HireACISO

vCISO vs a full-time CISO: which to choose

Cost is the obvious difference and the least interesting one. The real question is whether your security decisions this year need four days a month of senior attention or twenty.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

For most Canadian companies between 50 and 500 people, a vCISO is the correct choice. The volume of security decisions does not fill a full-time executive's week, and hiring costs somewhere around $300,000 to $450,000 CAD loaded in the first year. A full-time CISO becomes correct when you have a security team to manage, a regulator or a contract requiring a dedicated officer, or an operational tempo that needs someone present daily. Those thresholds arrive earlier than founders expect in regulated sectors and later than they expect in software.

Below 50 people neither option is right. Most companies that size are not buying senior security leadership at all. The realistic choice is an internal owner with protected time plus a few advisory hours, set out on 30 people and no security person. The rest of this page is written for companies past that point.

Side by side

Fractional against full-time security leadership
DimensionvCISOFull-time CISO
First-year cost, CAD $36,000 to $300,000 depending on hours Roughly $275,000 to $540,000 loaded
Time to productive Days to weeks Three to nine months including the search
Attention available Contracted hours, scheduled Whatever the week demands
Breadth of experience Multiple companies and audits concurrently Deep in your company, narrower across the field
Context on your business Good on systems, thinner on politics and history Full, including who to persuade and how
Managing a team Can direct two or three, not more The core of the job at scale
Exit and continuity risk Notice period, and a replacement from the same firm Severance, a vacancy, and a fresh search
Independence from engineering Structurally independent Depends entirely on reporting lines

What each one actually buys you

The question a board is really asking is what the cheaper option does not include. Nothing in the left column requires an employee. Nothing in the right column is available on a retainer at any price.

What a vCISO gives you, and what only a full-time hire gives you
A vCISO gives youOnly a full-time hire gives you
A named, accountable security officer for customers, insurers and the board, on your trust page and in your contracts Presence. Somebody in the room for the conversations that were never scheduled, which is where a lot of security decisions are actually made
Ownership of the risk register, the policy set, the roadmap and the framework decision People management: hiring, performance reviews, career development and being reachable when a report needs their manager
A first SOC 2 or ISO 27001 driven to a contractual date by somebody who has done it before Daily operational tempo. Continuous incident volume, a live regulatory examination or a merger integration outruns a scheduled retainer
Large-company questionnaires answered and the buyer security call taken, usually the highest-value line in the engagement Deep institutional context: the history, the politics, who has to be persuaded and in what order
Structural independence from engineering, without adding an executive to the org chart Equity alignment, and a security direction that is part of the product rather than an assurance layer over it
Breadth. Someone seeing several companies and several audits at once, which your budget cannot buy full time Unbounded availability in a bad week, without an overage conversation
An exit that costs a notice period rather than severance, a vacancy and a fresh search A role that regulated obligations and some enterprise master agreements specify as a dedicated officer

Write the role down before choosing. Put a monthly hour estimate beside each responsibility on the job description and total it: under about 40 hours a month is a retainer and hiring buys idle senior time, past 80 is a job. The hours calculator does the same arithmetic from six questions, and vCISO pricing covers what the retainer side is quoted at.

Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.

Canadian salary context

Public compensation data for Canadian CISOs is thin, and it mixes a bank's group CISO with a fifty person startup's first security hire. Treat these as approximate bands, not published figures. A CISO at a Canadian company of 50 to 500 people generally sits between $180,000 and $300,000 CAD base. Toronto financial services and large regulated employers sit at the top. Smaller markets, non-regulated sectors and first-time CISOs sit at the bottom.

Base is roughly two thirds of the story. Add a bonus at 15 to 25 percent, employer burden at 15 to 20 percent for CPP, EI, benefits and a retirement match, an executive search fee at 20 to 30 percent of base, and equity if you are a startup. The first-year total realistically starts around $275,000 CAD and reaches past $500,000. The full build-up is on fractional CISO cost.

The second cost of hiring is the search. The Canadian pool of people who have held the role at your size and in your sector is small, and executive security searches here routinely take four to six months. Your customer is waiting through all of them.

When you should hire full time

The wrong answer here wastes a year.

You have three or more security staff. Hiring, performance management, career development and being available when someone needs their manager do not compress into a part-time schedule. Once a team exists, the management load alone justifies the role.

