HireACISO

What does a vCISO do? The actual work

A vCISO owns the security program: deciding what risk the company accepts, running the compliance work, answering customers and insurers, and reporting to the board. Here is what that looks like week by week.

Last reviewed 2026-08-16Written by Jacob Masse, TrazTech Inc.

A vCISO does four things: decides what security risk the business accepts, runs the programs that produce evidence of it, speaks for the company to customers, insurers, auditors and the board, and directs the people who do the remediation. Everything below is a version of one of those four. What a vCISO does not do is operate tooling, respond to alerts at two in the morning, or write the code that fixes a finding.

Job descriptions for this role tend to be lists of adjectives. What follows is the actual calendar.

The first 30 days

Every engagement opens the same way, and it is the part with the most visible output. In the first month a vCISO should produce:

  • An inventory of what you have: systems, cloud accounts, data stores, third parties, and who has administrative access to each.
  • A gap assessment against whichever standard you are actually being measured on, which may be SOC 2, ISO 27001, a customer's questionnaire, or an insurer's application.
  • A risk register that names owners and is short enough that an executive will read it. Twelve to twenty entries, not two hundred.
  • A roadmap with dates and costs, split into what closes the immediate business problem and what is genuinely important but can wait.

If the first month produces a policy pack and nothing else, the engagement has started badly. Policies are the easiest artifact to generate and the least predictive of whether a company is secure.

The weekly cadence

On a 20 to 40 hour per month retainer, a normal week involves a standing call with whoever owns delivery, usually the CTO or head of engineering, to push open items forward and unblock decisions. Around that:

Recurring vCISO work by cadence
CadenceWork
Weekly Delivery call, review of open findings, decisions on exceptions, triage of anything the team escalated
As they arrive Customer security questionnaires, vendor security reviews, contract security schedules, prospect security calls
Monthly Access review, vulnerability report review, third-party risk additions, metrics pack, roadmap update
Quarterly Board or executive report, risk register review, policy review cycle, tabletop exercise, penetration test scoping
Annually Full risk assessment, business continuity and disaster recovery test, audit or certification cycle, insurance renewal
On demand Incident response leadership, diligence support, breach assessment and regulatory notification decisions

Customer questionnaires and security reviews

For a company selling to enterprises, this is often the highest-value thing a vCISO does and the reason the engagement pays for itself. Enterprise vendor security reviews arrive as spreadsheets of two hundred or more questions, usually with a deal attached and a deadline measured in days. A CTO answering one loses most of a week, answers three questions in a way that creates a contractual obligation nobody noticed, and says "no" to something that would have been fine with an explanation.

A vCISO answers these routinely, keeps a maintained response library so the second questionnaire takes hours rather than days, and knows which "no" needs a remediation date attached to stay acceptable. They also take the follow-up call with the customer's security team, which is frequently where a deal is actually won or lost.

The answer that ends deals

Inventing a yes. Buyers accept documented gaps with dates far more often than people expect, and they do not accept discovering during an audit that an answer was false. A good vCISO will tell you plainly when a control does not exist and negotiate the timeline rather than the truth.

Running the compliance program

Most vCISO engagements have a certification underneath them. The vCISO is the person who selects the framework, defines the scope, picks the auditor, runs the readiness work, arranges the penetration test the auditor will ask for, and holds the internal team to the evidence schedule.

Choosing the framework is a real decision and it is where an inexperienced provider costs you a year. A North American enterprise buyer generally means SOC 2 Type 2. A European or UK buyer generally means ISO 27001. A federal department or defence prime means CPCSC. If nobody has named one, the framework selection question should be answered before any money is spent.

Scope is the other lever. A SOC 2 scoped to the production platform and its supporting systems is a manageable program. One scoped to everything the company touches is a two year project, and companies frequently do the second by accident because nobody senior drew the line.

Reporting to the board

A quarterly security report to a board or an audit committee is a specific document with a specific job, and most technical leaders write it badly. It needs to state what has changed in the company's risk position, what is being accepted deliberately, what the money bought, and what decision the board is being asked to make. Vulnerability counts and tool dashboards belong nowhere near it.

The other half is directors' duty of care. A board that receives no security reporting has no record of oversight, which is a problem after an incident and during an acquisition. Part of what a vCISO produces is the paper trail showing that risks were surfaced, priced, and accepted or funded by the people with the authority to do so. The larger-organization version of this goes further, with formal committee reporting and regulator-facing material.

Incidents

When something happens, the vCISO runs the response: convening the right people, deciding what gets disconnected and when, managing external counsel and forensics, and making the notification calls. In Canada that last part is a legal assessment, not a communications one. PIPEDA requires a report to the Privacy Commissioner and notice to affected individuals where a breach creates a real risk of significant harm, and requires a record of every breach for 24 months regardless of whether the threshold was met. Quebec's Law 25 has its own duties. Getting the assessment wrong in either direction is expensive.

They also run the rehearsal. A tabletop exercise once or twice a year, with the executive team rather than only the engineers, is the cheapest thing on the security roadmap and the one most consistently skipped.

What a vCISO does not do

Setting this boundary early prevents most of the disappointment in these engagements.

  • Not a security operations centre. Monitoring, alert triage and 24 hour coverage are a managed detection service, bought separately.
  • Not an implementation team. A vCISO specifies the control and verifies it works. Someone else configures it.
  • Not your auditor. The firm that builds the program cannot attest to it. Independence is the point of the audit.
  • Not IT support. Laptop provisioning and identity administration are an IT function, and asking a $300 an hour executive to do them is an expensive way to fill hours.
  • Not a penetration tester. They scope it, choose the firm, and manage the findings.

The full boundary, including where the scope lines usually get drawn in a contract, is on vCISO services.

Need someone to own this

Tell us which of the above you actually need covered and we will match you with Canadian providers who do that work.

Get matched

Common questions

What does a vCISO do in the first month?

Builds an inventory of systems, data and third parties, runs a gap assessment against the standard you are being measured on, produces a short risk register with named owners, and delivers a roadmap with dates and costs. The first month is the most intensive of the engagement, which is why many providers charge a separate assessment fee for it.

Does a vCISO write our security policies?

Yes, or more often they adapt a policy set to match what your company genuinely does and then get it approved. The failure mode is a policy pack that describes an imaginary company, which auditors detect immediately by asking for the evidence a policy implies. Policies should be written after the inventory, not before.

Will a vCISO handle our customer security questionnaires?

Almost always, and for enterprise sellers it is frequently the single most valuable part of the engagement. Expect them to build a maintained answer library so repeat questionnaires take hours instead of days, and to join the customer's follow-up security call. Confirm turnaround expectations in the contract, since these arrive with deal deadlines attached.

Can a vCISO manage our security team?

They can direct a small team and set its priorities, and many do. What part-time leadership handles poorly is day to day people management: hiring, performance reviews, career development and being available when someone needs their manager. Once you have more than two or three security staff, the management load alone starts to justify a full-time hire.

How is a vCISO different from a security consultant?

A consultant delivers an assessment and leaves. A vCISO stays and is accountable for whether the risk position improves, which means they are the one explaining to your board why something did not get done. If a proposal has deliverables but no ongoing accountability, you are buying consulting, which may well be what you need.