vCISO positioning against MSSPs
An MSSP sells operations. You sell accountability. A provider running the systems cannot independently decide what risk the company takes with them.
When a prospect says they already have a managed security provider, the answer is that the MSSP is doing a different job and probably doing it well, and that nobody in the arrangement is accountable for the decisions. Ask two questions rather than arguing: who signs off the risks the company is choosing to accept, and whose name goes in the customer contract that requires a security officer. An MSSP will not answer either, because answering puts an operator in the position of judging its own work. That is structural, not a criticism of the provider, which is why it beats any feature comparison.
MSSPs and managed service providers are also the largest partner referral channel available to a Canadian fractional practice. Treating them as competitors costs more than displacing one wins.
What each of these actually sells
- MSP
- Managed service provider. Runs the infrastructure: endpoints, identity, patching, backups, the help desk. Security is a part of the job rather than the job.
- MSSP
- Managed security service provider. Runs security tooling and operations: monitoring, alert triage, firewall and endpoint management, sometimes vulnerability scanning. Paid per seat, per device or per volume of data.
- MDR
- Managed detection and response. A narrower MSSP focused on detecting and containing an active intrusion, often with a contractual response time. Bought by companies that already know what they are protecting.
- vCISO
- An accountable security executive on a fraction of a week. Decides what risk the company takes, owns the program and the framework position, reports to the board or the owner, and is answerable for the decisions rather than for the uptime of a tool.
Four different purchases, and a company of 150 people usually needs two of them. The MSSP has no interest in being told it does not do leadership and you have no interest in telling it, because the right answer for the client is usually both.
Who owns what, and what neither of you owns
| Responsibility | MSSP | vCISO |
|---|---|---|
| Monitoring, alert triage, tooling operation | Owns it | Does not touch it |
| Deciding which risks the company accepts | Cannot, it operates the systems in question | Owns it |
| Choosing which security tools to buy | Sells them, so cannot advise neutrally | Owns the decision, or should |
| SOC 2 or ISO 27001 program ownership | Supplies evidence for its own scope only | Owns the whole program |
| Answering large customer security questionnaires | Answers the part about its own service | Answers for the company |
| Named security officer in a customer contract | Will not be named | Can be named, and prices for it |
| Board and insurer reporting | Reports on service metrics | Reports on the company's risk position |
| Deciding the MSSP is underperforming | Cannot | Owns it |
| The gap | Everything in the second column is unowned at a company that has only an MSSP. The company usually does not notice until an large customer, an insurer or an auditor asks who owns it. | |
The last row closes deals and needs raising carefully. Somebody has to be able to tell the MSSP its detection coverage is inadequate, and nobody inside the MSSP will volunteer for that. It also sounds most like an attack, so use it late and as a question.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Answering "we already have an MSSP"
The instinct is to explain the difference. It fails. The prospect hears a vendor explaining why the vendor they already pay is not enough, which every security seller who has called them has already said.
| What they say | What loses | What works |
|---|---|---|
| We already have an MSSP | Explaining that an MSSP is not a CISO | Good, keep them. Who reviews what they report and decides whether the coverage is right? |
| Our MSSP includes a vCISO | Calling it a fake vCISO | How many hours a month, who is the named person, and have they ever recommended you buy less tooling? |
| Our MSP handles security | Listing what an MSP cannot do | When your last large customer sent a security questionnaire, who filled it in? |
| We are covered, we have tools | Arguing about the tools | If your insurer asked who is accountable for information security, what name goes on the form? |
| The MSSP is cheaper than you | Discounting | They are, and they are buying something else. Compare the retainer with a full-time hire at $275,000 to $540,000 CAD, not with a per-seat service |
Every answer in the third column is a question the prospect can only answer by finding the gap themselves. It is also the only version that survives the prospect repeating the conversation to their MSSP account manager afterwards.
The MSSP that says it already includes a vCISO
This is the real competitor. A managed security provider with a bundled vCISO offer prices the retainer at $2,500 to $7,000 CAD a month, at or below the bottom of the independent band of $3,000 to $12,000 CAD. Sometimes that is a senior person at a fair price. Sometimes it is below cost, because the retainer is the route into a multi-year tooling contract.
The independence point
A vCISO employed by a company that also sells the client security product is advising on purchases their employer profits from. That is manageable when everyone knows it and recommendations come with alternatives and stated reasons. It is not manageable when the retainer is a loss leader for the tooling contract. This site tells buyers the same thing on vCISO pricing: ask what else is in the master services agreement when a retainer is quoted at $2,500 CAD a month. Make the point about the structure, not the person. The person is often good and will remember which you attacked.
Where you win against a bundled offer is on the questions the structure cannot answer well: how many contracted hours, whether the named individual is contractually yours, whether they will be named in customer contracts, and whether they have ever told a client to spend less. Where you lose is on price and on convenience, and you will not fix either, so do not try.
Why the MSSP is worth more as a partner than as a target
An MSSP with 80 mid-market clients has a running list of companies being asked for SOC 2 by a large buyer, failing an insurance renewal question, or arriving after an incident, and it cannot serve any of them. It has a commercial reason to want them served: a client that gets its security program organised buys more managed service, not less.
The partnership works when you are visibly not a threat. Say that you do not do monitoring, tooling or operations, put it in writing, and mean it. A fractional CISO who takes over the tooling relationship once inside an account has ended that referral channel, and the MSSP community in any Canadian city is small enough that others hear about it.
Ten to twenty percent of first year revenue is the going rate for the introduction, which on a $6,000 CAD monthly retainer is $7,200 to $14,400 CAD. That is expensive against a channel that costs nothing and cheap against a client worth six figures over its life. The rest of the channel arithmetic is on how to get vCISO clients. Building the partner list from a standing start is in your first ten vCISO clients.
Be findable when the MSSP cannot help
Companies arrive at this site because somebody told them they need security leadership and their existing providers cannot supply it. A listing is free and matched enquiries cost nothing.
List your firmCommon questions
How do I answer a prospect who says they already have an MSSP?
Agree with them, then ask who reviews what the MSSP reports and decides whether the coverage is right. The gap is not in operations, it is that nobody is accountable for the decisions, and a prospect who works that out from your question believes it in a way they will not believe a comparison slide. Never suggest they drop the MSSP, because most of the time they should keep it.
Is an MSSP-provided vCISO a real vCISO?
Sometimes, and the way to find out is to ask how many contracted hours a month, who the named individual is, and whether they have ever recommended the client buy less tooling. The structural problem is that the person advising on security purchases works for the company selling them, which is manageable with written alternatives and unmanageable when the retainer is a loss leader for the tooling contract.
Should a fractional CISO practice compete with MSSPs or partner with them?
Partner, in almost every case. An MSSP has a continuous supply of clients being asked for SOC 2, failing insurance questions or recovering from an incident, and no way to serve them. Ten to twenty percent of first year revenue is the normal introduction fee, and the requirement for the relationship to last is that you never take over the tooling or operations relationship.
Can an MSSP be named as the security officer in a customer contract?
In practice no, and this is one of the cleanest ways to show a prospect the gap. Named-officer exposure means accepting reputational and sometimes contractual responsibility for a company's security position, which is not something a per-seat service provider will sign for. A fractional CISO can accept it, should charge for it, and should never accept it without knowing the contract wording.
How do I price against a cheaper MSSP bundle?
Do not price against it. A bundled retainer at $2,500 to $7,000 CAD a month is buying something else, and matching it prices your independence at zero. Anchor instead against the cost of the alternative the buyer is actually weighing, which is a full-time Canadian CISO at $275,000 to $540,000 CAD in year one.