What does a vCISO do? The actual work
A vCISO owns the security program: deciding what risk the company accepts, running the compliance work, answering customers and insurers, and reporting to the board. Here is what that looks like week by week.
A vCISO does four things: decides what security risk the business accepts, runs the programs that produce evidence of it, speaks for the company to customers, insurers, auditors and the board, and directs the people who do the remediation. Everything below is a version of one of those four. What a vCISO does not do is operate tooling, respond to alerts at two in the morning, or write the code that fixes a finding.
Two follow-on questions have their own pages: how the role differs from the titles it gets confused with, in CISO against vCISO against security manager, and how the work is bought, in engagement models. If you are still at the definition stage, what is a virtual CISO covers the role itself and why virtual, vCISO and fractional all name the same job.
- Deciding
- Setting what the company will and will not do about a given risk, writing the decision down, and naming who accepted it. This is the part that cannot be delegated to a tool or a template, and it is the reason the role exists separately from engineering.
- Running
- Owning the certification or the remediation plan to a date: scope, control design, the evidence schedule, the auditor relationship, and holding internal people to their commitments.
- Speaking
- Being the named security officer to customers, insurers and the board. Questionnaires, buyer security calls, the insurance application, and the quarterly paper that lets directors show they applied their minds.
- Directing
- Telling engineering and IT what has to change and in what order, then verifying it happened. Not doing the work, and not managing a team of any size, which is where the part-time version of the role runs out.
Job descriptions for this role tend to be lists of adjectives. What follows is the calendar. The vCISO job description is the same four duties written as something you can post or send to a provider.
The first 30 days
Every engagement opens the same way. In the first month a vCISO should produce:
- An inventory of what you have: systems, cloud accounts, data stores, third parties, and who has administrative access to each.
- A gap assessment against whichever standard you are actually being measured on, which may be SOC 2, ISO 27001, a customer's questionnaire, or an insurer's application.
- A risk register that names owners and is short enough that an executive will read it. Twelve to twenty entries, not two hundred.
- A roadmap with dates and costs, split into what closes the immediate business problem and what is genuinely important but can wait.
If the first month produces a policy pack and nothing else, the engagement has started badly. Policies are the easiest artifact to generate and the least predictive of whether a company is secure.
The weekly cadence
On a 20 to 40 hour per month retainer, a normal week involves a standing call with whoever owns delivery, usually the CTO or head of engineering, to push open items forward and unblock decisions. Around that:
| Cadence | Work |
|---|---|
| Weekly | Delivery call, review of open findings, decisions on exceptions, triage of anything the team escalated |
| As they arrive | Customer security questionnaires, vendor security reviews, contract security schedules, prospect security calls |
| Monthly | Access review, vulnerability report review, third-party risk additions, metrics pack, roadmap update |
| Quarterly | Board or executive report, risk register review, policy review cycle, tabletop exercise, penetration test scoping |
| Annually | Full risk assessment, business continuity and disaster recovery test, audit or certification cycle, insurance renewal |
| On demand | Incident response leadership, diligence support, breach assessment and regulatory notification decisions |
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Customer questionnaires and security reviews
For a company selling to enterprises this is often the highest-value thing a vCISO does. Enterprise vendor security reviews arrive as spreadsheets of two hundred or more questions, with a deal attached and a deadline measured in days. A CTO answering one loses most of a week, answers three questions in a way that creates a contractual obligation nobody noticed, and says "no" to something that would have been fine with an explanation.
A vCISO answers these routinely, keeps a maintained response library so the second questionnaire takes hours rather than days, and knows which "no" needs a remediation date attached to stay acceptable. They also take the follow-up call with the customer's security team, which is frequently where the deal is won or lost.
The answer that ends deals
Inventing a yes. Buyers accept documented gaps with dates far more often than people expect, and they do not accept discovering during an audit that an answer was false. A good vCISO will tell you plainly when a control does not exist and negotiate the timeline rather than the truth.
Running the compliance program
Most vCISO engagements have a certification underneath them. The vCISO is the person who selects the framework, defines the scope, picks the auditor, runs the readiness work, arranges the penetration test the auditor will ask for, and holds the internal team to the evidence schedule.
Choosing the framework is a real decision and it is where an inexperienced provider costs you a year. A North American large buyer generally means SOC 2 Type 2. A European or UK buyer generally means ISO 27001. If nobody has named one, the framework selection question should be answered before any money is spent.
Scope is the other lever. A SOC 2 scoped to the production platform and its supporting systems is a manageable program. One scoped to everything the company touches is a two year project, and companies frequently do the second by accident because nobody senior drew the line.
