Do you need a vCISO? A six question check
This will tell you not yet if the answer is not yet, which is the answer for a lot of the companies that land here. When it does say yes it names the engagement model and the Canadian dollar band that goes with it.
Buying security leadership before there is a security program to lead is a common and expensive mistake, and it is the one this exists to prevent. Six questions, then a straight answer: not yet, buy one thing once, or buy a retainer of a particular size.
Nothing is emailed anywhere unless you ask at the end. The answer appears on this page.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
How this decides
Four things move the answer, roughly in that order of weight: whether something external is forcing the issue, what you hold, how much internal capacity exists to act on advice, and how much of a program already runs. Headcount is the weakest of the signals and it is the one most people rely on, which is why a forty person company selling to hospitals and a four hundred person company selling to other software firms can come out in opposite places.
Two rules override the arithmetic. A real incident moves the answer up regardless of everything else, because after a compromise the question stops being whether you can justify the spend. And nothing external plus a company under twenty people returns not yet no matter what else is ticked, because at that size the decisions are few and the money is better spent on the groundwork.
If it says not yet
Then take it at face value. The work worth doing instead costs almost nothing, does not expire, and counts toward any framework you later need: multi-factor authentication everywhere including the domain registrar and the cloud root account, a written list of who has access to what reviewed quarterly, a backup you have actually restored, endpoint detection someone looks at, a two page incident response plan with real phone numbers, a named individual accountable for privacy as PIPEDA requires, and a breach record register kept for 24 months. The longer version of that reasoning is worth reading if a board or an investor is pushing back.
Common questions
Does this tool ever actually say no?
Yes, and for a meaningful share of the companies that reach it. A company under twenty people with nothing external forcing the question gets not yet regardless of what else is ticked. So does a company with a program already running, current documents and a security engineer internally, because what that company needs is occasional advice rather than an owner on a retainer.
Why does holding health data change the answer so much?
Because PHIPA and its provincial equivalents create duties that follow the data rather than scaling with your headcount. Holding personal health information on behalf of an Ontario custodian usually makes you an agent under that Act. A twelve person company in that position has real obligations on day one, which is not true of a twelve person company selling project management software.
We failed a security review. Does that mean we need a retainer?
Not necessarily. A failed review often needs a fixed-scope engagement that produces the missing artifacts and a named contact for the duration, at $15,000 to $40,000 CAD, rather than an open-ended monthly fee. Buy the retainer when there is a program to run between events, not to solve a single event.
What if we disagree with the answer?
The most common reason to disagree is that something external is pressing that the six questions did not capture, such as an acquisition in progress or a contract clause with a deadline in it. Those move the answer up. The second most common reason is wanting to buy reassurance, and that is the case where taking the answer at face value saves the most money.