HireACISO

When a vCISO engagement is not working

The usual failure is not a bad vCISO. It is an engagement scoped as advice when the company needed delivery, or a company with nobody free to do the work. Both are fixable in month two and expensive in month eight.

Last reviewed 2026-09-01Written by Jacob Masse, TrazTech Inc.

If three months in you have documents but nothing has changed, the engagement is not working, and the cause is one of four things: the scope was advisory when you needed delivery, nobody internal has time to implement, the vCISO is working to a framework nobody asked for, or the person on the monthly call is not the person who was sold to you. Each has a different fix and only the last one requires changing providers.

Six signs, and what each one means

Failure signals and their most likely cause
What you are seeingUsual causeFix
Policies arrived, nothing else has Template-led delivery, or an advisory scope on a delivery problem Re-scope to program leadership with named deliverables and dates
The same items roll over every month No internal capacity, not a vCISO problem Fund implementation hands, or shrink the roadmap to what you can actually do
Reports reference a framework nobody asked you for One template, applied regardless Send the customer or insurer request in their words and ask for the work to be re-aimed at it
A different person each month Bench delivery behind a senior name Invoke or add the named individual clause. See the contract checklist
You cannot get them for a customer call No response commitment in the agreement Add response times, or stop naming them as your security officer
The board paper says the same thing as last quarter The program has stalled and nobody has said so Ask for a written statement of what is blocked and who is blocking it

The failure that is usually yours

The most common cause of a disappointing engagement is that the company has nobody free to do the remediation work. A vCISO with no engineering capacity behind them produces an accurate backlog and no change, and then both sides spend six months being frustrated with each other about it.

Two options. Fund implementation alongside the retainer, which for a company of 100 people is often another $4,000 to $10,000 CAD a month of contract engineering or managed IT time. Or cut the roadmap down to the two or three items you can land this quarter and accept the rest in writing in the risk register. Both beat paying for advice you cannot act on.

The reverse check, before you blame the provider

Look at how many of the last quarter's items were blocked on a decision only you could make. If it is most of them, the engagement is not failing, it is waiting. A vCISO can chase, and cannot approve budget, prioritise against the product roadmap or overrule your CTO. If nobody internally is doing that work, changing providers changes nothing.

How to raise it

  1. Write down what you expected by now, in one paragraph, in your own words. Not against the contract, against what you thought you were buying.
  2. Put it in an email before the call, so the provider can prepare rather than defend.
  3. Ask for one thing: a written 30 day plan with named deliverables and the internal decisions they need from you. Providers who are going to fix it will produce it in a week.
  4. Set a date to review it. Thirty days, not the next quarterly.
  5. If the plan does not land or the deliverables slip again, start the exit. Two failed 30 day plans is enough evidence.

Leaving without losing the work

The cost of changing providers is not the notice period, it is the year of context that walks out with them. Before the last day, get the risk register as a spreadsheet, the policy set in an editable format, the evidence collected so far, the vendor assessments, any auditor correspondence, and a written handover note naming what is open and who owns it.

If your agreement did not specify the exit package, ask anyway. Most providers will hand it over, and the ones that will not have told you something useful about why the engagement went the way it did. If you are replacing rather than stopping, the questions to ask the next provider are on how to choose a vCISO. Ask too whether what you need now is a full-time hire.

Replace an engagement that is not delivering

Changing providers is easier than most companies assume, and cheaper than another quarter of nothing. Tell us what you need and compare who else is available.

Get matched

Common questions

How long should we give a new vCISO before judging?

Ninety days. By the end of month three you should have an inventory, a gap assessment, a risk register with owners and a costed roadmap. If those five artifacts do not exist, the engagement is behind regardless of how good the conversations have been. The schedule is on the first 90 days.

Can we reduce the retainer instead of ending it?

Often the right answer. If the program is running and the problem is that you are paying for 30 hours and using 10, step down to an advisory retainer rather than leaving. Providers generally prefer a smaller ongoing engagement to a cancellation and will agree to it mid-term.

Should we tell our auditor or customers we changed vCISO?

Tell the auditor, because the person who designed a control being gone mid-window is something they will find anyway and it is better volunteered. Customers only need to know if you named the individual to them, in which case send the replacement name before they notice.