vCISO ROI calculator, Canadian dollars
Five questions, then three columns in Canadian dollars: what a vCISO retainer would cost you, what hiring would really cost in the first year, and what deferring the decision moves rather than saves.
The comparison a board asks for is almost always the wrong one, because it puts a monthly retainer next to a base salary. The retainer is the whole cost and the salary is roughly half of it. This works out both properly, in Canadian dollars, and is explicit about where the compensation figures come from.
Nothing is emailed anywhere unless you ask at the end. The numbers appear on this page.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
Where the compensation numbers come from
There is no large, published, Canadian-specific salary survey for the chief information security officer role, and any tool that implies otherwise is inventing precision. The bands used here are assembled from posted Canadian executive security roles, recruiter guidance for the Canadian market, and the compensation structure that Canadian employers actually use. They are ranges, they are Canadian dollars, and the top of each band sits with Toronto financial services while the bottom sits with smaller markets and non-regulated sectors.
| Component | Assumption | Why |
|---|---|---|
| Base salary | $170,000 to $350,000 | Varies with company size, sector and city. Set by the size you chose |
| Bonus | 15 to 25 percent of base | Standard executive short-term incentive range at this level |
| Employer burden | 15 to 20 percent of base | CPP and EI contributions, health benefits, retirement match, employer-paid insurance |
| Recruiting | 20 to 30 percent of base | Executive search fee, or the internal time if you run it yourself. A first-year cost either way |
| Training and certifications | $5,000 to $15,000 | Conferences, certification maintenance, professional membership |
| Search and ramp | Not costed, but stated | A Canadian security executive search commonly runs three to six months, and the first 90 days are assessment. The salary column buys less delivery in year one than it looks like |
Equity is deliberately excluded. It is real compensation and it is not cash in the first year, so including it would inflate a comparison that is meant to be about budget. The retainer column has no equity component at all, which is itself part of the argument in either direction.
Why the third column has no scary number in it
Plenty of calculators put a breach cost in this column, multiplied by a probability, and produce a figure with two decimal places. Nobody can support that number for your company, and a board that has seen one such slide discounts every number that follows it.
What can be said honestly is that deferring does not reduce the cost of the program, it moves it. The audit fee, the platform, the penetration test and the remediation engineering are the same numbers next year, usually bought under more time pressure and therefore quoted higher. Meanwhile the friction is real and observable in your own pipeline: deals sitting in security review, an insurance renewal that asks a question nobody can answer, and a founder or CTO spending evenings on questionnaires instead of the job you hired them for. That is the honest version of the third column, and it is more persuasive to a board than a fabricated probability.
Common questions
Why does the retainer estimate change with internal capacity?
Because a vCISO with an engineer or a capable IT lead to direct needs far fewer hours than one who has to author every policy and chase every ticket personally. The same company can sit at either end of the band depending on who is available to do the work, and the difference is routinely $50,000 CAD a year. It is the cheapest lever you control.
Is a full-time hire ever the cheaper option?
Not usually on cost alone below a few hundred people. It becomes the right decision on other grounds: a security team to manage, a regulator or a contract requiring a dedicated officer, or an operational tempo that needs someone present daily. If the case for hiring rests only on cost, the arithmetic will not support it, and the comparison page sets out the grounds that do.
Does this include the audit fee?
No. Neither column includes the external audit or certification, a penetration test, a compliance platform subscription or security tooling, because those costs are the same whoever is leading the program. Budget $15,000 to $60,000 CAD for a first audit and see fractional CISO cost for the rest of a realistic first-year budget.
What if we split the difference and promote someone internally?
It is a legitimate third path and it is not free. A promoted internal lead needs the decision authority, the budget and usually external coaching, and they carry the same independence problem as a CTO if they also build the systems. Many companies pair a light advisory retainer with an internal owner, which costs $36,000 to $72,000 CAD a year and works well when the internal person has time genuinely allocated to it.