If you searched "virtual CISO" or "fractional CISO," you're probably staring down a security question you can't fully answer yourself: a customer wants proof you take security seriously, a board member is asking who owns your security program, or a SOC 2 auditor just asked for a risk assessment you don't have. This guide explains what the role actually is, in plain language, so you can decide if it's what you need.
What a virtual CISO actually is
A CISO (Chief Information Security Officer) is the executive who owns an organization's security strategy: what gets protected, how, and who's accountable when something goes wrong. Most small and mid-sized companies can't justify a full-time CISO salary, which typically runs well into six figures. A virtual CISO, also called a fractional CISO, does the same job on a part-time or contract basis, working across several client organizations instead of one.
"Virtual" and "fractional" describe the same arrangement. Buyers search both terms interchangeably, and vendors use them the same way. There's no meaningful distinction between the two beyond wording.
The core idea: you get executive-level security leadership without carrying a full-time executive salary, benefits, and the months it takes to recruit one. You're buying expertise and accountability, not headcount.
Who actually needs one
A virtual CISO makes sense for companies in a specific position: security matters enough to need a real owner, but not enough (yet) to justify a full-time hire. That usually describes:
- SaaS companies pursuing a SOC 2 report because an enterprise deal is stalled on it
- Companies that just landed their first large customer and are now fielding detailed security questionnaires
- Startups whose board or investors are asking for a formal security program
- Organizations that had a security incident, or a near-miss, and realized nobody actually owns the response plan
- Companies scaling past the point where "the CTO handles security on the side" still works
If none of that applies yet, you probably don't need one. A virtual CISO is overkill for a five-person company with no customer data and no compliance pressure. It becomes the right call once security decisions start affecting revenue, whether that's a deal you can't close or an audit you can't pass.
What the work actually involves
This isn't a consultant who drops off a PDF and disappears. A working virtual CISO engagement typically covers:
- Program ownership. Someone has to own the security policies, the risk register, and the roadmap, not just write them once and file them away.
- Security questionnaires. Enterprise buyers send these constantly. A vCISO answers them accurately instead of your sales team guessing.
- Audit and certification prep. For SOC 2, ISO 27001, or similar frameworks, the vCISO builds the control set, coordinates evidence collection, and works directly with the auditor.
- Board and leadership reporting. Translating security posture into language a board or investor actually understands, and reporting on it on a regular cadence.
- Vendor and incident response oversight. Reviewing third-party risk, and having an actual plan (and owner) if something goes wrong.
The depth of involvement should scale with the engagement. A few hours a month suits an early-stage company doing basic hygiene. A more intensive arrangement fits a company mid-audit or managing a live incident. Our own fractional CISO service is structured this way: the person leading it is a published security researcher, not someone reading from a framework template, which matters when auditors or customers start asking hard technical questions.
Realistic timeline
Don't expect a security program to materialize in week one. A reasonable pace looks like:
- Weeks 1 to 2: Risk assessment and gap analysis against whatever framework or customer requirement is driving the engagement.
- Weeks 3 to 6: Policies, controls, and a prioritized roadmap built around your actual environment, not a generic checklist.
- Ongoing (monthly or quarterly): Questionnaire responses, board reporting, vendor reviews, and steady progress toward certification if that's the goal.
If you're heading toward SOC 2, the certification itself takes longer than the vCISO setup, usually several months for a Type I report and closer to a year of evidence for Type II. The vCISO's job is to keep that timeline realistic and moving, not to promise a shortcut that doesn't exist.
Common misconceptions
"A vCISO will do all the technical work himself." No. The vCISO sets strategy, owns the program, and coordinates the work. Your engineers still patch systems and configure infrastructure. Think of it as direction and accountability, not a one-person IT department.
"It's the same as hiring a compliance consultant." Related, but not identical. A compliance consultant maps you to a framework's checklist. A vCISO owns the broader security program and keeps working after the audit is done. Framework-specific work, such as our compliance readiness engagements, often runs alongside a vCISO relationship rather than replacing it.
"It's cheaper, so it must be lower quality." The cost difference comes from the fractional structure, not reduced expertise. You're getting the same calibre of leadership a full-time hire would provide, spread across a part-time schedule instead of a full one.
