A Chief Information Security Officer (CISO) at a Fortune 500 company earns $300,000-$500,000/year. They manage a team of 20-100 security professionals. They report to the CEO or the board. They are responsible for protecting billions of dollars in assets.
Your 25-person startup does not need that. But you do need what a CISO provides: security strategy, risk management, compliance oversight, and incident response leadership. A virtual CISO (vCISO) gives you all of that for $3,000-$10,000/month. That is exactly what our CISO as a service engagement is.
What a vCISO actually does
A virtual CISO is a part-time security executive who serves as your company's security leader. They typically work 10-30 hours per month and provide:
- Security strategy. They assess your current security posture, identify risks, and create a prioritized roadmap for improvement. This includes choosing the right security tools, defining policies, and setting security architecture standards.
- Compliance management. They lead your SOC 2, GDPR, HIPAA, or ISO 27001 compliance efforts. They know which controls you need, how to implement them efficiently, and how to prepare for audits.
- Risk assessment. They evaluate your threat landscape, identify your most critical assets, and help you allocate security resources where they matter most.
- Vendor security reviews. They evaluate the security posture of your vendors and partners. When an enterprise customer sends you a security questionnaire, they handle it.
- Incident response. They build your incident response plan and serve as the escalation point when security incidents occur.
- Board and investor communication. They present security posture and risk to your board in terms that non-technical stakeholders understand.
When you need one
Three triggers tell you it is time for a vCISO:
Enterprise customers are asking about security. When prospects start sending security questionnaires and requiring SOC 2 reports, you need someone who can manage that process. Your VP of Engineering should not be filling out 200-question security assessments.
You are handling sensitive data. If you process financial data, health records, personal information of EU residents, or any data that is regulated, you need security leadership. The penalties for getting this wrong range from fines to lawsuits to losing your business.
You are scaling past 20 employees. At this size, informal security practices break down. You need documented policies, access management processes, and someone thinking about security architecture as your product grows.
vCISO vs security engineer
A vCISO and a security engineer are not interchangeable. A security engineer is hands-on: they configure firewalls, run penetration tests, implement security tooling, and respond to alerts. A vCISO is strategic: they decide which firewalls to buy, what the penetration test should focus on, which tools to implement, and how to prioritize alert response.
Most startups need the strategic layer first. You can outsource the hands-on work or assign it to your existing engineers. But without someone setting the security strategy, your tactical security investments will be scattered and incomplete.
How to evaluate a vCISO
Look for someone who has worked with companies at your stage and in your industry. A vCISO who has spent their career at Fortune 500 companies may overengineer everything. You need someone who understands startup constraints and can prioritize ruthlessly.
Ask about their experience with the compliance frameworks your customers require. Ask for references from companies similar to yours. Ask how they measure success and what deliverables you can expect in the first 90 days.
Need a virtual CISO?
traztech provides virtual CISO services tailored to startups. We handle security strategy, compliance, and risk management so you can focus on building product.
Book a free strategy callWhat the first 90 days should actually produce
The vaguest thing about a fractional security leader is the deliverable. Strategy is not a document you can hand an auditor or a buyer, so ask for named artefacts with dates against them before you sign anything. A reasonable first quarter produces an asset and data inventory that lists every production system, every place customer data lands, and who owns each one. It produces a risk register with roughly fifteen to thirty entries, each scored, each with a named owner and a decision: fix, accept, transfer, or defer with a review date. It produces a policy set that matches how you actually work rather than a generic library, usually somewhere between twelve and twenty documents covering access control, change management, vendor review, incident response, business continuity, secure development, and acceptable use. It produces a control matrix mapping those policies to whichever framework your buyers are asking about. And it produces a twelve-month roadmap with a budget attached, because a roadmap without a number beside each line is a wish list.
If the first ninety days end with a slide deck and a spreadsheet of "recommendations," you bought advice, not leadership. The difference shows up the first time a buyer asks for evidence. Advice cannot be uploaded to a security review portal.
