpleasant discoveries surface: a former contractor still holding an active IAM key, backups that nobody has ever restored from, a production database reachable from a developer laptop over a VPN with a shared credential. Those findings are the real value of the first quarter, and they are the reason a discovery period cannot be compressed to a kickoff call.

By the end of the third month you should have a named control owner for every control, evidence collecting somewhere durable rather than in one person's Google Drive, and a security questionnaire answer library your sales team can use without escalating every request. If a vCISO engagement has run ninety days and your account executives still forward every questionnaire to the founder, the engagement is not working, regardless of how many meetings happened.

What Buyers Ask in a Security Call, and Why That Determines the Model

The clearest way to decide between fractional and full-time is to sit through three of your own enterprise buyer security calls and write down what gets asked. In our experience those calls follow a predictable shape. The buyer's security analyst wants to know where their data lives, who inside your company can read it, how access is granted and removed, what happens when you find a vulnerability, and whether an independent party has tested the thing. Then they ask something specific to their own risk appetite: subprocessor lists for a European buyer, breach notification timelines for a Quebec buyer under Law 25, cardholder data flow for anyone in payments.

Almost every one of those questions is answered from a document. That is precisely the work a part-time senior person does well. What a fractional model handles poorly is the follow-up that arrives two days later asking your engineering team to change a design decision before contract signature. If your deals routinely end with an architectural commitment made live on a call, you need someone with standing authority inside the company, and a retainer with a fixed hour budget is the wrong instrument. That is the honest dividing line, and it has nothing to do with headcount.

Cost Drivers That Move a Fractional Retainer

Fractional CISO work at traztech starts from $3,000 per month, and it is worth being explicit about what pushes an engagement above a floor price, because founders often assume the variable is company size when it usually is not. The four things that reliably increase hours are the number of concurrent frameworks in flight, the number of separate production environments or cloud accounts in scope, the volume of inbound customer security reviews per month, and the maturity of your engineering process. A twenty-person company with one AWS account, a single framework, and a disciplined change management process is cheaper to run than a twelve-person company with three legacy environments inherited from an acquisition.

The fifth driver is less obvious: whether the company has anyone internal who can execute. A fractional CISO who has to personally configure logging, chase evidence, and write Terraform is being used as an expensive engineer. The retainer stretches much further when there is a technically capable internal owner, often a senior developer or a head of platform, who takes tasks and closes them. When budget is tight, hiring or assigning that internal person is a better first spend than buying more advisory hours.

Costs that people forget to model on the full-time side are recruiting fees, the three to six month vacancy while you search, ramp time before a new hire is productive, and the risk of a mis-hire in a role where a bad fit is expensive to unwind. A first-time CISO hired into a company with no existing programme also arrives without a team, which means their first year is spent doing exactly the work a fractional engagement would have done, at four to five times the run rate.

How Fractional Engagements Fail

The failures are consistent enough to list. The first is no authority: the vCISO recommends, engineering deprioritises, and six months later nothing has moved except invoices. The fix is structural, not personal. The engagement needs an executive sponsor who will actually re-rank the backlog, and a standing agenda item where blocked items are escalated with names attached.

The second is access starvation. If the fractional lead cannot read your cloud console, your identity provider, and your ticketing system directly, every fact they report is second-hand and every evidence request becomes a favour asked of a busy engineer. Read access on day one, granted through your normal joiner process with the same offboarding path as an employee, removes most of the friction.

The third is the silent scope drift where a retainer bought for audit readiness slowly becomes general IT support, vendor negotiation, and answering procurement emails. That is not a betrayal by either side, it is just gravity, and the cure is a monthly written report of where hours went so both parties can renegotiate deliberately rather than discovering the drift at renewal.

The fourth is single-person dependency. Ask what happens if your named advisor is unavailable during an incident, and whether the engagement includes a documented escalation contact. If the answer is vague, the incident response element of the engagement is decorative. Companies with real breach exposure should pair a fractional programme owner with a defined response arrangement, which is one of the reasons our retainer options separate ongoing programme work from incident response coverage.

What to Put in the Contract

A few clauses separate a serious engagement from a monthly invoice. Name the individual, not just the firm, and name the substitute. Set a response time for buyer-driven requests, because a questionnaire that sits for a week costs you deal velocity. Define what happens to the artefacts if you cancel: policies, risk register, evidence, and questionnaire library should be yours in a portable format, held in a system you control rather than a consultant's private workspace. We keep client artefacts in the free traztech Workspace for exactly this reason, so an exit is a permissions change rather than an export project.

Also agree in writing on what the fractional lead will and will not sign. A vCISO can attest to the design and operation of controls they oversee. They should not be signing customer contracts, representing themselves as an employee on your org chart to a buyer who asked whether you have a full-time security officer, or accepting a legally defined accountable-person role in a regime that requires an employee. Being straight with a buyer about the model is a better position than being caught papering over it in a later audit.

When You Should Not Buy Either One

There are situations where hiring security leadership, in any form, is the wrong purchase. If you are pre-revenue with no customer asking security questions, buy nothing and instead do the four things that will be asked of you later: turn on multi-factor authentication everywhere, get secrets out of source control, enable logging with retention, and stop sharing accounts. That costs nothing and removes most of the findings a first assessment would report.

If you have exactly one blocking requirement, usually a customer who wants a SOC 2 report by a date, you may not need ongoing leadership at all. A fixed-scope gap analysis and a defined readiness project, priced up front, answers that requirement without committing to a monthly retainer that outlives the deal. Our fixed-scope pricing exists specifically so a company with one problem can buy one thing.

If your real problem is that nobody can build, you need an engineer rather than an advisor. Plenty of companies come to us for a fractional CISO when the honest diagnosis is that they have good intentions, a written policy set, and nobody with the time or permissions to implement anything. Advisory hours layered on top of an execution shortage produce a very well-documented list of things that never got done.

And if you operate in a sector where a regulator or a major contract obliges you to name an employed, accountable security officer, do not try to satisfy that with a fractional arrangement and hope nobody reads the definition. Get the requirement in writing from the counterparty first, then hire. If you want a straight read on which of these describes your company, our fractional CISO page explains how we scope engagements, and we will tell you when the answer is that you should not buy one.

Making the Handover Work When You Do Hire

The transition from fractional to full-time is where a lot of value gets thrown away. The incoming CISO arrives, decides the previous programme was built wrong, and restarts the risk register from scratch, which costs a quarter and produces a nearly identical document. Two things prevent that. First, hand over a written programme state, current risks with owners and dates, open findings, audit history, and buyer commitments made, rather than a verbal debrief. Second, keep the fractional advisor on a small advisory retainer for one or two quarters with an explicitly narrowed scope, so the new hire has someone to ask about decisions made before they arrived without that person hovering over their programme. Companies that plan the overlap tend to keep their audit dates. Companies that treat the handover as a termination usually slip by a cycle.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.

Fractional CISOOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.