"Once we hit SOC 2, we won't need this anymore." Security programs need ongoing ownership. Certifications require annual renewal, and the risks you're managing don't stop the day you get the report.
Is it right for you
If a customer, auditor, or board member is asking who owns your security program and the honest answer is "nobody, really," that's the signal. A virtual CISO fills that gap without the cost and delay of a full-time executive hire, and gives you a real, accountable answer the next time the question comes up.
Not sure whether your situation calls for a fractional CISO, a focused compliance sprint, or something else entirely? Get in touch and we'll walk through what actually fits your stage and your timeline.
How these engagements are actually structured
Three structures dominate, and the one you choose changes what you get far more than the hourly rate does.
Hours-based retainer. You buy a block of hours per month, typically somewhere between ten and forty, and draw against it. This is the most common arrangement and the easiest to compare across vendors. Its weakness is that it turns every request into a budget conversation, and it rewards the provider for time spent rather than problems closed. If you buy hours, ask what happens to unused time and whether an urgent week can borrow against next month.
Deliverable-based. You agree on a defined set of outputs, a risk register, a policy set, an incident response plan, a questionnaire library, an audit readiness position, with milestone dates. This suits companies with a specific driver such as a stalled deal or an upcoming audit. Its weakness is that it ends, and security programs that end tend to decay.
Outcome retainer. You buy ownership of the program with defined service levels rather than a time budget: questionnaires answered within a set number of business days, a monthly risk review, a quarterly board report, availability for buyer security calls. This is how we structure most ongoing engagements, because the thing a company actually needs is a security owner who answers the phone, not a timesheet.
Our own fractional CISO work starts from $3,000 a month, and the honest driver of price above that floor is the number of frameworks in play, the volume of enterprise security reviews you run, and whether an audit is live. A company doing one framework and two questionnaires a quarter sits near the floor. A company running SOC 2 and ISO 27001 in parallel with weekly enterprise reviews does not.
What belongs in the contract
Most vCISO agreements are two pages and omit the terms that matter when the relationship is under stress. Six items are worth insisting on.
A named individual. Specify the person, not the firm. If they intend to rotate delivery across a bench, you want to know that before you sign, because half the value is one person accumulating context about your environment.
Response commitments. Separate the routine from the urgent. A questionnaire turnaround of five business days is reasonable. A security incident needs a response time measured in hours, and you need to know whether that includes evenings and weekends or costs extra.
Incident authority. Write down what the vCISO can decide alone. Declaring an incident, engaging outside counsel, instructing engineering to isolate a system, and notifying a customer are four different levels of authority and you should be explicit about each.
Document ownership. Policies, risk registers and evidence produced under the engagement should be yours outright, in editable form, on a platform you control. Some providers keep everything inside their own tooling and hand you PDFs at the end, which turns a change of provider into a rebuild.
Conflicts. A fractional CISO works across clients. Ask whether they work with your direct competitors and how they handle that. Most practitioners handle it professionally, and you still want the answer on the record.
Exit and handover. Define notice period and what the handover pack contains. This is the single most useful clause you will negotiate and the one nobody thinks about at signing.
Evaluating a candidate: what to ask
The market for this service is crowded, and the label covers people whose actual capabilities differ enormously. A few questions separate them quickly.
Ask them to walk you through a penetration test report they received on behalf of a client, and what they did with the findings. Someone who owns security programs can talk fluently about triage, risk acceptance, and pushing back on a tester who inflated a severity. Someone selling templates will describe the report rather than the decisions.
Ask what they would tell a customer whose auditor issued an exception. The good answer involves management response, root cause, and a remediation commitment. A weak answer treats it as a failure to be hidden.
Ask how they handle a control the company genuinely cannot meet this year. You want to hear about compensating controls and documented risk acceptance signed by an owner, rather than a promise that everything will be green.
Ask for a reference from a client who left. How a provider talks about an ended engagement tells you what your own exit will look like.
The red flags are consistent. A vCISO who cannot read a cloud architecture diagram will not survive a technical buyer's security call. A provider whose deliverables are a policy pack with another company's name still in the header is selling documents rather than judgment. And anyone who guarantees you will pass an audit is telling you something they cannot know, since the auditor is an independent party with their own opinion.
