Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Visual overview of the Virtual CISO's five key service elements for cybersecurity governance.

Virtual CISO: A Clear Guide to All 5 Service Elements

A virtual CISO is an experienced security leader engaged part-time, across several
organisations, instead of hired as a full-time executive. The model exists because the demand for
security leadership arrived long before most companies were large enough to justify the salary —
and because the customer questionnaires now asking “who owns security?” do not accept “everyone”.

Virtual CISO: the five elements of the service and where the model fits badly
The five elements of a virtual CISO service, and the situation the model does not fit.

What a virtual CISO actually does

The common misconception is that this is fractional engineering. It is not. A virtual CISO is
accountable for the security programme, not for its implementation, and the work is mostly judgement
and governance rather than configuration.

Element What it involves
1. Risk ownership Maintaining the risk picture and putting decisions in front of the people who can make them
2. Programme governance Policy set, roadmap, budget input, board and audit committee reporting
3. Compliance and certification Getting and keeping whatever the market demands — ISO 27001, SOC 2, sector rules
4. Third-party assurance Customer questionnaires, due diligence, supplier assessment
5. Incident readiness Response plan, exercises, and being the person called at 2am

Element five is where the model is genuinely tested. A virtual CISO who is unreachable during an
incident is a governance consultant with a better title, and the engagement terms need to say plainly
what availability the client is buying.

Where a virtual CISO fits, and where it does not

It fits where an organisation needs the seniority but not the hours: a company under 200 people, a
regulated startup, a private equity portfolio company being prepared for diligence, or a business that
has just lost its security lead and needs continuity.

It fits badly where security work is overwhelmingly hands-on — a company needing a SOC built,
a network re-architected or a serious remediation programme executed. That is engineering capacity,
and a part-time leader cannot substitute for it. Selling a virtual CISO into that situation produces
an unhappy client within a quarter.

The documentation problem behind the model

The economics only work if the security leader is genuinely leading rather than typing. A CISO
working three days a month per client cannot spend two of them drafting an access control policy from
a blank page — and every client needs substantially the same policy set, differing in scope,
systems and risk appetite rather than in structure.

This is why practitioners in this model almost universally work from a maintained library and
tailor. The trap is licensing: most document packs are sold to a single organisation, which does not
cover deploying them across a client portfolio. Our guide to
white label compliance
templates
sets out the five terms to check before buying anything you intend to use this way.

One library, every client, licensed for it.

The Consultant Package licenses all 71 toolkits — 6,000+ documents across ISO 27001, SOC 2, GDPR, HIPAA, PCI DSS, NIS2, DORA, CMMC, ISO 42001 and more — to your whole firm, for unlimited client engagements, with clients keeping the deliverables you hand them. One-time $1,399, perpetual, 12 months of updates.

See the Consultant Package →

Structuring a virtual CISO engagement

  1. Define the days, and what happens when they run out. Two days a month is a
    different service from two days a week. State the allocation and the process for exceeding it, or
    every incident becomes an awkward invoice conversation.
  2. Name the decision rights. What can the virtual CISO decide alone, what do they
    recommend, and who accepts risk? Accountability without authority fails here exactly as it does in a
    PMO.
  3. Set the reporting line. To the CEO, the board, or an audit committee — and
    with what cadence. A security leader reporting to the person whose budget they are challenging is
    structurally compromised.
  4. Agree the first 90 days explicitly. Usually: current-state assessment, risk
    register, prioritised roadmap, and the two or three fixes that visibly reduce exposure.
  5. Write down incident availability. Response time, out-of-hours expectations, and
    what an incident does to the monthly allocation.
  6. Plan the exit from the start. The goal for a growing client is a permanent hire,
    and a virtual CISO who has made themselves impossible to replace has failed the engagement rather than
    secured it.

The independence question

A virtual CISO who builds the management system cannot also provide independent assurance over it.
If the client needs internal audit, that has to come from someone else — a different person in
your firm, or a peer arrangement with another practice. The same principle keeps certification bodies
out of consultancy, and it applies just as squarely inside a small practice. Our guide to
choosing a certification body
covers the client-side view.

Portfolio limits

The honest constraint on this model is how many clients one person can hold in their head. Each one
brings a distinct risk picture, a distinct architecture and a distinct set of relationships, and the
value of the role is context rather than throughput. Practitioners generally find the ceiling lower
than the diary suggests — the day that fits is not the same as the client you can genuinely
represent in a board meeting.

Pricing and packaging a virtual CISO service

The model breaks commercially in a predictable way: sold as a monthly retainer with an implied
day allocation, then consumed as though the retainer bought availability. Six months later the
practitioner is working double the days at half the effective rate and the client has no idea
anything is wrong.

Three mechanics prevent that. Separate the retainer from project work, so a
certification push is scoped and priced as its own engagement rather than absorbed. Report
consumption monthly
, in days used against days allocated, in the same pack as everything else
— a client who sees the number is a client who self-manages. And price incident
availability explicitly
if you are offering it, because a genuine out-of-hours commitment is
a real constraint on your life and should be paid for.

Tiering by what the client actually needs

A useful packaging is three levels. A governance tier that maintains the risk picture, the policy
set and board reporting. A compliance tier that adds getting and keeping a specific certification. And
a leadership tier that adds architecture input, supplier assurance and incident command. Each is a
defensible standalone service, and the ladder gives the relationship somewhere to grow.

What does not work is a single undifferentiated offer, because the range of what buyers mean by
virtual CISO is enormous — from “sign our questionnaires” to “run our security function” —
and quoting one price against that range guarantees mispricing in both directions.

Handing over to a permanent hire

The best outcome for a growing client is that they outgrow you, and how that transition is handled
decides whether it produces a referral or a grudge. Start it before it is needed: keep the risk
register, policy set, roadmap and supplier assessments in the client’s own systems rather than yours,
so there is nothing to migrate. Document the decisions and their reasoning, not just the outcomes
— an incoming CISO inheriting a set of controls with no record of why they were chosen will
reopen every one of them.

Then offer to stay for the overlap. Two or three months of advisory support alongside the new hire
costs the client little, gets the handover right, and is frequently where the next referral comes
from.

Frequently asked questions

What is a virtual CISO?
An experienced security leader engaged part-time and usually across several organisations, providing
security leadership and accountability without a full-time executive hire.

How is it different from a security consultant?
A consultant delivers a defined piece of work and leaves. A virtual CISO holds an ongoing
accountability for the security programme, including being the escalation point when something goes
wrong.

Can a virtual CISO get us ISO 27001 certified?
They can lead the programme, but they cannot audit or certify the system they built. Certification
comes from an accredited certification body, and internal audit needs someone independent of the
implementation.

How many days a month does it take?
It depends entirely on the size of the organisation and whether a certification is in flight. What
matters is that the allocation is written down along with what happens when it is exceeded.

When should a company hire a permanent CISO instead?
When the hours needed approach full-time, when the security team grows past a couple of people, or
when the business becomes regulated in a way that requires a named accountable individual on staff.

Where this leaves you

The virtual CISO model works when the client needs seniority rather than hours, and it fails when
it is sold as a substitute for engineering capacity. Define the days and what happens when they run
out, name the decision rights, set the reporting line above the budget you are challenging, write down
incident availability, and plan the exit from the first month. On the delivery side, the economics
depend on not drafting from scratch — which makes a maintained, properly licensed document
library less of a convenience and more of a precondition for the model working at all.

References

More for compliance consultants

All 71 toolkits are licensed for client work in the Consultant Package, or start with the free ISO templates.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.