Some companies genuinely need the executive on payroll, and pretending otherwise would be selling. Three situations make the case. First, security as product: if buyers are effectively purchasing your controls — an infrastructure platform, a security vendor, a custodian of unusually sensitive data — the person who owns them belongs inside the building. Second, mandate: certain regulated environments and large enterprise contracts expect a named, dedicated senior security officer, and a fractional arrangement won’t satisfy the examiner reading the org chart. Third, sheer surface: thousands of employees, dozens of products, a live threat stream — enough decision volume to fill an executive calendar every single week.
There’s a quieter fourth reason: organizational weight. In a large company, security competes for budget and roadmap against other executives, and an outside voice — however good — doesn’t sit in those rooms all day. If your security function’s biggest problem is internal politics, a badge and a title are part of the fix.
We won’t print salary numbers — they vary by market and go stale fast. The structure is what matters: a full-time CISO is a senior-executive compensation package, plus the security engineers who do the actual implementing, plus a months-long search before day one. An executive without a team is a very well-paid author of recommendations, so the real commitment is a department, not a hire.
The fractional structure is different in kind, not just size: you buy a defined slice of executive judgment, and — in the bundled model — the execution team arrives in the same scope instead of as future headcount. The comparison worth making isn’t “executive versus contractor.” It’s “department you build versus program you subscribe to,” and the details of the second are on the vCISO pricing page.
The failure mode isn’t hiring a CISO — it’s hiring one two years before the job exists.
Watch for three. The board starts wanting security in the room quarterly rather than in the appendix. Product decisions start embedding security trade-offs weekly — features, architectures, customer commitments — which no outside calendar can attend. And the internal coordination load (dozens of engineering teams, several business units) becomes a daily management job rather than a governance one.
A provider paid on outcomes should be the one telling you this. When Agency sees an engagement cross those lines, the recommendation is to open the search — while we keep the program running so the incoming executive isn’t greeted by a fire.
Most companies don’t face a binary — they face a sequencing decision. The pattern that works: fractional coverage through the years when the workload is real but sub-executive, then a full-time hire when the signals above appear. Done right, the handover is an asset. Your first CISO inherits a documented risk register, running controls, an audit history, an evidence archive, and vendor and access cadences that fire on schedule — a program to lead, not a cleanup to survive.
That inheritance changes the hire itself. Instead of recruiting someone willing to spend year one building plumbing, you recruit for strategy and scale — a better candidate pool and a faster payback. Several Agency clients have made exactly this transition, with our vCISO team staying on through the handoff and, in some cases, continuing as the execution layer under the new executive. What that executive actually inherits, week by week, is laid out in what a vCISO does.
No fixed headcount, despite what hiring guides imply. The honest triggers are qualitative: regulatory or contractual expectations of a named in-house executive, security decisions embedded in daily product work, and internal coordination too heavy for an outside calendar. Companies hit those at very different sizes.
In our experience running buyer diligence, yes — what buyers actually evaluate is the program: certifications, questionnaire quality, incident readiness, and a named accountable leader who shows up on the call. A sharp fractional leader with a real program beats an overwhelmed full-timer with neither.
Compare structures. Full-time means a senior-executive compensation package plus the supporting engineers plus recruiting time — a department. Fractional means a scoped program fee that, in Agency’s bundled model, already includes the execution team. For startups the program side is published: packages run $2,500 to $12,500 all-in.
Generally yes — auditors, insurers, and most frameworks care that a qualified, named individual is accountable, not where their W-2 sits. Regulated corners that require an in-house officer are exactly the “full-time is right” cases this page flags. When in doubt, we’ll say which side of the line you’re on.
A transition window, not a cliff: the incoming CISO gets the risk register, roadmap, audit history, and evidence archive on day one, plus overlap time with the fractional leader. Many teams keep the engineering layer in place underneath the new executive — the hire changes who decides, not who does.