The security knowledge can be identical — plenty of consultants are former CISOs. What differs is the shape of the engagement. Consulting is scoped to an artifact: assess this, document that, remediate these. When the statement of work completes, so does the accountability; the findings, the auditor’s follow-ups, and next quarter’s questionnaire all belong to you again.
A vCISO signs up for a standing role. There is no “between engagements” — the audit calendar, the buyer calls, and the surprise incident all land on the same named person, quarter after quarter. Continuity compounds too: by month six they know your environment well enough that decisions take minutes, where a returning consultant would open with another discovery phase.
Consultants remain the right buy for bounded problems: a point-in-time architecture review, a niche assessment, an expert second opinion. The mistake is buying a deliverable when what you need is an owner. The standing role is described in what a vCISO does; Agency’s version — where the leader arrives with an execution team rather than a report template — is on the vCISO services page.
Sometimes — but watch what the contract says, not the title. If the renewal still reads like a series of deliverables, you have a repeat consultant. The upgrade is real when someone accepts standing ownership of outcomes: the risk register, the audit dates, the buyer conversations.
Regularly, and it works well: the vCISO owns the program and pulls in specialist consultants for point problems — a hardware assessment, an unusual regulation, a deep code review. The important part is that specialists report into an owner, so their findings become someone’s job to close.