The seat is executive. A vCISO decides what your security program must accomplish and in what order, then puts their name on it: the risk assessment, the roadmap, the board update, the customer security call, the auditor interview. What the seat is not is the person grinding through tickets and evidence — that delivery layer is a separate function, described under managed GRC.
The label gets stretched. Some vendors sell a policy-template subscription and call it a vCISO; others staff a genuine former security executive a few hours a week. Ask what artifacts you would own after a quarter — the answer separates the two. The deliverable-by-deliverable version of the role lives at What Does a vCISO Do.
The model fits companies that need credible security leadership — for an audit, an enterprise deal, a board mandate — before a full-time executive makes financial sense. That describes most startups and much of the mid-market. Agency’s vCISO service staffs the seat with senior practitioners and backs them with delivery engineers, so the strategy shows up with hands attached; scoping and rates are published at vCISO Pricing. Growth changes the answer eventually: the role converts to a permanent hire once security becomes a daily executive concern.