What vCISO services actually cover (and what they do not)
A plain-English look at virtual CISO (vCISO) services: what senior security leadership on a retainer includes, what stays with your MSP, and when the model fits.
If you have been reading about vCISO services, you have probably seen two extremes. One is a glossy promise that a remote CISO will "own cybersecurity." The other is a cheap hourly consultant who writes a policy PDF and disappears.
Neither is useful if you are a mid-market company that needs a real security seat without a full-time hire.
Here is the version we use with leadership teams.
What a virtual CISO is
A virtual CISO (also called a fractional CISO) is a senior security leader who works with you on a monthly retainer. Same kinds of decisions a full-time CISO would make. Different contract. You are buying ownership of the security program, not a stack of tickets.
Typical work looks like:
- Security roadmap and priorities the CEO or board can follow
- Policies and controls that match how you actually operate
- Vendor and third-party risk reviews
- Customer security questionnaires (review or response, depending on depth)
- Audit and compliance cadence (SOC 2 and similar, when that is in play)
- Incident response leadership: who decides, who calls whom, what gets documented
That last word matters. Leadership is not the same as staffing a 24/7 SOC.
What vCISO services are not
They are not your helpdesk. Password resets, laptop imaging, and printer tickets stay with your MSP or internal IT.
They are not a one-week "AI transformation" workshop with a new logo on the slide.
They are not a replacement for every tool you already pay for. A good vCISO often cuts noise: fewer overlapping products, clearer owners, less spreadsheet theater.
If a prospect only wants cheaper break-fix support, a vCISO retainer is the wrong product. Say that early.
Who this fits
The pattern we see most often:
- Roughly 50 to 500 employees
- No named CISO on the leadership page
- Real pressure from customers, insurers, or an upcoming audit
- An MSP already in place (or a thin internal IT bench)
You do not need to be a Fortune 500. You do need a reason the seat cannot stay empty: questionnaires blocking deals, board questions without answers, or a compliance date that is not moving.
Nonprofits and associations hit the same wall when boards and insurers ask for written security and AI-use process. The model is the same. The buying cycle is often slower.
How depth usually scales
Market retainers for serious vCISO work commonly sit in a few bands. Light advisory is a handful of hours a month: roadmap, reviews, accountability. Managed depth adds policy ownership, questionnaire lead, and a steadier reporting rhythm. Embedded work is closer to a part-time executive seat.
We start most conversations on advisory or managed depth. Embedded and hard on-call promises only make sense when capacity and insurance are honest.
For a clearer cost walkthrough, see How much does a virtual CISO cost?.
How this shows up at Bade Group
We treat vCISO work as a named leadership engagement. You get a senior person who can talk to your executives without translating everything into vendor jargon. Your MSP (or internal team) keeps day-to-day tickets. We keep the program: priorities, vendors, policy, questionnaires, and the story your board expects to hear.
If you are hiring a full-time CISO, a retainer can still bridge the gap so the seat is not empty through the search. The job posting is a signal. The buyer is still usually the CEO or CFO.
Request a conversation
Share context under NDA. We typically respond within two business days with a partner-led discussion, not a generic sequence.
Request a conversation