The job title CISO conjures a war room, but the substance of the role at most organisations is judgement: deciding which risks matter, what to spend against them, and how to answer the people entitled to ask, boards, insurers, auditors, customers. Organisations under about a thousand people generate a real but part-time volume of that judgement, which is the entire case for the virtual CISO model. You need the seniority; you do not yet need the headcount.
What follows is what the days actually contain, because "security leadership as a service" describes a price, not a job.
The standing decisions
A few days a month, spent honestly, covers a recognisable rhythm. The risk register gets maintained as a living document rather than an annual artefact: what changed, what got worse, what the business is about to do that security should hear about before contracts are signed. The security roadmap gets sequenced against budget, with the vCISO as the person who says which of the twelve worthy projects come first and takes responsibility for the ordering.
Vendor and architecture decisions get an experienced eye at the moment they are cheap to influence. A new SaaS platform, a data-sharing agreement, an integration with a partner: each is an hour of scrutiny early or a remediation project later. And the board gets reporting written in risk and dollars, by someone who can stand behind it in the meeting, because security that cannot explain itself upward eventually loses its budget.
The events
Between the routines sit the spikes. A customer security questionnaire lands and the answers shape whether the deal closes; a vCISO who knows the environment answers in days, accurately, rather than letting sales improvise. The insurer's renewal arrives with new control requirements. An incident happens, and the difference between a practised escalation and an improvised one is the difference we have written about before. The vCISO is the standing point of accountability through each: one person who holds the thread.
What the model deliberately is not
A vCISO is not a security team. Patching, monitoring, administration and engineering still have to live somewhere, internal IT, a managed provider, or engineering practices that build the controls. The vCISO directs that work and verifies it happened; renting judgement does not remove the need for hands.
It is also not a certificate of outsourced accountability. The organisation still owns its risk. What the model provides is someone qualified to put that risk in front of the owners in a form they can act on, which is precisely what auditors and boards increasingly ask to see.
The graduation signal
The model has a natural end, and it is worth naming in advance: when security decisions queue daily rather than weekly, when the questionnaire volume becomes a workload, when the organisation's size or regulatory position warrants a permanent seat at the executive table, it is time to hire. A good vCISO arrangement treats that as success, helps write the job description, and hands over a documented, operating function rather than a dependency.
Our cyber security practice runs vCISO arrangements on a retained basis, usually beginning with an assessment that establishes the honest baseline.
Ben Jones leads penetration testing, red team and incident response at Coder Trove.