CISO vs vCISO vs security manager vs CTO
The difference between these roles is not experience. It is who is allowed to accept a risk on behalf of the company, and how many people reports into them. Get those two answers and the title follows.
A CISO accepts risk for the company and manages a security team. A vCISO accepts risk on the same terms but works four to eight days a month and manages nobody directly. A security manager runs the controls and escalates the risk decision to someone else. A CTO owns building the system, and cannot credibly assure it as well. A DPO is a privacy role with a statutory independence requirement and is not a security job at all. The test: when the company ships with a known vulnerability, whose name is on the decision.
In a startup under 50 people none of these titles exists yet. The question is which of your existing people holds the accountability, and what you buy to support them. That is answered on who owns security when there is no CISO. Read on if you are choosing between roles to fill.
Which role is which
Every row is about authority, not seniority. A very good security manager is often more technically capable than the CISO they report to.
| Role | Accepts risk | Manages people | Usually reports to | Typical Canadian cost |
|---|---|---|---|---|
| CISO, full time | Yes, to the board | Yes, 2 to 30 | CEO, COO or CIO | $220,000 to $400,000 base |
| vCISO or fractional CISO | Yes, recommends and documents | No, directs other teams | CEO, or the audit committee | $3,000 to $12,000 per month |
| Security manager or head of security | No, escalates | Sometimes, 1 to 5 | CTO or CIO | $120,000 to $180,000 base |
| CTO wearing the security hat | Yes, but is also the builder | Yes, engineering | CEO | Free, and the reason auditors ask questions |
| Privacy officer or DPO | No, advises independently | Rarely | Highest management level | $2,000 to $8,000 per month fractional |
| MSSP or SOC provider | No, operates controls | Their own staff | Whoever holds the contract | $2,000 to $15,000 per month |
Salary figures are Canadian dollars, base only, bands assembled from posted Canadian job advertisements rather than a survey. The full working, including employer burden and recruiting cost, is on CISO salary in Canada.
Why the CTO cannot be the CISO for long
The person who decides a feature ships is not a credible reviewer of whether it ships safely, and every external party eventually notices. An auditor testing a change management control finds the approver and the requester are the same person. An underwriter asks who signs off on exceptions. A large customer's security team asks who the security officer is and gets the name of the person who wrote the code.
None of those are fatal on their own. Together they are the most common reason a company that was managing fine at 30 people starts losing time at 80. Separating the two accountabilities is often why a vCISO is brought in, and it only works if the vCISO does not report into the CTO. That argument is worked through on who a CISO should report to.
The exception worth naming
A company under about 25 people with a technical founder does not need this separation yet, and creating it early produces meetings rather than security. The line moves when someone external starts asking, usually the first large deal or the first insurance renewal. The vCISO check will tell you if you are not there.
Do you need a leader or a manager?
This is the question most companies get backwards. They hire a leader when the controls are broken, or a manager when the problem is that nobody will make a decision.
- Write down the last three security decisions that stalled. If they stalled because nobody knew what to do, you need a leader. If they stalled because nobody had time to do the work, you need hands.
- Count the security people you employ. Under two, there is nothing to manage and a manager title is decoration.
- Ask who currently answers a customer security questionnaire. If the answer is the CEO or a sales engineer, you need a named owner before you need anything else.
- Ask whether an external party has a date attached to their request. A date means program leadership, which is the 20 to 40 hour per month version of the retainer rather than the 8 to 16 hour one.
Most companies of 50 to 200 people need one leader for four to eight days a month and one or two implementers, not a full-time executive. What that costs against hiring is set out on fractional CISO cost, and the total price of standing up the internal version is on the cost of an in-house security function.
What the titles mean on a proposal
- Virtual CISO
- Remote, retained, usually monthly. The most common Canadian phrasing.
- Fractional CISO
- The same work, usually with some on-site presence and a seat in the leadership meeting. No standard separates the two terms.
- CISO as a service
- Firm-delivered rather than person-delivered, with a bench behind the named lead. Better continuity, less consistency of voice. Covered on CISO as a service.
- Security advisor
- Hourly, no ownership of anything. Useful and cheap, and not a substitute for someone accountable.
- Interim CISO
- Full time, temporary, filling a gap between two permanent hires. Priced near a salary rather than near a retainer.
Common questions
Is a vCISO less senior than a CISO?
Usually the opposite. A vCISO who serves several companies is often more experienced than a company of 100 people could afford to hire, because they are spreading one senior salary across four or five clients. What they have less of is time and context, which is why the model works for decisions and fails for daily operations.
Can our IT manager just take the CISO title?
They can hold the title, but it does not transfer the decision rights on its own. If the IT manager still reports to the CTO and cannot stop a release, the company has renamed a role rather than filled one. Auditors and underwriters look at the reporting line and the exception log, not the business card.
At what size does a company hire a full-time CISO?
In Canada, most companies cross that line somewhere between 250 and 500 staff, or earlier if they are federally regulated, hold a lot of health data, or have a security team of more than three people to manage. Below that, the work is real but it does not fill a week. The comparison is on vCISO versus a full-time CISO.
Do we need both a CISO and a DPO?
If you are subject to the GDPR and meet one of the Article 37 triggers, you need a DPO and it should not be the same person as your security lead, because Article 38 requires the DPO to be free of instructions and free of conflicting duties. In Canada, PIPEDA requires an accountable individual for privacy but does not require independence, so one person can hold both. The distinction is set out on DPO versus CISO.
Not sure which role you are buying
Describe what stalled and who asked. We will tell you whether it is a leadership problem, a delivery problem or a tooling problem before anyone quotes you.
Get matched