Skip to main content
Why BreachCraft
6 min read

What a Part-Time CISO Actually Does (And Doesn't Do)

What a fractional CISO handles day to day, the work it will never cover, and why we staff vCISO engagements with a full team behind one point of contact.

What a Part-Time CISO Actually Does (And Doesn't Do)

Virtual CISO services have gotten common enough that the label stopped meaning much. Two providers can both sell you a “vCISO” and deliver very different things: one gives you a seasoned executive who runs your security program, the other gives you a consultant who joins a monthly call and emails a template.

So here is what the role actually covers, where it stops, and how we staff it.

What a virtual CISO does

The work splits into five areas that recur across almost every engagement.

Owns the security program. Someone has to decide what your security program is trying to accomplish this year, write it down, and be accountable for it. That means a roadmap tied to business goals, policies that reflect how your company really operates, and a risk register that gets reviewed instead of filed.

Makes the risk calls. Most security decisions are tradeoffs with no clean answer. Do you spend on identity or on logging? Do you accept the risk on that legacy application for another two quarters? A vCISO makes those calls, documents the reasoning, and owns the outcome.

Handles compliance strategy. Not the evidence collection itself, but the decisions above it: which frameworks apply, how to scope the environment, what the gap assessment found, and what order to fix things in. Ongoing compliance guidance across HIPAA, PCI-DSS, SOC 2, and similar frameworks.

Translates for the board. Executives and directors need security explained in terms of business risk, spend, and trend. That is a specific skill, and it is usually the thing a technically strong IT lead is least practiced at.

Runs point during incidents. When something happens, a vCISO coordinates the response, manages the communication up to leadership, and handles the questions from customers, insurers, and regulators that arrive a week later.

What a virtual CISO doesn’t do

This half gets skipped in most vendor writeups, and it is where engagements go wrong.

It is not hands-on-keyboard work. A vCISO does not patch your servers, tune your EDR, or administer your identity provider. If what you need is someone to do the work rather than direct it, you need staff or a managed service, and paying executive rates for administration is a bad trade.

It is not 24/7 coverage. Fractional means fractional. We build surge capacity into engagements and we pick up the phone during incidents, but a part-time arrangement is not a SOC and should never be sold as one.

It is not instant compliance. A vCISO shortens the path to an audit and keeps you from wasting effort in the wrong places. The remediation still takes as long as it takes, and anyone promising a certification on a fixed date without seeing your environment is guessing.

It is not a substitute for testing your own defenses. Strategy and validation are different jobs. Your vCISO can tell you the controls are designed correctly; a penetration test tells you whether they hold. We keep those separate on purpose so the person grading the work is not the person who designed it.

How we staff it

Most vCISO arrangements assign you one consultant. That person is as good as their background, and their background has edges. We run it differently.

A team behind one point of contact

You get a dedicated primary contact, so you always know who to call and you are not re-explaining your environment every month. Behind that contact, the rest of the team works your account. Recommendations get reviewed internally before they reach you, which is how weak assumptions get caught. Coverage holds through vacations and personnel changes. When an engagement spans PKI, incident response, and regulatory work at the same time, we bring in whoever actually knows each area rather than stretching one generalist across all three.

Knowledge that moves between clients

Our team works across financial services, healthcare, education, local government, water utilities, and manufacturing. Patterns show up in one sector months before they show up in another. A control approach that worked for a credit union often transfers to a specialty clinic with small adjustments. We move those observations across the client base, minus anything client-specific.

Hours measured over the year, not the month

Engagements run from 10 to 60 hours monthly, and we track them on a long-term average. Front-load a heavy quarter for an audit push and pull back later without triggering an overage conversation. If an incident eats a week, we deal with the incident. Bean-counting a retainer to the hour makes clients hesitate to call, which defeats the point of having a security leader on retainer.

No product commissions

We do not resell security products and we take no vendor incentives, so when we recommend a tool the recommendation is only about whether it fits your environment. You can verify this the easy way: ask any provider what they earn if you buy what they suggest.

A partner network with a real structure behind it

When implementation work needs specialized hands or extra capacity, we bring in partners through our Partner Program, which we opened up in 2026. It runs three relationship types, referral, reseller, and strategic, with commissions and deal registration tracked in a portal rather than handled by handshake. Two things about that matter to you as a client. Partners come to us through a defined program with training and vetting, not an ad hoc contact list. And the commercial terms are visible, so nobody in the chain has a hidden reason to steer you toward a particular outcome.

Fixed annual terms

One-year contracts, a fixed monthly allocation, predictable pricing, no surprise invoices. We publish how vCISO pricing works so you can sanity-check any quote you get, including ours.

Who this fits

The team model earns its keep when your problems cross domains: an environment with PKI and OT and a SOC 2 deadline, a growing program that needs direction more than headcount, a regulated industry with continuous obligations, or a business whose security context is unusual enough that one person’s prior experience will not cover it.

A worked example. A Colorado financial services firm brought us in at 20 hours a month. Inside that allocation we handled PKI infrastructure guidance and rollout, wrote their data protection standards, made physical security recommendations, and built and tested incident response procedures. Four domains, one retainer. Finding a single practitioner deep in all four is possible, but you will wait a long time and pay for the search.

The flip side, so you can rule us out quickly: if you have one framework, a simple environment, and a strong IT lead who mostly needs a sounding board, a solo consultant at a lower rate may be the better buy. We would rather say that now than six months into a contract.

Ready to talk it through? Contact us and we will tell you what we would do in your first ninety days, and whether we are the right fit at all.

Frequently Asked Questions

How many hours a month does a virtual CISO need?

Most of our engagements land between 10 and 60 hours a month. Ten to fifteen hours covers a small organization with a stable environment and one framework to satisfy. Twenty to thirty is the common middle: policy work, risk reviews, vendor questionnaires, and a monthly leadership report. Forty and up usually means an active compliance push, a recent incident, or an acquisition. We size the first year on what you are actually trying to finish, then adjust once we have seen a few months of real work. See what a vCISO costs for how hours translate into price.

Does a virtual CISO replace my IT team?

No, and an honest provider will tell you that up front. A vCISO sets direction, makes risk calls, and owns the security program on paper. Your IT team or MSP still does the hands-on work: patching, configuration, identity administration, backups. The two roles need each other. Where a vCISO does help your IT team is by ending the argument about priorities, because someone accountable has now written down what gets fixed first and why.

Can a virtual CISO satisfy a regulatory requirement for a named security leader?

It depends on the framework, and the difference matters legally. GLBA (the Qualified Individual under 16 CFR 314.4) and NYDFS (the CISO role under 23 NYCRR 500.4) both explicitly permit an outsourced or third-party individual, so a vCISO can satisfy those. HIPAA's Security Official under 45 CFR 164.308(a)(2) is a role a vCISO can serve or support. Frameworks that only require you to assign responsibility, such as CMMC, NIST 800-171, and PCI-DSS Requirement 12.1, are ones a vCISO can provide and support rather than satisfy outright. Ask any provider to be precise about which of those three they mean.

What happens if my primary vCISO contact leaves?

Your program keeps running. Because the whole team works your account behind a single point of contact, the documentation, decision history, and context already live with more than one person. Handing off means introducing a new face, not rebuilding a year of institutional knowledge. This is the practical reason we staff the way we do, and it is the failure mode that hurts solo arrangements most.

Ready to Strengthen Your Defenses?

Schedule a free consultation with our security experts to discuss your organization's needs.

Or call us directly at (445) 273-2873