Skip to content

Cybersecurity CISO

What Is a vCISO

When the conversation turns to security leadership, business owners give one of two answers: they cannot afford a CISO, or they point to Jon who games on weekends and built the network. Neither answer is a security strategy.

Illustration for the article: What Is a vCISO
When the conversation turns to security leadership, business owners give one of two answers: they cannot afford a CISO, or they point to Jon who games on weekends and built the network. Neither answer is a security strategy.

In seventeen years of working with businesses on their technology and security, I have come across exactly one company that had a full-time Chief Information Security Officer on payroll. One. They have been in business for years, employ over 5,000 people, and only made that hire within the last year.

Every other organization I have walked into has handled security one of two ways.

The Two Answers Every Business Owner Gives

When the conversation turns to security leadership, it almost always ends in one of two places.

Option one: “There is no way I am paying for a CISO. I could pay all my employees for six months for what one person costs in a year.”

They are not wrong about the number. A full-time CISO costs $200,000 to $350,000 in base salary – and when you add benefits and bonuses, the total compensation often lands between $250,000 and $500,000 annually. For a 50-person business, that is not a hire. That is a budget category that does not exist.

Option two: “Can’t Jon do this? He and his buddies game every weekend, he built most of what you see here, and we never have issues. I’ll give him a bonus to offset some of his time.”

Notice what is not in either of those answers. Nobody is asking what a security leader actually does. Nobody is asking where to find one or what it would cost. The conversation jumps straight to “can’t afford it” or “we already have someone” – and in both cases, the organization ends up with the same result: no real security leadership.

The Problem With Jon

Jon is not the problem. Jon probably knows his way around a network better than most. He cares about the systems he built and he keeps things running.

But there is a question I like to ask business owners when they point to Jon as their answer.

If I walked you down to your shop floor right now and asked you to rebuild that transmission on the table – could you do it?

Ninety-nine times out of a hundred the answer is no. And when I ask why not – you own this business, shouldn’t you know every aspect of it? – the answer is always some version of the same thing:

“They went to school for that. They specialize in it. I went to business school. I pay them for what they know so I can focus on what I do.”

That right there is the answer. The word is specialized.

A vCISO is a professional who lives and breathes cybersecurity. They are not maintaining the network between other responsibilities. They are not learning security concepts on the weekend between gaming sessions. They are making the critical security decisions – clear, strategic, defensible decisions – while managing every thread that keeps an organization protected.

Jon keeps the lights on. A vCISO decides which lights should exist, who should be allowed to turn them on, and what happens when one of them fails.

Why the vCISO Model Exists

The Virtual CISO – vCISO – model exists because most organizations need strategic security leadership but cannot justify a full-time executive hire to provide it. The solution is fractional, on-demand leadership: a seasoned security executive who works with your organization on a retainer or project basis, at a fraction of what a full-time hire would cost.

The pricing works like this:

Monthly retainer: The most common model, typically ranging from $3,000 to $15,000 per month depending on hours and scope. A retainer might cover policy development, vendor oversight, compliance management, risk assessments, and ongoing advisory work.

Hourly engagement: Usually $200 to $400 per hour, appropriate for specific consultations or ad hoc projects.

Project-based: Ranges from $5,000 to $50,000 or more for discrete engagements like gap assessments, SOC 2 readiness, or incident response planning.

Compare the high end of a vCISO retainer – $180,000 annually – against the low end of a full-time CISO salary. You get strategic executive leadership, without the benefits package, the office, or the full-time headcount.

Stay Ahead of Technology Risk

Practical, no-jargon insights on cybersecurity, resilience, and IT strategy - built for business leaders, not engineers.

What a vCISO Actually Does That Jon Cannot

Here is where the conversation gets important.

When an organization brings in a vCISO, two things have already happened. First, leadership has acknowledged that there is a problem and it needs to be addressed. Second, the administrative staff has put their authority behind fixing it.

Those two things sound simple. They are not. And without both of them, no security program – vCISO or otherwise – can function.

Here is why.

Imagine Jon walks into a meeting and tells the team that starting Monday, everyone must log into every computer with a unique username, a strong password, and MFA. No exceptions. No shared logins. No leaving sessions open.

What happens? There is friction. There are complaints. People say it slows them down. Someone says Jon is just on a power trip, pushing policies that sound cool because they give him a god complex. And because Jon does not have the organizational authority to enforce the policy, the rollout stalls, the exceptions multiply, and six months later nothing has changed.

Now imagine the same policy coming from a vCISO whose engagement was authorized by the owner, backed by the leadership team, and framed as a non-negotiable operational requirement – not a suggestion from the guy who also fixes the Wi-Fi when it goes down.

The policy lands differently. The enforcement holds. The organization moves.

That is the real difference. A vCISO can walk into a business and require that passwords change every 45 days, that access is restricted to only what each role actually needs, that global admin accounts are eliminated because convenience is not a security strategy. They can require those things because leadership has already said: we brought this person in because we acknowledged there was a problem, and we are backing the solution.

You cannot fix what you do not know is broken. And if you do not know it is broken, you do not know to fix it. The vCISO engagement begins the moment an organization admits both of those things out loud.

Who Actually Needs a vCISO

Not every organization is ready for a vCISO. And not every organization needs one on retainer.

But if any of the following are true, the conversation is worth having: – You have customer data, financial records, or operational systems that would be catastrophic to lose or expose – You are subject to regulatory requirements – FTC Safeguards, HIPAA, PCI-DSS, state breach notification laws – and you are not certain you are compliant – Your cyber insurance application was filled out by someone who was guessing – You have an IT provider but no one internally who owns security strategy – You have had an incident – even a small one – and nobody knew what to do – You are growing and your security posture has not kept pace

The vCISO is not a luxury for organizations that have already figured everything out. It is a resource for organizations that are honest enough to admit they have not – and smart enough to understand that admitting it is the first step toward fixing it.

The Transmission Analogy, Revisited

You would not let the business school owner rebuild the transmission just because he owns the shop. You would not ask the dispatcher to handle the accounting just because she is sharp and picks things up quickly. You pay specialists for what they know because that specialization is the thing that keeps the business running.

Security is no different. The question is not whether you can afford a vCISO.

The question is whether Jon – with his full-time job, his weekend gaming, and his zero organizational authority – is actually the answer to a problem this important.

Kelly Hansen is the author of The IT Dilemma: Why Good Businesses Fail During Cyberattacks, Outages, and Technology Disasters – and How to Prevent It. Have a question about your own environment? Reach out: Contact, or connect with me on LinkedIn.

Related reading: The Insurance Trap

Key Takeaways

  • In seventeen years of IT work I have come across exactly one company with a full-time CISO on payroll
  • Jon keeps the lights on — a vCISO decides which lights should exist, who should be allowed to turn them on, and what happens when one fails
  • You cannot fix what you do not know is broken — and if you do not know it is broken you do not know to fix it
  • A vCISO engagement only works when leadership has admitted there is a problem and put their authority behind the solution
  • The question is not whether you can afford a vCISO — it is whether Jon with his weekend gaming and zero organizational authority is actually the answer