Skip to content

Managed vCISO

vCISO or in-house CISO

What this is

A virtual CISO provides fractional security leadership on a retainer; an in-house CISO is a permanent employee. The choice turns on four things: whether the organisation needs full-time leadership capacity or full-time accountability, how quickly the role must be filled, whether the work is programme-shaped or continuous, and how much delivery capability sits behind the leader.

The problem

Both answers are right for someone. The question is which situation you are in.

The comparison is usually framed as a cost question and that is the least interesting dimension. A vCISO costs less than a full-time hire, everyone knows it, and cost alone would make the decision trivial - which it plainly is not, or nobody would ever hire a CISO.

The dimensions that actually decide it are capacity versus accountability, speed, shape of work and depth of delivery. An organisation needing a security leader in the building every day, embedded in culture and hiring a team, needs an employee. An organisation needing senior accountability, a certification programme delivered and a board reporting rhythm established needs neither more nor less than fractional leadership with a delivery team behind it.

Getting this wrong in either direction is expensive. Hiring too early produces an underused senior person doing hands-on work they were not hired for, who leaves. Going fractional too late means a growing internal team reporting to someone who is present four days a month.

Who this is for

  • Companies who have approved a CISO hire and want to sense-check the decision before recruiting.
  • Organisations who have been searching for a CISO for months without a placement.
  • Firms who have lost a CISO and are deciding whether to replace or restructure.
  • Boards asking why the security roadmap requires a six-figure hire to begin.
  • Companies with a certification deadline that arrives before any hire realistically could.

Delivery

How the engagement actually runs

Sprints inside your engineering cycle, with findings arriving continuously rather than a report arriving at the end. Durations are elapsed time for a typical scope, and get re-scoped against your estate before anything is committed.

  1. 013-5 days

    Define the requirement

    Separate leadership, programme and operational needs, because conflating them is what produces a job description nobody can fill.

  2. 021 week

    Assess the gap

    What is genuinely uncovered today and what the cost of the gap is, in commercial terms rather than risk-register terms.

  3. 033-5 days

    Compare honestly

    Both options against your numbers and your timeline, with the case for hiring made properly where it applies.

  4. 042-3 days

    Decide and plan

    A recommendation, and a transition plan if the answer changes over the next eighteen months - which it often should.

Deliverables

What you actually receive

Artefacts your team owns and can maintain after the engagement, not a report that ages the moment it lands.

Deliverables for vCISO or in-house CISO, with what each one contains and when it lands
DeliverableWhat it containsWhen
Requirement definitionWhat the role genuinely needs to cover in your organisation, separated into leadership judgement, programme delivery and hands-on operations - which are three different jobs frequently written as one.Week 1
Coverage gap analysisWhat is currently uncovered, what is covered informally by people whose job it is not, and what would break if they left.Week 1-2
Comparison against your numbersBoth options costed against your actual requirement - including recruitment, employer costs, ramp time and the delivery capability behind the leader.Week 2
Recommendation with reasoningA clear recommendation and the reasoning, including the case for hiring where that is the honest answer.Week 2
Transition planIf fractional now and permanent later, what the handover looks like and what the vCISO leaves behind for whoever arrives.Week 2

Frameworks this touches

FAQ

Questions people actually ask

When is hiring an in-house CISO the right answer?

When the organisation needs full-time presence rather than full-time accountability. Concretely: when there is a security team to build and lead, when security is deeply embedded in the product such that constant engineering involvement is required, when regulatory obligations require an employed approved person, when the organisation is large enough that the role is genuinely a full week of work, or when culture change is the primary objective and that requires someone in the building.

How much does a vCISO cost compared with hiring?

A vCISO is a monthly retainer scaled to the days required; a permanent CISO is salary plus employer national insurance, pension, benefits, recruitment fees typically 20 to 30 per cent of first-year salary, and the ramp period before they are effective. The retainer is a fraction of the fully loaded cost, and it also includes delivery capability that a single hire does not bring. Cloudgap publishes indicative figures only where they reflect delivered engagements; those are being confirmed before publication rather than estimated here.

Can a vCISO satisfy a regulatory requirement for a named security officer?

Often yes, depending on the regime. Many frameworks and supervisory expectations require a named, accountable individual with appropriate seniority, authority and board access, and an appropriately mandated vCISO satisfies that. Some regimes require the individual to be an employee or hold an approved-person status. This must be checked against your specific obligation rather than assumed either way.

How long does it take to hire a CISO?

Three to six months from opening the search to a start date is typical, and longer where the specification is unrealistic or the compensation is below market. Notice periods at that level are commonly three months. Against a certification deadline or an enterprise deal that is blocked now, that timeline frequently makes the hire irrelevant to the immediate problem, which is one of the more common reasons organisations start fractional.

What happens to a vCISO engagement when we do hire?

It should make the hire more successful, not compete with it. A vCISO engagement leaves a documented risk register, a live roadmap, an operating policy set, a functioning governance forum and a certification position - which is what a new CISO would otherwise spend six months building before doing anything visible. The usual pattern is that the vCISO supports the recruitment, hands over, and steps back to an advisory role for a quarter.