What is a virtual CISO?
A virtual CISO is a part-time, named security executive who owns your security program on a retainer. Virtual CISO, vCISO and fractional CISO describe the same job, and the market uses the three terms interchangeably.
A virtual CISO is a security executive you engage part-time, by the month, to own the security program of a company that is not ready to employ a chief information security officer full-time. The word virtual refers to the employment arrangement, not to the work. The person is real, named, and accountable in the same way a full-time officer would be, across a fixed number of days a month and usually for more than one company.
3 names Virtual CISO, vCISO and fractional CISO are the same role
Monthly Almost always bought as a retainer, not a project
Named A person signs the work, not a firm alone
Virtual CISO, vCISO and fractional CISO are the same role
This is the first thing to settle, because it wastes more buyer time than anything else in the category. The three terms describe one job. A firm advertising a fractional CISO and a firm advertising a virtual CISO are selling the same thing, and vCISO is only the abbreviation of virtual CISO. Nothing in the scope, the accountability or the contract changes between the labels.
There are shades of usage:
- Fractional
- Borrowed from fractional CFO and fractional COO, and it emphasises the slice of a role. People who use it tend to be thinking about a fraction of a full-time executive, for example two days a month out of twenty.
- Virtual
- Emphasises that the person is not sitting in your office. It is the older term in security and the one most used in vendor marketing and in search. Some firms use it for a service delivered by a rotating team rather than one person, which is a real difference, but it comes from the firm's delivery model and not from the word.
- vCISO
- The short form. It appears in job descriptions, proposals and procurement documents more often than the words it stands for.
The distinction that actually matters is not which of the three words a firm picked. It is whether you get a named individual with the seniority to make decisions, or a support queue with an executive title on the invoice. Ask that question directly and the vocabulary stops mattering. The differences between this role and adjacent titles are worked through in CISO against vCISO against security manager.
What the role covers
A virtual CISO owns the security program end to end at the level of decisions and accountability. Four things sit inside the role in almost every engagement.
Risk decisions. Deciding what the company will do about a given risk, what it will accept, and writing down who accepted it. A company without this function does not have a security problem so much as an unowned decision problem. Every finding sits in a spreadsheet because nobody has the authority to close it or to accept it.
The program itself. Policies, the risk register, access reviews, vendor review, incident response planning, security awareness, and the roadmap that sequences them. If you are working towards SOC 2 or ISO 27001, the virtual CISO owns scope, control design, the evidence schedule and the relationship with the auditor, which is covered on vCISO work for SOC 2.
Speaking for the company. Being the named security contact to enterprise customers, insurers, regulators and the board. Security questionnaires, buyer security calls, the cyber insurance application, and the quarterly board paper. For many companies this is the trigger that started the search in the first place, as when do you need a fractional CISO sets out in detail.
Directing the fixes. Telling engineering, IT and operations what has to change, in what order, and then verifying it happened. Directing, not doing. The week to week and month to month shape of this is set out in what a vCISO does, and the first three months specifically in the first 90 days.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
What the role does not cover
The boundary is where most disappointing engagements go wrong, and it is almost always because it was never written down. A virtual CISO is a few days a month. That budget buys direction, not delivery, and it does not buy coverage.
- Hands on remediation. They will not patch the servers, rewrite the Terraform, configure the identity provider or fix the code behind a finding. They will tell you what has to change and check that it did.
- Around the clock monitoring. Nobody on a two-day-a-month retainer is watching alerts at three in the morning. That is a separate service.
- Incident response on the tools. They will run the incident from a command position, brief the board and handle the notification decisions. Forensics and containment work is separate, usually retained separately, and the plan should name who does it before you need them.
- Managing a team of any size. A part-time officer can direct two or three people. Past that, the arithmetic of a few days a month stops working and the conversation is about a full-time hire, which is the subject of moving from a vCISO to a full-time CISO.
- Being the audit. A readiness position and an audit opinion are different products, and the same party cannot honestly do both.
Who it suits, by company stage
The fit question is mostly about headcount, data sensitivity and who is asking you questions from outside.
| Stage | Typical position | Fit |
|---|---|---|
| Under 20 people, pre-revenue or early revenue | No security owner, no customer asking yet | Usually too early. A short advisory block or a maturity baseline is enough |
| 20 to 80 people, enterprise deals landing | A CTO doing security alongside product, and a stalled procurement review | The core case. This is where the role earns its cost |
| 80 to 200 people, regulated or handling sensitive data | A security engineer or two, no executive owner, board starting to ask | Strong fit, often with a larger monthly commitment and a named deputy |
| 200 plus, or a security team of five or more | Real team, real budget, continuous obligations | Transition territory. A virtual CISO can bridge or can run the search |
Two signals outweigh headcount. If a customer contract or a regulator requires a designated security officer by name, you need the role regardless of size. If your engineering lead is spending more than a day a week on questionnaires and audit evidence, the role is already being done, badly and expensively, by someone whose real job is something else. That case is made in when the engineering lead is doing security. The do you need a vCISO tool walks through the same test with your own numbers.
How engagements are structured
Nearly all of this work is bought as a monthly retainer. Three variables define the engagement and all three belong in writing.
- Hours or days per month
- The unit of purchase. Small programs commonly sit at one to two days a month, a company in an active certification at three to five, and a regulated or post-incident program higher still. Ask whether unused time rolls forward and for how long, because a month where nothing happened is common and a month where everything happens follows it. The hours estimator gives a starting number.
- A named individual
- The contract should name the person, not only the firm. If a team delivers the service, ask who is accountable, who attends the board meeting, and what happens when that person leaves. This is the single most useful question in the whole evaluation.
