What Is a Virtual CISO (vCISO)? A Board-Level Guide

Most mid-sized and private equity backed businesses reach a point where cyber risk has outgrown the people managing it. The board wants assurance. An insurer or a large customer wants evidence. An acquirer's due diligence team wants a named security leader they can question. Yet a full-time Chief Information Security Officer, at £150,000 or more plus package, is hard to justify for an organisation that needs senior judgement more than it needs another permanent hire.

What Is a Virtual CISO (vCISO)? A Board-Level Guide - Richard Keenlyside, Fractional CIO, CTO and CISO
What Is a Virtual CISO (vCISO)? A Board-Level Guide

A virtual CISO, or vCISO, closes that gap. It gives you experienced, board-level security leadership on a part-time or retained basis: the strategy, governance and assurance of a CISO, without the cost or commitment of a permanent appointment. This guide explains what a vCISO does, how the role differs from a full-time or fractional CISO, what it costs, and when your business genuinely needs one.

What a virtual CISO (vCISO) is

A virtual CISO is an experienced security executive who leads your cyber and information security function on a flexible, ongoing basis. The word "virtual" refers to the operating model, not the seniority. A good vCISO carries the same accountability as a permanent CISO: setting the security strategy, owning the risk position, reporting to the board, and standing behind the organisation when a regulator, an auditor or an acquirer asks hard questions.

The difference is how the time is bought. Instead of a full-time salary, you engage a vCISO for a defined number of days a month against clear priorities. For most SMEs and portfolio companies, that is enough. Security leadership at this level is about the quality of the decisions, not the number of hours in the building.

What a vCISO actually does

The role is often misunderstood as outsourced IT security or a managed service. It is neither. A vCISO leads; the tooling and the monitoring sit beneath the role, not above it.

Security strategy and board reporting

A vCISO translates cyber risk into language the board can act on. That means a clear picture of where the organisation is exposed, what it would cost to fix, and which risks the board is choosing to accept. It also means a reporting rhythm the board can trust, so cyber stops being a once-a-year fright and becomes a managed part of governance.

Risk and compliance

Most engagements involve a certification or a regulatory driver. A vCISO owns the roadmap to standards such as ISO 27001, Cyber Essentials Plus, SOC 2, and readiness for regimes including GDPR, NIS2 and DORA. I have taken a regulated FinTech to ISO 27001 in nine months and delivered GDPR and MiFID II compliance in parallel, so I write these roadmaps from delivery experience rather than theory.

Incident readiness

The value of a vCISO is proven before an incident, not during one. That means tested response plans, clear board and executive roles, and a decision framework agreed while everyone is calm. Outsourcing and centralising a Security Operations Centre, as I have done across a multi-country manufacturing group, gives you detection and response capability without building it in-house from scratch.

Supplier and technology assurance

Cyber risk increasingly enters through the supply chain and the technology estate. A vCISO sets the standards suppliers must meet, reviews the controls behind your critical systems, and makes sure security is a factor in procurement rather than an afterthought. Done well, this also removes cost: disciplined vendor and licence management has delivered more than £20 million in savings across engagements I have led.

vCISO vs full-time CISO vs fractional or interim CISO

The terminology causes real confusion, and it matters when you are deciding what to buy.

vCISO vs a full-time CISO

A full-time CISO makes sense once security is a daily, in-house discipline with a team to lead, typically in larger or highly regulated organisations. Below that scale, a full-time hire is often under-utilised and hard to recruit. A vCISO gives you the same seniority and accountability, sized to what the business actually needs, and is far quicker to put in place.

vCISO, fractional CISO and interim CISO

  • A vCISO or fractional CISO is an ongoing, part-time arrangement. The same person leads your security function over the long term, a few days a month.
  • An interim CISO is a full-time appointment for a fixed period, usually to cover a gap, steady the function after a departure, or lead through a specific event such as a breach or an acquisition.

In practice I provide all three, and the right one depends on whether you need steady long-term leadership or focused, full-time cover for a defined period.

How much does a vCISO cost?

vCISO engagements are usually priced one of two ways: a monthly retainer for an agreed number of days, or a day rate drawn down as needed. UK day rates for genuinely board-level security leadership typically sit well above those for hands-on technical roles, which is why the model works. You are buying a small amount of very senior time, not a large amount of junior time.

The right way to judge cost is against the alternative. A permanent CISO is a six-figure fixed commitment plus recruitment and package. A vCISO gives you a fraction of that cost for the leadership that matters, and the spend scales with the work: heavier during a certification push or an acquisition, lighter once the function is stable. For most SMEs and PE-backed companies, that flexibility is the point.

When your business needs a vCISO

The trigger is rarely subtle. You should be considering a vCISO when:

  • The board is asking for cyber assurance it cannot currently get.
  • A customer, insurer or regulator now requires a named security leader or a certification such as ISO 27001 or Cyber Essentials Plus.
  • You are heading into, or coming out of, a private equity transaction, and cyber has surfaced in due diligence.
  • You have suffered an incident, or a near miss, and realised no one owns the response.
  • Security decisions are being made by IT, or by no one, with no board-level owner.
  • You cannot justify or recruit a full-time CISO, but the risk is real and growing.

Any one of these is enough. Two or more, and the gap is already costing you.

What good looks like in the first 90 days

A credible vCISO does not arrive with a generic checklist. The first month is spent understanding the business, the risk appetite and the real exposures, then agreeing the two or three things that matter most with the board. The second and third months turn that into a prioritised roadmap, a working reporting rhythm, and early, visible progress on the highest risks. By day 90 the board should have a clear view of where it stands, where it is heading, and what it is spending to get there. That clarity, more than any tool, is what the role delivers.

Frequently asked questions

What is a virtual CISO (vCISO)?

A virtual CISO is an experienced security executive who leads your cyber and information security function on a part-time or retained basis, providing the strategy, governance and board-level assurance of a Chief Information Security Officer without the cost of a full-time hire.

What is the difference between a vCISO and a CISO?

The role and accountability are the same. The difference is the operating model: a full-time CISO is a permanent, in-house appointment, while a vCISO delivers the same leadership flexibly, for an agreed number of days, which suits organisations that need senior judgement more than daily headcount.

What does a vCISO actually do?

A vCISO sets the security strategy, owns the organisation's risk position, reports cyber risk to the board, leads certification and compliance work such as ISO 27001, prepares the business for incidents, and holds suppliers and technology to a clear security standard.

How much does a vCISO cost?

Most vCISO engagements are priced as a monthly retainer for an agreed number of days, or a day rate drawn down as needed. It is a fraction of the six-figure fixed cost of a permanent CISO, and the spend scales up or down with the work.

When does a business need a vCISO rather than a full-time CISO?

When the risk is real but a full-time hire cannot be justified or filled: typically a mid-sized or PE-backed business facing a certification requirement, a board asking for assurance, or a due diligence process, without existing board-level security leadership in place.

Is a vCISO the same as a fractional or interim CISO?

A vCISO and a fractional CISO are effectively the same thing: ongoing, part-time security leadership. An interim CISO is different, being a full-time appointment for a fixed period, usually to cover a gap or lead through a specific event.

Bring board-level security leadership into your business

If your board needs cyber assurance it cannot currently get, a virtual CISO is often the fastest, most cost-effective way to put credible security leadership in place. I provide vCISO, fractional CISO and interim CISO support to UK SMEs and private equity backed businesses, from certification and board reporting through to incident leadership and due diligence.

You may also find it useful to read why your business needs an interim CISO for incident response leadership and do you need a CIO, a CISO, or both. Book a confidential conversation if you would like to discuss what the right model looks like for your business.