Career Engine

How To Choose Between A CISO, A vCISO And CISO-As-A-Service

A full-time CISO runs $250,000 to $400,000 or more a year. A vCISO runs $3,000 to $25,000 a month. CISO-as-a-Service adds overnight monitoring. Here is which one fits a growing company, and when to switch.

Choosing between a full-time CISO, a vCISO and CISO-as-a-Service

A full-time CISO makes sense once a company needs one person owning security full time and answering directly to the board. A vCISO delivers the same strategic ownership part time, for a fraction of the cost. CISO-as-a-Service adds round-the-clock monitoring on top of that. Pick based on stage and risk, not on which title sounds senior.

Takeaways

  • A full-time CISO costs $250,000 to $400,000 or more a year once salary, bonus, equity and benefits are counted, according to 2026 pricing data from BD Emerson.
  • A vCISO typically costs $3,000 to $25,000 a month depending on hours and scope, so a growing company can buy the oversight it needs without a full-time salary.
  • Under New York’s cybersecurity regulation, 23 NYCRR 500, a third party can carry the CISO title, but the company must still name a senior employee to oversee that work.
  • The SEC requires public companies to disclose a material cybersecurity incident within four business days of determining it is material, so whoever carries the CISO title needs to be reachable, not just qualified.
  • CISO-as-a-Service usually bundles a vCISO’s strategy with a managed security provider’s round-the-clock monitoring, so it fits companies that need both a plan and overnight coverage.
Full-time CISO $250,000-$400,000+ a year, fully loaded
vCISO $3,000-$25,000 a month by scope
CISO-as-a-Service ~$13,000 a month, vCISO plus MSSP bundled
SEC disclosure window 4 business days after materiality is determined

What’s the difference between them?

A CISO is a full-time employee whose only job is security, who sits in leadership meetings and answers to the board every quarter. A vCISO, short for virtual or fractional CISO, is an outside expert who does the same strategic work: setting policy, running the risk program, sitting in leadership meetings and reporting to the board, but for a fixed number of hours a month instead of forty. CISO-as-a-Service (CaaS) goes a step further and wraps that same fractional leadership inside a managed security provider’s contract, so one agreement gives you a security leader and the analysts watching for incidents overnight. The three are three altitudes of one job, not three competing products.

The stakes for choosing wrong are not small: IBM’s 2025 Cost of a Data Breach Report put the global average breach at $4.44 million, down from $4.88 million the year before, while the US average rose to $10.22 million. If you are unsure who inside the company should own that risk conversation before hiring any of the three, settle who owns cybersecurity across the CISO, CIO, CTO, CFO and CHRO first.

What does a full-time CISO cost?

A full-time CISO is the most expensive option and carries the most direct accountability. Fully loaded, including salary, bonus, equity and benefits, a full-time CISO runs $250,000 to $400,000 or more a year as of 2026, according to BD Emerson’s 2026 pricing breakdown. Compensation researchers IANS Research and Artico Search found that CISOs at small and midmarket companies earned roughly $415,000 in total compensation in their most recent benchmark, while CISOs who do not also own IT reported a median of $669,000 across the wider market. That gap between the small-and-midmarket figure and the broader median is the first sorting question: a company under roughly $100 million in revenue is usually paying for scope it does not need at the median rate.

Full-time hires also carry turnover risk. Cybersecurity Ventures found that 24% of Fortune 500 CISOs had been in the role a year or less, and a 2025 survey by Hitch Partners put average tenure in the current role at 39 months industry-wide. Measured differently, IANS and Artico’s 2026 benchmark report put average CISO tenure at nine years across employers, counting time spent across multiple companies rather than one.

What does a vCISO cost per month?

A vCISO costs $3,000 to $25,000 a month depending on how many hours you buy and how much of the program they run, according to 2026 market pricing compiled by SideChannel. At the low end, ten to twenty hours a month buys board reporting and program oversight. At the high end, an embedded arrangement approaching half time adds policy writing, vendor risk reviews, incident response leadership and tabletop exercises. That range exists because “vCISO” describes a level of seniority, not a fixed scope of work, so two companies paying $8,000 a month can be buying very different amounts of time. Demand has grown fast: research covered by SC Media found that virtual CISO offerings roughly tripled among managed security providers in a single year, with 96% of those providers reporting high or moderate customer interest.

What is CISO-as-a-Service?

CISO-as-a-Service bundles a vCISO’s strategic role with a managed security provider’s operational monitoring, so one contract covers both the plan and the people watching for it to fail. A vCISO alone tells you what to do and reports it upward. CISO-as-a-Service also runs the tooling that generates the alerts the vCISO is reporting on. Combined, a vCISO at $8,000 a month plus an MSSP at $5,000 a month runs close to $13,000 a month, per SideChannel’s 2026 estimate, still under half of a full-time CISO’s fully loaded cost. The model fits a company that has outgrown an informal check of the dashboard but has not outgrown fractional leadership. Run the math per hour of coverage, not per line item, before committing to either the bundle or the full-time hire.

The five triggers, ranked by urgency

Five events push a growing company to decide, ranked from the one that cannot wait to the one you can plan around months in advance.

  1. A confirmed incident at a public company, where the clock for a materiality decision and a possible SEC filing within four business days is already running.
  2. A customer, investor or acquirer contract that names a specific security leadership requirement as a closing condition.
  3. A cyber insurance renewal where the underwriter’s questionnaire asks for one named, accountable security executive rather than a checklist.
  4. Revenue crossing roughly $50 million to $100 million, where a founder or CTO handling security part time stops covering the company’s risk.
  5. A board member or new investor asking, for the first time, exactly who owns the security program by name.