Somebody also has to decide where the program lives. A vCISO working four days a month needs one place holding the control set, the evidence register, the risk register and the policies, and it should be an account your company owns rather than the consultant's. That can be a drive with a disciplined structure, a paid compliance platform at $7,500 to $50,000 CAD a year, or a free compliance workspace such as traztech Workspace, run by TrazTech, which operates this site. It covers 10 frameworks with an evidence register mapped to controls, and has no seat limit or export fee. It checks AWS, Okta, Google Workspace, GitHub, GitLab, Cloudflare and Jira daily and files the result as evidence. It has no endpoint agent and no HR integration, so a company that needs either should buy a platform. What should be in whichever one you pick by day 30 is on what a vCISO hands you in month one.
Reporting to the board
A quarterly security report to a board or audit committee has a specific job, and most technical leaders write it badly. It states what has changed in the company's risk position, what is being accepted deliberately, what the money bought, and what decision the board is being asked to make. Vulnerability counts and tool dashboards belong nowhere near it.
The other half is directors' duty of care. A board that receives no security reporting has no record of oversight, which is a problem after an incident and during an acquisition. Part of what a vCISO produces is the paper trail showing risks were surfaced, priced, and accepted or funded by the people with the authority to do so. The larger-organization version of this goes further, with formal committee reporting and regulator-facing material. What belongs in the quarterly paper itself, section by section, is set out in the board report template, and the maturity assessment produces the domain scores that usually sit inside it.
Incidents
When something happens, the vCISO runs the response: convening the right people, deciding what gets disconnected and when, managing external counsel and forensics, and making the notification calls. In Canada that last part is a legal assessment, not a communications one. PIPEDA requires a report to the Privacy Commissioner and notice to affected individuals where a breach creates a real risk of significant harm, and requires a record of every breach for 24 months regardless of whether the threshold was met. Quebec's Law 25 has its own duties. Getting the assessment wrong in either direction is expensive.
They also run the rehearsal. A tabletop exercise once or twice a year, with the executive team rather than only the engineers, is the cheapest thing on the security roadmap and the one most consistently skipped.
What a vCISO does not do
Setting this boundary early prevents most of the disappointment in these engagements.
- Not a security operations centre. Monitoring, alert triage and 24 hour coverage are a managed detection service, bought separately.
- Not an implementation team. A vCISO specifies the control and verifies it works. Someone else configures it.
- Not your auditor. The firm that builds the program cannot attest to it. Independence is the point of the audit.
- Not IT support. Laptop provisioning and identity administration are an IT function, and asking a $300 an hour executive to do them is an expensive way to fill hours.
- Not a penetration tester. They scope it, choose the firm, and manage the findings.
The full boundary, including where the scope lines usually get drawn in a contract, is on vCISO services.
None of this describes a company under about 50 people, where the same work is done informally by whoever set up the cloud account. If that is you, read who owns security when there is no CISO, and, where the answer has landed on your engineering lead by default, what to do when that has stopped working.
Need someone to own this
Tell us which of the above you need covered. We will match you with Canadian providers who do that work.
Get matchedCommon questions
What does a vCISO do in the first month?
Builds an inventory of systems, data and third parties, runs a gap assessment against the standard you are being measured on, produces a short risk register with named owners, and delivers a roadmap with dates and costs. The first month is the most intensive of the engagement, which is why many providers charge a separate assessment fee for it.
Does a vCISO write our security policies?
Yes, or more often they adapt a policy set to match what your company genuinely does and then get it approved. The failure mode is a policy pack that describes an imaginary company, which auditors detect immediately by asking for the evidence a policy implies. Policies should be written after the inventory, not before.
Will a vCISO handle our customer security questionnaires?
Almost always, and for enterprise sellers it is frequently the single most valuable part of the engagement. Expect them to build a maintained answer library so repeat questionnaires take hours instead of days, and to join the customer's follow-up security call. Confirm turnaround expectations in the contract, since these arrive with deal deadlines attached.
Can a vCISO manage our security team?
They can direct a small team and set its priorities, and many do. What part-time leadership handles poorly is day to day people management: hiring, performance reviews, career development and being available when someone needs their manager. Once you have more than two or three security staff, the management load alone starts to justify a full-time hire.
How is a vCISO different from a security consultant?
A consultant delivers an assessment and leaves. A vCISO stays and is accountable for whether the risk position improves, which means they are the one explaining to your board why something did not get done. If a proposal has deliverables but no ongoing accountability, you are buying consulting, which may well be what you need.