Where the hours actually go
Ten to thirty hours a month sounds generous until you watch it get consumed. In a typical month with an active enterprise pipeline, a fractional CISO spends four to six hours on buyer security reviews: questionnaires, follow-up calls with the prospect's security analyst, and the redlines their legal team wants on the security schedule of your contract. Another three to five hours goes to evidence upkeep, because control evidence decays. Access reviews go stale, a new subprocessor gets added without anyone updating the list, an engineer spins up a database in a region you do not have documented. Two to four hours goes to vendor reviews as your team keeps buying tools. Two hours goes to the standing meeting with engineering where the roadmap items get weighed against product work. Whatever is left goes to the actual program building.
That arithmetic matters because it explains the most common failure in these engagements. A company signs a ten hour per month retainer, then lands three enterprise deals in the same quarter. The questionnaire load alone eats the entire retainer, the roadmap stops moving, and by month five the founder concludes the engagement is not working. It was working. It was underscoped. Agree in advance what happens when questionnaire volume spikes: either an hours ceiling with overflow billed separately, or a higher base with the expectation that some months are quiet.
Cost drivers nobody quotes you on
The monthly fee is the visible number. Our fractional CISO engagements start from $3,000 per month, and that figure moves for reasons worth understanding before you compare quotes.
Framework count. One framework is a program. Three frameworks is a program plus a translation layer, because every piece of evidence has to satisfy three different vocabularies. If you are carrying SOC 2 and ISO 27001 and a customer-imposed questionnaire standard at once, expect the effort to be higher than the sum of any one of them alone until the control mapping is built and stable.
Environment sprawl. A single AWS account with one production environment is straightforward. Four cloud accounts, a legacy colocated server nobody wants to talk about, a data science team with its own tooling, and two acquired products on different stacks is a different engagement entirely. The control set does not change. The evidence collection does, and evidence collection is where the hours die.
Headcount and turnover. Access reviews, onboarding and offboarding checks, and security training all scale with people. A company hiring twenty people a quarter generates far more control activity than one holding steady at forty staff.
Customer concentration. Ten mid-market customers who accept your SOC 2 report and move on cost almost nothing to service. Two large regulated customers who each run their own annual vendor assessment, request a bespoke penetration test summary, and want a live call with your security lead can consume a quarter of the retainer between them.
Existing debt. If nobody has run an access review in two years, if secrets are in environment files committed to the repository, if there is no logging in production, the first six months are remediation rather than governance. That is real work and it is worth doing, but it is not the same as running an established program and it should not be priced like one.
The access problem
Half the fractional CISO engagements that stall do so for a boring reason: the security leader cannot see anything. They are asked to own the program but given no read access to the cloud console, no seat in the identity provider, no visibility into the ticketing system, and no place in the on-call rotation. They end up interviewing engineers about the state of controls and writing down what they are told, which is a survey, not an assessment.
Decide early what access the role gets. At minimum it should be read-only on the cloud accounts, read access to the identity provider and the endpoint management tool, membership in the engineering ticket system, and visibility into the code repositories. If your legal or investor situation makes external access genuinely impossible, then pair the external leader with an internal engineer who has the access and the time to pull evidence, and budget that person's hours honestly. What does not work is pretending the constraint is not there.
Engagement shapes and how each one fails
Hourly with no minimum. Flexible and cheap-looking. It fails because nobody wants to send the email that starts the clock, so small issues go unraised until they are large issues, and because the provider has no reason to invest in understanding your environment deeply.
Monthly retainer with a fixed hours band. The most common shape and generally the right one. It fails when the band is set from optimism rather than from the pipeline, and when nobody tracks the hours until the relationship is already strained. Ask for a monthly note on hours consumed and what they went to. Not a timesheet, a paragraph.
Fixed-scope project. Right when you have a defined outcome, such as getting a first report done. Our SOC 2 in 75 Days engagement starts from $3,000 for the gap analysis for exactly this reason: the deliverable is knowable, so the price can be. It fails when the company assumes the project fee also covers the year of program operation that follows the audit. It does not, and the gap between the two is where certifications lapse.
Equity or advisory-shares arrangements. Attractive when cash is tight. It fails quietly, because an advisor with equity and no fee has no contractual obligation to respond within any particular window, and security work is exactly the kind of work that gets deprioritized when there is no invoice attached.
What the role cannot do, stated plainly
A fractional CISO cannot certify you. Certification comes from a licensed audit firm for SOC 2 and an accredited certification body for ISO 27001. Anyone who blurs that line is either careless or selling something they cannot deliver. Readiness partners prepare you. Certifying bodies certify you, and they will not do both for the same client because independence rules forbid it.