- Scope in writing
- What is inside the retainer, what is quoted separately, and what is explicitly excluded. Certification support, penetration test management, incident response and questionnaire volume are the four that most often get assumed in and then argued about. The scope definer produces a scope statement you can put in front of a provider.
Beyond the standard retainer there are project-shaped versions: a fixed-term engagement to reach a certification date, a diligence sprint before a funding round, and an interim arrangement covering a departure. Those are compared in engagement models, and what the market charges for each is on fractional CISO cost and vCISO pricing.
What a virtual CISO is not
Four adjacent services get sold beside this one, and buyers regularly sign one while believing they bought the other. None of the four is a poor product. They answer different questions.
Not a managed security service. An MSSP operates tooling and watches your environment. It is an operational capability measured in coverage and response time. A virtual CISO decides what you should be watching and whether the MSSP contract is worth what you pay for it. Companies that buy monitoring and think they have bought governance still fail the questionnaire, because the questionnaire asks who owns risk. The two together are a normal and sensible arrangement, and the split is worked through in vCISO against MSSP.
Not a compliance consultant. A compliance consultant takes you to a framework and a date. That is a defined project with an end. A virtual CISO owns security whether or not a framework is in play, which includes the risks no standard asks about and the quarters when no audit is running. Plenty of engagements start as the first and become the second.
Not a penetration tester. Testing produces findings. The virtual CISO decides which findings get fixed, in what order, at what cost, and which are accepted with a signature. The same party should not both test and own the remediation decision, because the independence of the finding is the point of paying for it.
Not a managed SOC. A security operations centre is detection and response staffing. It is a 24 by 7 cost line. A virtual CISO may well tell you that you do not need one yet, which is one of the more valuable things the role does.
How to evaluate one
The title is unregulated. Anyone can print it. These are the questions that separate an executive from a consultant with an upgraded business card.
- Who, by name, and what have they run? Ask for the individual, their background, and two engagements at companies of your size and sector that can be referenced. Certifications are a floor, not an answer.
- Have they sat in front of a board or an enterprise buyer? A large part of this job is communication under scrutiny. Someone who has only ever produced documents will not carry a hostile security review.
- What do the first 90 days produce? A credible answer is specific: a current-state assessment, a risk register, a prioritised roadmap and a board-ready summary. Anything vaguer than that is a sales pitch.
- Do they sell anything they would also recommend? If the same firm supplies the tooling, the monitoring and the testing, ask how the advice stays independent and get the answer in writing.
- How is remediation priced? Honest work assesses the gaps first and prices the fixes from the findings. A fixed remediation price quoted before anyone has looked is a guess wearing a number.
- What happens when the named person is unavailable? Holidays, illness and departures are certain. The cover arrangement should be named before you need it.
- Which entity signs, and under which province's law? Where the engagement data lives matters too, especially if you hold Quebec personal information or health records.
How to choose a vCISO takes these further, and how to vet a firm covers the provider rather than the person. Canadian providers are listed in the directory.
What the contract should say
A short agreement is fine. A vague one is not. Seven clauses do the work:
- The named person, their committed days or hours per month, and the notice required to substitute them.
- Scope in and scope out, with certification support, testing, incident response and questionnaire volume each addressed by name rather than left to be inferred.
- Authority. What the virtual CISO can decide alone, what needs an executive signature, and who inside the company signs a risk acceptance. Without this the role advises and nothing closes.
- Deliverables and cadence. The monthly report, the quarterly board paper, the risk register, and the review meeting that actually happens.
- Unused time. Whether it carries forward, and the cap.
- Incident terms. What response is included, what is billed separately, expected availability, and who does forensics.
- Exit. Notice period, and the handover pack: policies, the risk register, evidence, vendor records and credentials, in formats you keep. Work product should belong to you.
Insurance, confidentiality and the governing province round it out. The contract checklist and the interactive version cover the full list, and when a vCISO is not working describes the failure modes these clauses prevent.
Where to start
If you are not sure the role is the right purchase yet, run the need assessment first. If you are, the scope definer produces a scope statement and the job description page gives you language for a brief. Firms serving each market are listed on vCISO services in Canada. This directory is operated by TrazTech Inc.
Get quotes from Canadian vCISO providers
Tell us your headcount, your data, and what triggered the search. We will put it in front of firms that do this work in Canada.
Get matchedCommon questions
Is a virtual CISO the same as a vCISO and a fractional CISO?
Yes. The three terms name one role and the market uses them interchangeably. vCISO is simply the abbreviation of virtual CISO. Fractional borrows its framing from fractional CFO and leans on the idea of a slice of a full-time role, while virtual leans on the person not being in your office, but neither word changes the scope, the accountability or the contract. What does change things is whether you are buying a named individual or a shared support queue, so ask that instead of asking which label a firm uses.
Can a virtual CISO satisfy a customer that requires a named security officer?
Usually yes, provided the person is named in your documentation, reachable by the customer, and demonstrably doing the work. Enterprise buyers, banks, insurers and health systems commonly require a designated security function at their suppliers, and a part-time officer meets that requirement in most policies. What fails review is a title with nobody behind it, or a firm name where the policy asks for a person. Confirm the contract names the individual before you put them forward.
How many days a month does a virtual CISO actually need?
It depends on what is running. A steady program with no active certification often sits at one to two days a month. A company working towards SOC 2 or ISO 27001 with an audit date tends to need three to five while the evidence work is live, then falls back. A regulated company, or one recovering from an incident, runs higher. Set the number by listing the obligations and deadlines first and deriving the time from them, which is what the hours estimator on this site does.