What a vCISO hands you in month one
Month one is not a listening tour. It should end with five things you can open, each with a name against it, held somewhere that is yours rather than somewhere the consultant rents.
At the end of month one a vCISO should hand you five artifacts: an inventory of systems, data and administrative access; a gap assessment against the one standard you are measured on; a risk register of 12 to 20 rows with named business owners; a short list of decisions that need an executive to make them; and a stated cadence saying what happens weekly, monthly and quarterly from here. If what arrives instead is a set of policies, the engagement started in the wrong place. Policies written before the inventory describe a company nobody has looked at yet.
5 artifacts What day 30 should produce
20 to 40 hours Typical month-one effort
The five artifacts, and how to test each one
The right-hand column matters more than the left. Each of these artifacts can be produced in a form that looks complete and tells you nothing, so each row carries the question that separates the two.
| Artifact | Hours | What good looks like | The question that tests it |
|---|---|---|---|
| Asset, data and access inventory | 8 to 14 | Every system that holds customer data, who administers it, and where the data physically sits | Which three systems surprised you, and who has admin on each |
| Gap assessment | 6 to 10 | A finding per control with a current state, a required state and an effort estimate | What are the five gaps that would stop an audit tomorrow |
| Risk register | 4 to 8 | 12 to 20 rows, each owned by someone outside security, each with a decision | Name a row an executive has actually accepted, in writing |
| Executive decision list | 2 to 4 | Three to six decisions only a budget holder can make, each with options and a cost | What is the decision that blocks the most other work |
| Operating cadence | 1 to 2 | Named recurring meetings and reviews, with the record each one produces | What evidence exists in three months that does not exist today |
| Month one | 21 to 38 | At $250 to $400 CAD an hour, roughly $5,000 to $15,000 CAD for the first month | |
The hours are a shape rather than a quote, and they move with how much already exists. A company with a current asset list and a previous audit can compress the first two rows sharply. A company where nobody has ever listed the SaaS estate cannot. What should not move is the count: five artifacts, by day 30. Where those hours sit inside a larger arrangement is on the engagement models page, and the two months after this one are on the first 90 days.
How the month runs
- Week one: interviews and access. The vCISO gets read access to the cloud console, the identity provider and the ticketing system, and talks to engineering, finance and whoever answers customer security questionnaires.
- Week two: the inventory gets written and circulated for correction. This is the step people skip, and every later artifact inherits the error if they do.
- Week three: the gap assessment against the standard you are measured on, scored against what exists rather than what is intended.
- Week four: risks drafted, owners agreed in conversation rather than assigned by email, and the decision list built from whatever the risk conversations could not settle.
- End of week four: a walkthrough with the executive who signs. Not a document sent by email, because the point of the decision list is to get decisions.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Where the artifacts should live
This part gets decided by accident and then causes an argument at the end of the engagement. The artifacts are yours. They belong in a system you control, and you should be able to open them the day after the vCISO stops working with you.
Three arrangements are common. The first is your own drive: free, works, and gives you no index from a control to the evidence that proves it. The second is the consultant's own template pack in the consultant's own account, which is convenient in month one and becomes a problem the day the engagement ends. The third is a compliance workspace, where cost enters: paid platforms run $7,500 to $50,000 CAD a year, and a company still deciding whether it needs a vCISO often cannot justify that in the same quarter.
It does not have to cost anything. TrazTech, which operates this site, runs traztech Workspace, a free compliance workspace covering 10 frameworks, with an evidence register mapped to controls, a risk register, 40 policy templates with approval history and readiness scoring. No credit card, no trial period, no seat limit and no export fee, and the data stays in the workspace when an engagement ends. It is one option among the three above, not the answer. It runs daily checks against AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira, and files what they return against the control it proves. Anything else has to be described as a check rather than picked off a list. That is the difference from Vanta and Drata, which carry hundreds of pre-built integrations, endpoint agents and HR systems. If your estate needs that coverage, buy one of those. Whatever you choose, choose it in week one, because moving a risk register between systems in month three is a day nobody has.
Sign-off checklist for the month-one handover
Work through this in the walkthrough meeting, not afterwards. An artifact that fails one of these is not finished, and month two is built on it.
0 of 0 accepted ·
The two things that mean month one went wrong
Policies arrived before the inventory did, or the risk register is owned entirely by the vCISO. The first means the program is describing a company nobody has examined. The second means no business decision has been made yet, and a register the security lead owns end to end is a document rather than a set of decisions. Both are recoverable in month two if you say so now.
Get quotes for a vCISO engagement
Tell us your size, your framework and your timeline, and we will match you with Canadian firms that do this work.
Get matchedCommon questions
Is one month long enough to produce anything useful?
Yes, for these five artifacts, because all five are assessments of what already exists rather than changes to it. What one month cannot produce is a closed gap, a completed control or an audit-ready evidence trail. If a proposal promises remediation inside 30 days, it is either describing a very small company or it is describing policies.
Who should own the artifacts, the vCISO or us?
You should, in an account your company controls, with the vCISO holding access rather than ownership. This is worth settling in the contract because it is invisible until the engagement ends, and recovering a risk register and an evidence set from a consultant's own tooling after a relationship has cooled is the worst possible time to discover the arrangement. The contract checklist covers the clause.
What does month one cost in Canada?
Roughly $5,000 to $15,000 CAD, on 20 to 40 hours at $250 to $400 CAD an hour, and the first month usually runs heavier than the months after it. Some firms sell the first month as a fixed-price assessment instead, which is a reasonable way to buy it because the deliverables are well defined. The cost page has the ongoing numbers.
Do we need tooling in month one?
You need somewhere to put the artifacts and an index from control to evidence. That can be a free compliance workspace or a drive with a disciplined structure. A paid platform at $7,500 to $50,000 CAD a year is a purchase for a program that already knows which framework it is running and has machine-generated evidence to collect, which in month one you usually do not.
What if we already have a risk register?
Then month one is shorter and the gap assessment absorbs the saved hours. Expect the vCISO to rewrite the scoring rather than accept it, since most existing registers score likelihood and impact without a stated scale. The risk register page covers what survives a hostile question from a board member.