A virtual CISO (vCISO) is an external security leader engaged for a defined fraction of time or scope. The arrangement works when the vCISO has a written mandate, direct access to decision-makers, reliable delivery capacity, clear incident authority and measurable outcomes. It fails when “CISO” is only a title attached to generic reports.
A vCISO can advise, coordinate and operate defined security processes, but accountable executives, risk owners and management bodies retain the decisions that law and governance assign to them. Under NIS2 Article 20, for example, the management body of an in-scope entity approves and oversees the cybersecurity risk-management measures.
When the model fits
A fractional model can fit when an organisation needs experienced leadership but not a permanent full-time role, needs interim cover, is building an ISMS or assurance programme, must coordinate a defined transformation, or needs independent challenge across a portfolio.
It may be the wrong model when daily executive presence is essential, the environment is extremely complex, conflicts cannot be separated, the provider lacks incident availability, or internal teams have neither authority nor capacity to implement decisions.
Do not decide from a universal employee threshold or claimed salary comparison. Scope the actual leadership and operating workload.
Define the mandate
Write down:
- reporting line and access to the board or management body;
- services, entities, locations and technology in scope;
- decision, recommendation and escalation authority;
- expected availability in ordinary work and incidents;
- internal teams and suppliers the vCISO may direct or coordinate;
- reserved management, legal, privacy and risk-acceptance decisions;
- deliverables, measures, records and meeting cadence;
- independence and conflict safeguards; and
- handover, knowledge transfer and exit.
Clarify whether the engagement supplies one named person, a team, or a service tier. Confirm backup and replacement arrangements before relying on the role.
Useful first-cycle outcomes
The first cycle should establish facts and decisions rather than produce a stock roadmap:
- confirm objectives, obligations and stakeholder commitments;
- validate systems, information, services and supplier dependencies;
- assess material risk and current control evidence;
- agree risk owners and priority treatment;
- establish incident, continuity and executive escalation;
- define measures and reporting that management can use;
- assign funded actions with owners and deadlines; and
- document residual risk and decisions.
If ISO/IEC 27001 or SOC 2 is in scope, the vCISO can coordinate readiness but cannot replace the independent certification body or CPA practitioner. If NIS2 is relevant, add entity and national-law analysis rather than claiming that an ISO programme is automatically sufficient.
Evaluate providers
Ask for evidence of:
- leadership in organisations with comparable services and risk;
- technical and regulatory depth relevant to the assignment;
- clear writing for executives and practical direction for operators;
- incident leadership and out-of-hours arrangements;
- capacity, named personnel and escalation coverage;
- secure handling of your data and privileged information;
- conflict identification and separation of incompatible work;
- professional references and insurance where appropriate; and
- portable documents, records and knowledge at exit.
Test a real scenario during selection: give the candidate incomplete facts about a supplier incident, competing recovery priorities and a possible reporting obligation. Evaluate the questions, decisions, uncertainty and escalation—not theatrical certainty.
Price the complete service
Compare proposals using the same scope: named personnel, time and availability, deliverables, meetings, travel, incident support, tooling, subcontractors, out-of-scope rates, transition and exit. A monthly fee is not comparable if one proposal excludes board work, incident response or operational follow-through.
Avoid generic market rates and guaranteed timelines. Price depends on mandate, risk, geography, complexity, availability and internal support.
Govern performance
Review whether the vCISO improves decisions and capability:
- material risks have named owners and current treatment;
- overdue exceptions and remediation are escalated;
- incidents and exercises produce verified improvement;
- evidence supports customer, audit and regulatory needs;
- supplier and continuity dependencies are visible;
- management receives candid, decision-ready reporting; and
- internal staff gain enough knowledge to avoid dependency.
For a scoped security-leadership and implementation engagement, see our cybersecurity services.
Sources and review
This guide was substantively reviewed on 8 August 2026. It removes unsupported salary, fee, company-size and speed claims and clarifies retained management accountability.
Robert Lozo, mag. iur., is a Partner at Vision Compliance specializing in EU regulatory compliance. He advises organizations on GDPR, NIS2, AI Act, and financial regulation, delivering audit-ready documentation and compliance roadmaps across regulated industries.