A regulator or a major contract requires a dedicated officer. Some financial sector obligations, some federal and defence arrangements, and some large enterprise master agreements specify a full-time named individual. Read the requirement. Many contracts that appear to demand this accept a named vCISO once asked.

Security is part of the product. If you sell a security product, or if security is the reason customers choose you, the person setting that direction should be an employee with equity and a seat at the executive table.

Your operational tempo is daily. A high volume of incidents, continuous regulatory examination, or a merger integration program means decisions arrive faster than a scheduled retainer can absorb them.

You are past roughly 500 people. This is a soft line and sector moves it a long way, but above it the internal coordination load alone tends to fill a week. Regulated companies cross it earlier, sometimes by hundreds of employees.

When fractional is plainly better

The trigger is a single event. A failed audit, an insurer's renewal, a diligence process or one large customer's demand are all finite problems. Hiring a permanent executive to solve one of them leaves you with a permanent cost and, often, a bored executive.

You need seniority you cannot afford full time. A retainer buys access to someone who has run programs at larger companies than yours. Your budget as a full-time salary buys someone earlier in their career who has not. For a company facing its first audit, the experience gap matters more than the hours gap.

You need independence from engineering. When the CTO both builds and assures the platform, there is no second opinion, and auditors and insurers notice. A vCISO reporting to the CEO or the board resolves that without adding a permanent executive.

You are not sure yet. A retainer for two or three quarters tells you how much security leadership your company consumes. Many companies discover the answer is less than they feared, and the ones who discover it is more go into a search knowing what to hire for.

The bridge, and the trap

The best use of an embedded engagement is a deliberate bridge: someone senior holding the role, running the program and helping write the job description while you search, then handing over. The trap is the bridge that never ends. If you are paying $15,000 CAD a month indefinitely and the need is clearly permanent, you are paying full-time money for part-time presence. Set a review date at six months and mean it.

The arrangement most companies end up with

The common path is not one or the other. A company brings in a vCISO on a program leadership retainer to get through a first SOC 2 or ISO 27001 certification, hires a security manager or analyst internally during that year because there is now real work to run, then steps the vCISO down to advisory hours providing the executive layer, the board reporting and the framework decisions. The internal manager grows into the role over two or three years, and the retainer ends when they are ready.

That path costs less than hiring first, and the person you promote has already run a certification with someone experienced beside them. When that moment arrives, the handover is set out on moving from a vCISO to a full-time CISO, and the cost of building the rest of the function around them is on the cost of an in-house security team.

The vCISO ROI calculator puts a retainer, a full-time hire and doing nothing into three columns in Canadian dollars, and says where the compensation bands come from.

Not sure which side of the line you are on

Tell us your headcount, your sector and what triggered the question. We will say plainly whether you should be hiring, and match you with Canadian providers if you should not.

Get matched

Common questions

At what headcount should we hire a full-time CISO?

There is no clean number, but roughly 500 people is where the internal coordination load starts to fill a full week for a typical software or services company. Regulated companies cross it much earlier, sometimes around 150, and a company with no compliance obligations and a strong engineering culture can run fractional well past 500. Team size is a better signal than headcount: three security staff means hire.

Will our large customers accept a vCISO as our security officer?

In nearly every case, yes. Procurement teams ask whether someone is accountable and reachable, not whether they are on payroll. The exceptions are specific contracts and regulated arrangements that name a dedicated officer, and those are worth reading rather than assuming. When in doubt, ask the customer directly before designing your org chart around a guess.

Can a vCISO become our full-time CISO?

Sometimes, and it is worth raising early. Many independent practitioners have deliberately chosen portfolio work and will decline, while some will take the right role. If you think it may happen, address it in the contract rather than later, because firms often include conversion fees for hiring their consultants.

Is a vCISO just a cheaper CISO?

No, and treating it that way leads to disappointment. You are buying a defined amount of senior attention, typically four to eight days a month, not a discounted version of a full-time hire. What you gain is seniority and breadth for the money. What you give up is availability and depth of context on your business.

What happens to our program if the vCISO relationship ends?

That depends entirely on what you own. If the policies, risk register, evidence and assessments live in your systems in a portable format, a handover is a few weeks of work. If the program lives inside the provider's platform and the knowledge lives in one person's head, you are effectively starting over. Settle ownership in the contract at the beginning, not at the end.