What a vCISO can and cannot sign
This comes up more often than people expect. A customer contract names a security officer. An insurance application asks for an attestation. A regulator or framework expects a designated role.
In practice a fractional CISO can be named as your security officer for most framework purposes, can sign policies as the approving authority when your leadership delegates that, and can represent your program to auditors and customers. What they generally will not do is sign representations that carry personal or corporate liability on your behalf, such as officer certifications on financing documents or insurance applications where the signature attests to facts across the whole business. Where a statutory role must be held by someone inside the organization, the workable pattern is that a named internal executive holds the role and the fractional CISO does the work and briefs them properly. Sort this out early, because discovering it mid-audit is disruptive.
Making it work internally
The most common reason these engagements underdeliver has nothing to do with the person you hired. It is that the company never gave them the position to be effective.
Decide who they report to. Reporting into engineering creates a conflict, because the security owner ends up asking their own manager to slow down a release. Reporting to the CEO or COO is cleaner and gives the role the standing it needs when it has to say no.
Give them real access. Read access to your cloud console, your ticketing system, your HR onboarding process and your vendor list. A vCISO working from interviews rather than systems will produce a risk register describing the company you think you are.
Put them in the room where product decisions happen, at least monthly. Security input in a design review costs an hour. The same input after launch costs a sprint.
And name an internal counterpart with allocated time for remediation. The vCISO decides what needs to happen and by when. Somebody inside the company still has to do it, and if that capacity does not exist the roadmap will look identical at every quarterly review.
How to tell whether it is working
Judge the engagement on things that move rather than on documents produced. Four measures are enough for most companies.
Time from receipt of a security questionnaire to a returned response, which should fall sharply after the first quarter as the response library fills. Number of deals stalled at security review, which is the number your CEO cares about. Percentage of your remediation roadmap closed on schedule, which tells you whether the internal capacity problem is real. And whether findings are getting harder, meaning your next penetration test surfaces subtler issues than the last one rather than the same missing patches.
If after two quarters your questionnaire turnaround has not improved and the roadmap has not moved, the problem is either the person or the access and authority you gave them. Both are fixable and neither improves by waiting another quarter.
When not to hire one
A fractional CISO is the wrong purchase more often than the market admits, and the alternatives are frequently cheaper.
If you have a single, specific compliance requirement and a modern environment, buy the scoped work rather than the ongoing role. A gap analysis and a readiness engagement will get you to an audit without a retainer, and our fixed-scope pricing exists precisely so companies can buy the piece they need. Auditors also quote a documented environment more cheaply than an undocumented one, so the readiness work tends to pay back part of its own cost, and none of it requires an ongoing seat on your leadership team.
If your real problem is that you do not know your technical exposure, spend the money on testing first. A penetration test starting at $1,000 will tell you more about your risk in two weeks than a quarter of governance work, and the results make any later program work sharper.
If you already have a strong engineering leader with interest and capacity in security, consider advisory sessions rather than a retainer. Several hours a quarter with someone experienced, reviewing decisions and challenging assumptions, is enough for many companies until they cross roughly fifty people or take on a regulated customer.
And do not hire a vCISO to fix a problem that is really a resourcing problem. If your engineering team has no time to patch, harden or build logging, adding a security leader produces a well-documented list of things nobody will do. Fix the capacity first, or accept that the initial deliverable will be a business case for that capacity rather than a completed program.
Moving on from the arrangement
The right end point for most companies is a full-time hire, and it usually arrives with scale rather than with a specific event. Once security work fills more than roughly half a full-time week every week, once you have two or more certifications on annual cycles, or once a customer contract requires a dedicated internal security function, the economics flip.
A good fractional CISO helps with that transition rather than resisting it: writing the role description, sitting on the interview panel, and handing over a program with history intact. Ask what the handover pack contains before you sign anything, and expect it to include the risk register with decision history, policies with revision records, the evidence repository, auditor and vendor relationships with context, and a written statement of what is still unresolved. If a provider is reluctant to describe that pack at the start of the relationship, you have learned something useful about how the end will go.
Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.
Fractional CISOOr talk about a retainer