
When a vCISO makes sense
A virtual CISO is a senior security leader engaged part-time, usually on a retainer, to do the work a chief information security officer would do: set direction, own the risk picture, make judgement calls, and represent security to the board, customers and regulators.
The question is not whether that work needs doing (in most organisations of any size it does) but whether a fractional arrangement fits better than a hire, and when that stops being true.
The situation it usually fits
You need the decisions, not the hours. The genuinely CISO-level work in a mid-sized organisation is not forty hours a week. It is a set of decisions, a governance rhythm, and availability when something happens. Buying a fraction of a senior person's time is a better match than buying all of a less experienced one's.
You have engineers but no one setting direction. A common and frustrating position: capable technical people, tools in place, and no coherent view of what the organisation is trying to achieve or in what order. Adding another engineer does not fix it.
Customers or regulators have started asking. Enterprise procurement, a certification requirement, an insurer's questionnaire, a sector regulator. These demand someone who can own the answers and be credible in the conversation. The requirement arrives faster than a hiring process can respond to it.
You are preparing for certification or a major assessment. Concentrated senior effort for a period, followed by a lighter ongoing load. That shape suits a retainer and does not suit a permanent hire.
A permanent CISO would be under-employed and hard to retain. A senior person hired into a role without enough scope tends to leave within eighteen months, and you have then paid a full salary and a recruitment fee for a gap.
The situation where it does not fit
You need hands on keyboards. If the actual problem is that nobody is patching, monitoring or responding, a vCISO will tell you that clearly and it will not solve it. That is an operational capacity problem, and it needs engineers or a managed service.
Security is genuinely core to the product. If you sell to customers whose primary concern is your security posture, or if a breach would be existential, the role probably warrants a full-time owner who is present in every significant decision.
Nobody internal can act. A vCISO produces direction, decisions and priorities. If there is no one to implement them, the output accumulates as unactioned advice, and both sides become frustrated. There needs to be at least one internal person with time and authority.
You want someone to blame. Accountability cannot be outsourced. A vCISO takes on responsibility for advice and direction; the organisation retains accountability for the risk it carries.
What the arrangement should actually include
Retainers vary widely, which makes them hard to compare. A reasonable one covers:
- A defined time commitment, stated in days per month rather than left vague.
- Governance rhythm: a regular risk review, and attendance at whatever forum makes decisions.
- Ownership of the risk register, including keeping it current rather than producing it once.
- Incident escalation, with defined availability. What happens if something serious occurs outside the agreed days is worth pinning down.
- Board and customer representation: being available for the conversations that need a credible senior voice.
- A stated plan with priorities, so that progress can be measured against something.
What it typically does not include, and should be explicit about: implementation work, day-to-day operations, and unlimited availability.
Judging whether it is working
Six months in, the useful questions are not about activity.
- Is there a risk picture that leadership recognises and believes?
- Has the organisation said no to something, or accepted a risk deliberately, on the basis of that picture?
- Can the business answer customer security questions without a scramble?
- Do the internal team know what they are working on next and why?
- Has anything actually changed, or is there just more documentation?
That last one is the honest test. A vCISO engagement that has produced a policy set and a register but no change in what the organisation does has not delivered.
When to move to a full-time hire
The signals are reasonably clear:
- The retainer keeps overrunning, and the conversation is regularly about scope rather than substance.
- Security decisions are needed faster than the agreed rhythm allows.
- The organisation has grown to where the role is genuinely full-time.
- A regulator or major customer expects a named, full-time executive.
The transition is often smoother than expected, because a good vCISO engagement leaves behind the artefacts a new hire needs: a current risk picture, a plan, and a functioning governance rhythm. Handing that over is a legitimate outcome of the arrangement rather than a failure of it.
The realistic summary
A vCISO fits organisations that need senior security judgement more than they need senior security hours, that have someone internal able to act on direction, and that face external expectations arriving faster than a hiring process can satisfy.
It does not substitute for operational capacity, and it does not transfer accountability. Engagements that disappoint are almost always ones where one of those two things was assumed.
Want this looked at in your own environment?
Talk to an expert →Keep reading


