HireACISO

How to get vCISO clients

A vCISO client is a retainer, so one signature is worth 12 to 36 months of revenue. That changes what you can afford to spend to win one, and it makes churn matter more than win rate.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

Most fractional security leadership work in Canada is signed through people who already know the practitioner: former colleagues, past clients, and partner firms that cannot do the work themselves. Everything else on this page exists because those three run out. At a retainer of $3,000 to $12,000 CAD a month over a life of 12 to 36 months, a signed client is worth $36,000 to $432,000 CAD, with the middle of the market near $108,000 CAD. Spending $5,000 to $10,000 CAD to win one is defensible arithmetic.

$108,000 Typical lifetime value of one vCISO client, CAD

12 to 36 Months a retainer usually runs

This page is for the firms and independents in this directory, not the companies hiring them. We operate the directory and sell listings on it, so read the directory section knowing that.

Why retainer work changes the acquisition maths

A penetration testing firm selling a $14,000 CAD engagement cannot spend $8,000 acquiring the client. The engagement ends and the cost repeats. A vCISO pays it once and bills every month until somebody cancels.

So the number that governs a fractional practice is churn, not win rate. Average client life is roughly one divided by monthly churn, and that ratio moves lifetime value faster than any sales improvement.

Client lifetime value at a $6,000 CAD monthly retainer, by monthly churn
Monthly churn Average client life Lifetime value (CAD) Affordable acquisition cost at 10 percent of value
3 percent33 months$198,000$19,800
5 percent20 months$120,000$12,000
8 percent12 months$72,000$7,200
12 percent8 months$50,000$5,000
What this saysHalving churn is worth more than doubling your close rate, and it costs nothing to sell.

That is a standard retention model applied to the Canadian retainer bands on vCISO pricing, not a survey. Run it on your own book. Most fractional practices have never calculated their churn, which is why the quarter after a cancellation goes into building a funnel instead of asking why the client left.

Retainers do not churn randomly

They cancel at three predictable moments: the month after the certification the engagement was bought for is achieved, the first budget cycle after a new CFO or CTO arrives, and the renewal that follows a quarter where nobody could say what the retainer produced. All three are visible weeks in advance. A retainer sold as the route to a SOC 2 report has no reason to continue once the report exists, and that is the one most practices walk into.

Where does vCISO work actually come from?

Work in cost per signed client, not cost per lead. Most marketing advice reports the second number. A fractional engagement takes three to six conversations with two or three people before anybody signs, so the gap between the two is large.

Client acquisition channels for a Canadian fractional security practice, CAD, 2026
Channel Cost per signed client Close rate Scales Time to first client
Former colleagues and past employer networkNear zeroVery highNo0 to 3 months
Referral from a current retainer clientNear zeroHighNo6 months and up
Partner referral from an MSP, MSSP, CPA firm, insurer or law firm10 to 20 percent of year oneHighSomewhat3 to 9 months
Fractional executive platform or talent network20 to 35 percent of every invoiceMediumYes1 to 4 months
Cold outbound run by the principal$4,000 to $12,000 in timeLowYes3 to 6 months
Outsourced outbound and appointment setting$10,000 to $30,000Very lowYes3 to 9 months
Speaking to a CISO peer group or industry association$2,000 to $8,000 in timeMediumNo2 to 6 months
Conference sponsorship$10,000 to $40,000LowNo3 to 12 months
Your own writing and searchHigh upfront, near zero laterMediumYes6 to 18 months
Paid search$5,000 to $15,000MediumYes1 to 3 months
Directory listing$600 to $4,000MediumCappedUnpredictable
The patternWith a client worth $36,000 to $432,000 CAD, none of these is too expensive. The cheap channels do not scale and the scalable ones close badly, and no amount of money changes that trade.

Those figures assume a retainer of $3,000 to $12,000 CAD a month, where Canadian mid-market work sits. At four hours a month for $1,500, paid search and conference sponsorship stop making sense long before the other channels do.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

The channel that produces your first clients

An independent who has just left a security leadership role starts with several hundred people who have watched them do the job. It is worth more than any funnel and it is almost always underworked, because asking former colleagues for work feels like an imposition.

It is not. The people best placed to hire a fractional CISO already know they need security leadership and have been told they cannot have a full-time hire. Working that list is the subject of your first ten vCISO clients, including what to charge before you have a reference.

Partner referrals, and the firms that cannot compete with you

The most underused channel in Canadian fractional security is the firm that sits next to the work and is barred from doing it. Independence rules stop a CPA firm that signs a SOC 2 opinion from building the control set for the same client. A managed service provider running a client's infrastructure cannot credibly own the risk decisions about it. A cyber insurance broker whose client just failed underwriting on a control question has nobody to hand them to, and neither does a litigator whose client has just been breached.

All four have clients who need a vCISO and cannot sell one. That is worth 10 to 20 percent of first year revenue, and it is durable in a way outbound is not: a partner who has been paid once calls again.

