Strip the acronym away and the role is accountability. Someone in the company has to be able to say — to a buyer, an auditor, an insurer, or the board — “here is what could hurt us, here is what we’ve decided to do about it, and here is the proof,” and be right. Everything a vCISO does in a given week traces back to keeping those three statements true.
What makes the job fractional-friendly is its rhythm. Security leadership is not forty hours of decisions a week; it’s a handful of high-stakes judgment calls wrapped in a large volume of recurring operational work — evidence, reviews, questionnaires, vendor checks. A good vCISO engagement splits those layers deliberately: the leader makes the calls, and an operating layer keeps the machinery running between them.
That split is the difference between vCISO offerings. Some sell you only the judgment and leave the machinery to your engineers. Agency’s version ships both: a named security leader backed by U.S.-based forward-deployed engineers, supercharged by proprietary AI, so the roadmap and the work it generates live with one accountable provider.
A real engagement covers all six. If one is missing, you bought advice, not leadership.
Maintains a risk register tied to the actual business — not a template — and makes the accept, mitigate, or transfer call on each entry. Revisits it when something changes: a new vendor, a new data type, a new market.
Turns the register into a sequenced, costed roadmap, and defends it to whoever signs the checks. Just as important: tells you which tools and certifications not to buy yet.
Decides which frameworks matter for your buyers and in what order, then owns the calendar — readiness, observation windows, audits, renewals — across SOC 2, ISO 27001, HIPAA, GDPR, FedRAMP, CMMC 2.0, ISO 42001, HITRUST, and US data privacy laws as needed.
Owns the security story that closes deals: questionnaires, trust-center content, and the calls where an enterprise buyer wants to “meet security” before signing.
Keeps a response plan people have actually rehearsed, knows who gets called at 2 a.m., and runs the room when something happens — including the judgment calls about disclosure and customer notice.
Translates posture into decisions leadership can act on: what improved, what’s exposed, what it costs to fix. Metrics that mean something, not a wall of dashboard green.
A composite month from live engagements. The cadence varies by company; the shape doesn’t.
A security engineer builds and fixes: hardens infrastructure, tunes detection, patches what scanners find. Their output is systems. A vCISO decides which of that work matters most, in what order, and answers for the outcome — they might never touch a terminal, but they own what the terminal work adds up to.
A compliance manager runs the paperwork engine for frameworks already chosen: evidence deadlines, policy renewals, audit logistics. Valuable — and much narrower. The vCISO chooses the frameworks, owns the risks that live outside any audit’s scope, and carries the conversations a coordinator can’t: pricing a risk for the board, or defending a control decision to an enterprise buyer’s security team.
Mature programs need all three functions. The practical question at most growing companies is who supplies the other two while headcount stays flat — which is why Agency pairs the leader with a managed execution team instead of leaving the engineering and coordination to whoever has slack that sprint.
Ninety days in, you should be able to point at artifacts: a risk register you recognize your company in, a roadmap with owners and dates, an audit calendar, questionnaires going out on time, and at least one report written for leadership rather than for the vendor’s own renewal. If all you can point at is a slide deck from month one, you hired a very expensive author.
The other tell is load. A working vCISO engagement takes work off your engineers — evidence requests stop landing in their sprint, buyer reviews stop routing to the CTO. If security tasks on your roadmap multiplied instead, the leadership came without hands. What that split should cost is its own question — covered honestly in vCISO pricing.
Think cadence, not hours. The steady state is a weekly operating rhythm — reviews, decisions, escalations — that surges around audit windows, incidents, and big deals. Scope drives it: a company with one framework and light buyer diligence needs far less of the leader’s calendar than one juggling three audits.
Depends on the model. Advisory-only vCISOs direct, and your team inherits the doing. Agency bundles the doing: engineers and AI agents under the vCISO handle remediation, evidence, and questionnaires, so the roadmap doesn’t become your engineers’ backlog.
Usually the CEO at startups and the CTO or COO at larger companies — functioning as a peer of the exec team, not a vendor on a ticket queue. What matters is standing access to leadership and the board, because half the job is making risk decisions someone senior has to ratify.
Yes — that’s a large share of the value. A named security leader joins buyer diligence calls, fields the auditor relationship, and signs the insurer’s attestations. Ask any provider who exactly shows up on those calls; “someone from our team” is the wrong answer.
A current risk register, a dated roadmap, adopted policies, an audit calendar, evidence flowing in your GRC platform, and a leadership-ready posture summary. Those artifacts are the deliverable — and they’re what a future full-time CISO inherits cleanly if you eventually hire one.