The first 90 days of a vCISO engagement
Ninety days is enough to produce an asset inventory, a gap assessment, a risk register with named owners, a costed roadmap and a first board paper. If month one produces only policies, the engagement has started badly.
A vCISO engagement should produce five artifacts in its first 90 days: an inventory of systems, data and administrative access; a gap assessment against whichever standard you are measured on; a risk register of 12 to 20 entries with a named owner on each; a roadmap with dates and CAD costs; and one board or executive paper that says where the company stands. At a 20 to 40 hour per month retainer that is roughly 60 to 120 hours of work and $18,000 to $36,000 CAD for the quarter.
Most of the value in the whole engagement sits in the first quarter, which is why a twelve month lock-in is worth resisting. The fair structure is a three to six month initial commitment, month to month afterwards.
What lands in each month
| Month | What is delivered | Hours | Cost at retainer |
|---|---|---|---|
| Month 1, discovery | System and data inventory, administrative access review, gap assessment started, interviews with engineering, IT and sales | 25 to 45 | $6,000 to $12,000 |
| Month 2, decisions | Gap assessment finished, risk register with owners, target framework chosen and defended, quick wins started | 20 to 40 | $6,000 to $12,000 |
| Month 3, direction | Costed roadmap, budget request, policy set drafted, first board or executive paper, cadence set for the rest of the year | 15 to 35 | $6,000 to $12,000 |
| First quarter, all in | 60 to 120 | $18,000 to $36,000 |
Month one: find out what is actually there
Nothing useful can be decided before someone has written down what the company runs and who can administer it. It is the step most often skipped, because everyone believes they already know.
That last item changes the plan most. The company's obligations are usually written in somebody's email rather than in a framework, and reading them is how you avoid spending a year on the wrong certification. If your data map is going to matter, build it while you are here rather than during a vendor review six months later.
Month one closes with a walkthrough, not an email. There is a short list of things to accept or send back before month two builds on them. What a vCISO hands you in month one has the five artifacts and the acceptance test for each.
Month two: decide, and write the decisions down
Month two is where a vCISO earns the title rather than the day rate. Three decisions have to be made and defended: which standard you are working to, what the company will not do about the risks it is accepting, and who owns each open item.
The risk register is the artifact that carries all three. Keep it to 12 to 20 entries. A register with 200 rows is a document nobody reads, and an unread register is worse than no register because it creates a written record that the risk was known and ignored.
Month three: cost it and take it upstairs
The roadmap has to have Canadian dollar figures against it, or the executive reading it cannot act. Split it in two: what closes the business problem that triggered the engagement, and what is important but can wait a quarter. Anything that cannot be put in one of those two buckets is not on the roadmap. The structure of the paper that carries this is on building a security roadmap.
Two signs the engagement is going wrong in month one
The first is a policy pack arriving before an inventory. Policies are the easiest artifact to generate and the least predictive of whether anything is secure. The second is a report written against a framework nobody has asked you for, which usually means the provider has one template and you are getting it. If either happens, say so in month one, not month five. What to do about it is on when a vCISO engagement is not working.
Get a first 90 days with something to show for it
Ask any candidate what they will have delivered by day 90 and compare the answers. Tell us what you need and we will put it in front of them.
Get matchedCommon questions
Can a vCISO do all this in 8 hours a month?
No. Eight to sixteen hours a month is a steady-state advisory number for a program that already exists. A first 90 days needs 20 to 40 hours a month, then steps down. A provider quoting a light retainer for a company starting from nothing is either going to overrun or going to deliver templates.
What if we already have policies and a compliance platform?
Then month one is shorter and month two starts with checking whether the policies describe what the company does. Generated policy sets are usually accurate about intent and wrong about practice, and an auditor tests practice. The 90 days still ends in the same place: a register, a roadmap and a board paper.
Should we sign a twelve month contract to get a better rate?
Rarely. The value is concentrated in the first quarter, so a twelve month lock-in transfers risk to you at exactly the point where you know least about the provider. Three to six months initial, month to month after, is the fair shape. The terms that matter more than the headline rate are on the contract checklist.
Who inside our company needs to be available?
Someone who can grant read access to systems, someone from engineering who can answer how things actually work, and an executive who can approve spending. Budget four to six hours of internal time a week during the first month. Engagements that fail usually fail on internal availability rather than on the vCISO.