HireACISO

CISO vs vCISO vs security manager vs CTO

The difference between these roles is not experience. It is who is allowed to accept a risk on behalf of the company, and how many people reports into them. Get those two answers and the title follows.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

A CISO accepts risk for the company and manages a security team. A vCISO accepts risk on the same terms but works four to eight days a month and manages nobody directly. A security manager runs the controls and escalates the risk decision to someone else. A CTO owns building the system, and cannot credibly assure it as well. A DPO is a privacy role with a statutory independence requirement and is not a security job at all. The test: when the company ships with a known vulnerability, whose name is on the decision.

In a startup under 50 people none of these titles exists yet. The question is which of your existing people holds the accountability, and what you buy to support them. That is answered on who owns security when there is no CISO. Read on if you are choosing between roles to fill.

Which role is which

Every row is about authority, not seniority. A very good security manager is often more technically capable than the CISO they report to.

Security leadership roles by decision rights, reporting line and Canadian cost, CAD
Role Accepts risk Manages people Usually reports to Typical Canadian cost
CISO, full time Yes, to the board Yes, 2 to 30 CEO, COO or CIO $220,000 to $400,000 base
vCISO or fractional CISO Yes, recommends and documents No, directs other teams CEO, or the audit committee $3,000 to $12,000 per month
Security manager or head of security No, escalates Sometimes, 1 to 5 CTO or CIO $120,000 to $180,000 base
CTO wearing the security hat Yes, but is also the builder Yes, engineering CEO Free, and the reason auditors ask questions
Privacy officer or DPO No, advises independently Rarely Highest management level $2,000 to $8,000 per month fractional
MSSP or SOC provider No, operates controls Their own staff Whoever holds the contract $2,000 to $15,000 per month

Salary figures are Canadian dollars, base only, bands assembled from posted Canadian job advertisements rather than a survey. The full working, including employer burden and recruiting cost, is on CISO salary in Canada.

Why the CTO cannot be the CISO for long

The person who decides a feature ships is not a credible reviewer of whether it ships safely, and every external party eventually notices. An auditor testing a change management control finds the approver and the requester are the same person. An underwriter asks who signs off on exceptions. A large customer's security team asks who the security officer is and gets the name of the person who wrote the code.

None of those are fatal on their own. Together they are the most common reason a company that was managing fine at 30 people starts losing time at 80. Separating the two accountabilities is often why a vCISO is brought in, and it only works if the vCISO does not report into the CTO. That argument is worked through on who a CISO should report to.

The exception worth naming

A company under about 25 people with a technical founder does not need this separation yet, and creating it early produces meetings rather than security. The line moves when someone external starts asking, usually the first large deal or the first insurance renewal. The vCISO check will tell you if you are not there.

Do you need a leader or a manager?

This is the question most companies get backwards. They hire a leader when the controls are broken, or a manager when the problem is that nobody will make a decision.

  1. Write down the last three security decisions that stalled. If they stalled because nobody knew what to do, you need a leader. If they stalled because nobody had time to do the work, you need hands.
  2. Count the security people you employ. Under two, there is nothing to manage and a manager title is decoration.
  3. Ask who currently answers a customer security questionnaire. If the answer is the CEO or a sales engineer, you need a named owner before you need anything else.
  4. Ask whether an external party has a date attached to their request. A date means program leadership, which is the 20 to 40 hour per month version of the retainer rather than the 8 to 16 hour one.

Most companies of 50 to 200 people need one leader for four to eight days a month and one or two implementers, not a full-time executive. What that costs against hiring is set out on fractional CISO cost, and the total price of standing up the internal version is on the cost of an in-house security function.

What the titles mean on a proposal

Virtual CISO
Remote, retained, usually monthly. The most common Canadian phrasing.
Fractional CISO
The same work, usually with some on-site presence and a seat in the leadership meeting. No standard separates the two terms.
CISO as a service
Firm-delivered rather than person-delivered, with a bench behind the named lead. Better continuity, less consistency of voice. Covered on CISO as a service.
Security advisor
Hourly, no ownership of anything. Useful and cheap, and not a substitute for someone accountable.
Interim CISO
Full time, temporary, filling a gap between two permanent hires. Priced near a salary rather than near a retainer.

Common questions

Is a vCISO less senior than a CISO?

Usually the opposite. A vCISO who serves several companies is often more experienced than a company of 100 people could afford to hire, because they are spreading one senior salary across four or five clients. What they have less of is time and context, which is why the model works for decisions and fails for daily operations.

Can our IT manager just take the CISO title?

They can hold the title, but it does not transfer the decision rights on its own. If the IT manager still reports to the CTO and cannot stop a release, the company has renamed a role rather than filled one. Auditors and underwriters look at the reporting line and the exception log, not the business card.

At what size does a company hire a full-time CISO?

In Canada, most companies cross that line somewhere between 250 and 500 staff, or earlier if they are federally regulated, hold a lot of health data, or have a security team of more than three people to manage. Below that, the work is real but it does not fill a week. The comparison is on vCISO versus a full-time CISO.

Do we need both a CISO and a DPO?

If you are subject to the GDPR and meet one of the Article 37 triggers, you need a DPO and it should not be the same person as your security lead, because Article 38 requires the DPO to be free of instructions and free of conflicting duties. In Canada, PIPEDA requires an accountable individual for privacy but does not require independence, so one person can hold both. The distinction is set out on DPO versus CISO.

Not sure which role you are buying

Describe what stalled and who asked. We will tell you whether it is a leadership problem, a delivery problem or a tooling problem before anyone quotes you.

Get matched