At some point every growing company has the conversation. A customer’s security questionnaire lands on the CFO’s desk. The cyber insurance renewal asks who is accountable for security. A board member asks who the CISO is, and the honest answer is “our IT director, when he has time.”
The instinct is to open a requisition for a CISO. Sometimes that is right. More often, for a company between roughly fifty and five hundred people, it is early, and the better answer is a virtual CISO: an experienced security executive who works with you on a retainer, part of the week, with the same accountability but without the full-time cost. Here is how I think about the choice.
Ask what the job actually is
A CISO’s job at a large enterprise is running a security organization: a team, a budget, a tool stack, a program of work. At a two-hundred-person company there is no security organization to run. The job is:
- Deciding what the company should be protecting and against what
- Setting the policy and the standard, and making sure someone follows it
- Answering the board, customers, auditors, and insurers credibly
- Choosing and overseeing the few vendors and tools that matter
- Owning the response when something goes wrong
That is executive judgment work, and it does not take forty hours a week at this scale. It takes the right ten or fifteen, consistently, from someone who has done it before. The hours that remain in a full-time role tend to get filled with work that a security engineer, an MSP, or a compliance analyst should be doing at a fraction of the cost.
When full-time is the right answer
Hire a full-time CISO when:
- Security is the product. If you sell trust (a fintech, a security vendor, a healthcare platform handling large volumes of PHI), customers will expect a named executive whose whole job is this, and the role will have a team under it.
- You have a security team to lead. Once you have three or more security-specific hires, they need a manager who is present, and the vCISO model stretches thin.
- Regulatory exposure demands it. Some regulated entities are expected to have a designated, full-time security officer. Your counsel will tell you if you are one.
- You are past roughly five hundred people or heading there fast. The coordination work alone starts to justify the role.
When a virtual CISO is the right answer
A vCISO fits when the company needs the executive function but not the executive’s full week:
- You have an IT function (in-house or an MSP) that can execute, but nobody setting direction or owning risk
- Customers, insurers, or a board are asking for accountable leadership and a real program
- You are preparing for SOC 2, HIPAA, or a similar framework and need someone to own it
- A PE sponsor expects a portfolio-standard security posture and wants a named owner
- You want to defer a full-time hire without deferring the work
The model has a second advantage that is easy to underrate: you get to see what the role actually needs before you write the job description. Many companies that start with a vCISO discover after a year that what they need to hire full-time is a security engineer or a GRC lead, not a CISO, and that the executive function is fine at part-time for a while longer.
The cost comparison, honestly
A full-time CISO in Texas is a senior executive salary plus benefits, equity, recruiting, and typically three to six months of vacancy before the person starts. A vCISO retainer is a fixed monthly fee for a defined block of hours, starting in weeks.
We publish our retainer tiers with the figures labeled illustrative, because scope drives the number, and we built a cost calculator so you can see the comparison for your own size and risk profile. The calculator uses published market ranges, not our opinion of what you should pay. The point is not that the vCISO is cheaper (it almost always is); it is that the cost difference is large enough to fund the engineering and tooling the program actually needs.
What to watch for either way
With a full-time hire: the long search, the risk of hiring a strong engineer who has never briefed a board, and the tendency for the role to become a compliance clerk if the CEO does not back it.
With a vCISO: make sure the retainer buys judgment and accountability, not a monthly report. Ask who actually shows up, how the escalation works when there is an incident at two in the morning, and whether the person has held the role in-house before. A vCISO who has never been the one accountable is an advisor, which is a different thing.
A simple test
If you removed the word “CISO” from the conversation and asked “who is accountable for security risk at this company, and is that person qualified and resourced to be?”, what is the answer today?
If it is a name, a real program, and a budget, you are ahead of most. If it is “sort of the IT director,” you need security leadership now, and the question of full-time versus virtual is about how much of it you need this year. That is a conversation we are glad to have without a sales pitch: book a 15-minute intro call.
More insights
What PE Firms Should Ask About Cybersecurity Before Close
The diligence questions that reveal real risk — and the ones that just generate paperwork.
Why AI Governance Is Becoming a Board-Level Issue
Regulators and customers are starting to ask how you govern the AI tools you’ve already adopted.
SOC 2 vs. HIPAA: Choosing the Right Path for HealthTech
The two frameworks overlap more than most teams expect — and the order you tackle them in matters.