The partner conversation that goes wrong most often is with an MSSP, which usually believes it already provides security leadership. Answering that is on positioning against MSSPs.

Cold outbound and the CASL constraint

Outbound works for fractional security leadership, badly. It works when it names a specific situation the reader is in, and those situations are visible from outside the company.

  1. Pick a trigger you can see: an announced US large customer, a funding round, a posted security engineer role with nobody above it, a breach notification, or the departure of the one person who held security.
  2. Write to the person the trigger lands on. For a company under 200 people that is a CTO, a COO or a founder, not a CISO, because if there were a CISO they would not need you.
  3. Say what you think their situation is in one sentence, and be willing to be wrong in public.
  4. Offer something bounded. A paid assessment or a 45 minute review of their security questionnaire converts far better than an open-ended retainer pitch, because nobody signs a 24 month commitment off a cold email.
  5. Stop after three attempts. The fourth does not convert and it costs the domain reputation you will want next year.

CASL applies and is stricter than the American equivalent. It requires express or implied consent for commercial electronic messages, an identifiable sender and a working unsubscribe, and the implied-consent grounds most B2B outbound advice assumes are narrower than they look. The carve-out that helps a new independent is the existing business relationship, which covers people you have done business with, so your former employer's vendor list is fair game in a way a purchased list is not. Read the rules before buying anything.

Writing, and what to write about

Publishing what you know is the only channel that gets cheaper over time, and the slowest to start. Six to twelve months before the first enquiries, then it keeps producing them at almost no ongoing cost.

The mistake is writing about your methodology. Nobody searches for it. They search for what something costs, whether they need it, and which of two things to buy. Here that means the price of a retainer, whether a fractional CISO can be named in a customer contract, what PIPEDA requires of a named accountable individual, and how a large buyer's security questionnaire gets answered. Put a real number in the first paragraph and say what your competitors will not.

Directories, including this one

We sell listings on this directory, so weigh what follows accordingly.

A directory is a capped channel. It produces the enquiries the site produces and no more, and a better position in a list nobody visits buys nothing. Ask any directory how much traffic it has, then whether its enquiries are people who have already decided to buy.

What a directory is good at is intent. Somebody comparing four fractional CISOs on a listing page has decided to buy security leadership and is choosing who provides it. That is later than a cold email reaches, which is why the close rate holds up and the volume does not.

This directory, at current traffic

It is new and has no meaningful traffic yet. A free listing costs nothing. The paid Verified tier is $300 CAD a month or $3,000 CAD a year, and at current traffic it does not pay for itself. It will when the traffic is there.

Take the free tier today. Claim a listing and decide about the paid one when there is something to decide.

What to do first, by size of practice

With fewer than five retainer clients, work the personal network and the partner channel and publish nothing. You do not have enough finished engagements to say anything a reader cannot get elsewhere, and a partner referral is the fastest route to client five.

Between five and fifteen, the constraint becomes capacity. Fifteen retainers is most of one person's week, so the practice either raises its rate or hires. What to charge and how to structure the hours is on pricing a vCISO retainer.

Past fifteen, the question is whether the practice can add people without adding the founder to every engagement. Coming from a project consultancy rather than an in-house role, the conversion problem is different and has its own arithmetic in from project work to retainer, including the case for staying on projects.

Be in the directory

A free listing puts your practice in front of the people using this site to choose one. It stays free, you edit it yourself, and matched enquiries cost nothing.

List your firm

Common questions

How much can I afford to spend to win a vCISO client?

Roughly 10 percent of lifetime value, which at a $6,000 CAD monthly retainer running 20 months is about $12,000 CAD. That is far more than a project-based security firm can spend, because the retainer keeps billing after the acquisition cost is paid. Work out your own number by multiplying your average retainer by one divided by your monthly churn.

How long does it take to sign a fractional CISO client?

Three to six conversations over four to twelve weeks for a first retainer, involving two or three people. It is slower than project work because the buyer is committing to a recurring line in the budget and usually needs a finance or board approval that a one-off assessment does not require. Selling a paid assessment first shortens this considerably.

Is a directory listing worth paying for as a vCISO?

Only if the directory has traffic, which is the number to ask for before paying anyone. The arithmetic is easy when it works, since one client worth $100,000 CAD covers years of any listing fee. The risk is not the price, it is that a listing on a site without visitors returns nothing at any price. Ask for traffic figures and treat a refusal as an answer.

Should I join a fractional executive platform?

It is a reasonable way to fill capacity early and a bad way to build a practice. Platforms take 20 to 35 percent of every invoice for the life of the engagement, not just the first year, and they usually hold the client relationship. Use one to survive a slow quarter, and do not let it become the channel that most of your revenue depends on.

Can I cold email Canadian companies about vCISO services?

Only with consent under CASL, which requires express or implied consent, an identifiable sender and a working unsubscribe. The implied-consent grounds are narrower than most American outbound advice assumes, though the existing business relationship ground does cover people and companies you have genuinely done business with before. The penalties are meaningful, so read the rules rather than a template.