Managed vCISO
vCISO or in-house CISO
What this is
A virtual CISO provides fractional security leadership on a retainer; an in-house CISO is a permanent employee. The choice turns on four things: whether the organisation needs full-time leadership capacity or full-time accountability, how quickly the role must be filled, whether the work is programme-shaped or continuous, and how much delivery capability sits behind the leader.
The problem
Both answers are right for someone. The question is which situation you are in.
The comparison is usually framed as a cost question and that is the least interesting dimension. A vCISO costs less than a full-time hire, everyone knows it, and cost alone would make the decision trivial - which it plainly is not, or nobody would ever hire a CISO.
The dimensions that actually decide it are capacity versus accountability, speed, shape of work and depth of delivery. An organisation needing a security leader in the building every day, embedded in culture and hiring a team, needs an employee. An organisation needing senior accountability, a certification programme delivered and a board reporting rhythm established needs neither more nor less than fractional leadership with a delivery team behind it.
Getting this wrong in either direction is expensive. Hiring too early produces an underused senior person doing hands-on work they were not hired for, who leaves. Going fractional too late means a growing internal team reporting to someone who is present four days a month.
Who this is for
- Companies who have approved a CISO hire and want to sense-check the decision before recruiting.
- Organisations who have been searching for a CISO for months without a placement.
- Firms who have lost a CISO and are deciding whether to replace or restructure.
- Boards asking why the security roadmap requires a six-figure hire to begin.
- Companies with a certification deadline that arrives before any hire realistically could.
Delivery
How the engagement actually runs
Sprints inside your engineering cycle, with findings arriving continuously rather than a report arriving at the end. Durations are elapsed time for a typical scope, and get re-scoped against your estate before anything is committed.
- 013-5 days
Define the requirement
Separate leadership, programme and operational needs, because conflating them is what produces a job description nobody can fill.
- 021 week
Assess the gap
What is genuinely uncovered today and what the cost of the gap is, in commercial terms rather than risk-register terms.
- 033-5 days
Compare honestly
Both options against your numbers and your timeline, with the case for hiring made properly where it applies.
- 042-3 days
Decide and plan
A recommendation, and a transition plan if the answer changes over the next eighteen months - which it often should.
Deliverables
What you actually receive
Artefacts your team owns and can maintain after the engagement, not a report that ages the moment it lands.
| Deliverable | What it contains | When |
|---|---|---|
| Requirement definition | What the role genuinely needs to cover in your organisation, separated into leadership judgement, programme delivery and hands-on operations - which are three different jobs frequently written as one. | Week 1 |
| Coverage gap analysis | What is currently uncovered, what is covered informally by people whose job it is not, and what would break if they left. | Week 1-2 |
| Comparison against your numbers | Both options costed against your actual requirement - including recruitment, employer costs, ramp time and the delivery capability behind the leader. | Week 2 |
| Recommendation with reasoning | A clear recommendation and the reasoning, including the case for hiring where that is the honest answer. | Week 2 |
| Transition plan | If fractional now and permanent later, what the handover looks like and what the vCISO leaves behind for whoever arrives. | Week 2 |
FAQ
Questions people actually ask
When is hiring an in-house CISO the right answer?
How much does a vCISO cost compared with hiring?
Can a vCISO satisfy a regulatory requirement for a named security officer?
How long does it take to hire a CISO?
What happens to a vCISO engagement when we do hire?
More in Managed vCISO
Start
Three ways in, depending on how close the deadline is.
- Book it
Book a discovery call
Thirty minutes, no deck. We work out whether there is a real engagement here, and say so if there is not.
- Go
Check the EU AI Act applies
Six questions, a dated list of the obligations that reach you, and a calendar file so the deadlines land somewhere you will see them again.
- Go
Request a roadmap
You know the obligation and the deadline. We scope the sprints, the deliverables and the dates.
Or just email a human: hello@cloudgap.ai
We reply within24 hours