Can a vCISO meet compliance rules?

Yes, in most cases, and the common claim that only a full-time employee can legally carry the CISO title is a myth. New York’s cybersecurity regulation, 23 NYCRR 500, explicitly allows the CISO function to sit with an affiliate or a third-party service provider. The catch is not the title, it is oversight: the covered entity must still designate a senior employee internally to direct and oversee that outside work, and examiners look closely at whether that internal oversight is documented or just a name on a form. NIST’s updated framework, CSF 2.0, makes a version of the same point. Its new Govern function, added in February 2024, expects cybersecurity risk decisions to trace back to accountable people inside the company, regardless of who carries the title outside it.

Which one should you pick?

Pick based on how many hours of security leadership the company needs this month, and whether a regulator or contract requires one specific accountable person, not on which title sounds senior. A pre-revenue or early-stage company almost always needs a vCISO rather than a CISO: the strategic work is the same, the cost is a fraction, and ISC2’s 2025 workforce study found that 95% of security teams already report at least one skills gap, which makes competing for full-time talent at that stage slow and expensive. A company handling regulated data around the clock, or one recovering from an incident, usually needs CISO-as-a-Service for the monitoring layer. A company past roughly $200 million to $300 million in revenue, with a board expecting a named executive in the room every quarter, usually needs the full-time hire. Whichever you choose, the board should judge the program by outcomes, not optics: a low phishing click rate on its own tells the board nothing useful about whether the security program is working.

Questions people actually ask

Can a vCISO legally hold the CISO title at my company?

Yes, in most cases. New York’s cybersecurity rule, 23 NYCRR 500, explicitly allows the CISO function to sit with an affiliate or third-party provider. The company still has to name an internal senior employee to oversee that work, so the compliance risk sits in weak oversight, not in the vCISO’s title.

Is a fractional CISO less accountable than a full-time one?

Not by design. A vCISO reports to the same board and carries the same liability exposure for the advice given; the difference is hours, not accountability. What varies is how closely the company documents and oversees that outside relationship, which mirrors the oversight a regulator expects for a full-time hire.

How many hours a month does a vCISO typically work?

Anywhere from ten hours a month for board reporting and program oversight up to close to half time for an embedded arrangement that includes policy writing and incident response leadership, according to 2026 vCISO pricing data. The hours you buy should match a specific list of deliverables, not a vague retainer.

Do early-stage startups need a CISO at all?

Most do not need a full-time CISO, but nearly all handling customer data need someone accountable for security decisions. A vCISO covering ten to twenty hours a month usually covers that need at a fraction of a full-time salary, and it scales up as the company, and its risk, grows.

What’s the difference between a vCISO and CISO-as-a-Service?

A vCISO provides strategic leadership: policy, risk decisions, board reporting. CISO-as-a-Service bundles that same leadership with a managed security provider’s round-the-clock monitoring, so one contract covers both the plan and the people watching the alerts it generates.

Sources

  1. 2025 Cost of a Data Breach Reportibm.com
  2. BD Emerson’s 2026 pricing breakdownbdemerson.com
  3. CISOs who do not also own IT reported a median of $669,000iansresearch.com
  4. Cybersecurity Ventures found that 24% of Fortune 500 CISOs had been in the role a year or lesscybersecurityventures.com
  5. Hitch Partners put average tenure in the current role at 39 monthshitchpartners.com
  6. IANS and Artico’s 2026 benchmark report put average CISO tenure at nine years across employersiansresearch.com
  7. SideChannelsidechannel.com
  8. SC Media found that virtual CISO offerings roughly tripled among managed security providers in a single yearscworld.com
  9. SEC filing within four business dayssec.gov
  10. 23 NYCRR 500dfs.ny.gov
  11. CSF 2.0nist.gov
  12. ISC2’s 2025 workforce study found that 95% of security teams already report at least one skills gapisc2.org

What happens next

Expect more state regulators to follow New York’s lead and explicitly permit third-party CISOs, since the model is already mainstream among managed security providers. Watch whether the SEC’s four-day disclosure clock pushes more companies toward CISO-as-a-Service, since a bundled monitoring contract is often the fastest way to know an incident happened at all. The harder question over the next few years is whether full-time CISO compensation keeps rising fast enough to price smaller companies out of that option entirely.

Take this further

Full resume rewrite, section by sectionBest on Claude
Act as a blunt hiring manager who has read ten thousand resumes, not a career coach. I will paste my full resume and the job description I want. Rewrite the whole resume for that role, section by section, in this order: summary, experience, skills, education. Rules: every experience line leads with impact, not duty. Use bracketed placeholders like [8 percent] for any number I did not give you, and list at the end every placeholder I need to replace with a real figure. Keep it to one page of text. Plain formatting only, no tables or columns, so screening software can parse it. After the rewrite, tell me the three weakest claims that need evidence before I send this anywhere. My resume: [paste resume]. The role: [paste job description].
Share this
About the author
Vinayak Kapoor
Vinayak Kapoor

Vinayak started at seventeen on a call centre floor and climbed every rung himself over fifteen years: millions of customer conversations for some of the world's largest brands, self-taught design, video and web work, a profitable e-commerce brand of his own, and now human cyber risk, where he has built customer success journeys for national critical infrastructure and leads business growth at HumanFirewall. Nobody groomed him. He learned every skill alone, including the AI he now builds with daily as founder of Quarry, MaaSify and HuMatrix. He writes here so your career gets the guide his never had.

Read next
Come find me

The daily thinking
lives on the feeds.

Long form here. The working notes, the arguments and the things that did not fit go out most days.

← All writing