A fractional CISO is also not a substitute for hands on keyboard. Somebody still has to rotate the keys, configure the logging pipeline, patch the base images, and fix the findings from the penetration test. If you have no engineer who can absorb that work, the roadmap will be beautifully written and entirely unexecuted. Budget implementation capacity alongside the leadership, whether that is your own engineers' time or an outside team.
And a fractional CISO is not a twenty-four hour incident response function unless you have explicitly paid for that. A ten hour monthly retainer does not include being woken at three in the morning. If breach response coverage matters to you, buy it deliberately and check the response commitment in writing, including what happens when your named person is on holiday.
When you should not hire one
There are three situations where we will tell you to keep your money.
You have fewer than about ten people and no regulated data and no enterprise buyer asking. You do not have a security governance problem yet. You have a hygiene problem, and hygiene is cheap: turn on multi-factor authentication everywhere, move secrets into a manager, enable logging, back things up and test one restore, and write a one-page incident plan with three phone numbers on it. That is a fortnight of an engineer's attention, not a monthly retainer. Come back when a buyer starts asking questions or when you start handling data that would hurt someone if it leaked.
You already have a strong engineering leader who wants the role. Some VPs of Engineering are genuinely good at this and want to grow into it. If that is your situation, the better spend is a short advisory arrangement, a few hours a month for six months, to give that person a sounding board and a structure. Paying an outsider to own something your own leader wants to own creates a turf problem and wastes both budget lines.
The only reason you are considering it is that one deal wants a name in a box. If a single prospect asked "who is your CISO" and that is the whole motivation, buy the narrow thing instead. A one-off security review of that buyer's requirements, a gap analysis, and help answering the questionnaire will move that deal for a fraction of an annual retainer. If a second and third buyer ask the same question, the economics change and you can start the retainer then, having lost nothing.
The version of this that we do turn down outright is the request to be listed as your security officer without any of the underlying work. It shows up more often than you would think, usually phrased as needing a name for a contract clause. A name on a document with nobody behind it is the sort of thing that looks fine right up until an incident, at which point it becomes a very expensive line in a legal filing.
Handing over to a full-time hire
The engagement should be designed to end. Most companies reach a point, usually somewhere between eighty and a hundred and fifty staff or when security work exceeds roughly two full days a week, where a permanent hire is the better economics. Plan for it from the start.
That means insisting that everything produced belongs to you and lives in your systems, not the consultant's. Policies in your document store. Risk register in your tooling. Evidence in a repository your team controls. If the artefacts only exist in the provider's platform and leave when they do, you have rented compliance rather than built it. Our clients keep their program in the traztech Workspace, which is free and stays with them whether or not they keep working with us, precisely because the alternative creates a hostage situation nobody benefits from.
It also means the fractional leader should help you write the job description and sit on the interview panel for their own replacement. A good one will push you towards that hire before you ask. Watch for the opposite behaviour, an advisor who keeps the program slightly opaque and the documentation slightly incomplete, because that is how a retainer becomes permanent for the wrong reasons.
Measuring whether it is working
Avoid metrics that measure activity. Number of policies written and hours logged tell you nothing about risk. Four measures actually indicate whether the money is doing something.
Time from questionnaire received to questionnaire returned. If it was three weeks before the engagement and it is four days after, the commercial value is obvious to your sales team, which is also how you keep the budget approved.
Number of deals delayed or lost on security grounds. Track it, because it is the number your board understands. One documented readiness position took $11,000 off a client's audit quote, and the same discipline is what stops a deal sliding a quarter.
Open findings older than their due date. Not total findings, which mostly measures how hard you are looking. Overdue ones, which measure whether the program has teeth.
Time to detect and time to contain, measured on real events. Not tabletop exercises alone. The first genuine incident, even a minor one, will tell you more about your program than a year of documentation. If nobody can answer how long the intruder had access or which accounts were touched, the logging work is not finished regardless of what the control matrix says.
If you want to talk through which of these shapes fits your situation, the fractional CISO page sets out how we scope it, and pricing lists what the fixed-scope alternatives cost if a project turns out to be the better answer than a retainer.
Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.
Fractional CISOOr talk about a retainer