Live webinar The Wrong Security Hire Burns Your B2B GTM Pipeline. A fireside chat for founders · Oct 6, 9:30am PTThe wrong security hire · Oct 6 Save your seat

Blog

By Jon McLachlan 33 min read

What Is a vCISO? What They Cost, What They Do, and When a Startup Needs One

Sooner or later an enterprise buyer asks to talk to your security leader, and you don't have one. Here's the plain-English version: what a vCISO is, what one really costs, what they do and don't do, who carries the risk, and how to tell when your startup needs one.

It usually comes right after the security questionnaire. You answered every row, the buyer’s security team read your answers, and now they want a meeting: “Can we get a call with your security leader?” At a thirty-person startup, the honest answer is that the security leader is the CTO on a good week and nobody on a bad one.

That request shows up earlier than most founders expect. When I asked a16z CISO Yash Kosaraju about it on episode 104 of the podcast, he described the sales signal exactly: some of the bigger clients will ask for “either a call with your security leader or a dedicated point of contact.” Then he added the part founders need to hear: “That’s probably not when you’re hiring for your head of security.”

That gap, between needing a security leader in the room and needing one on payroll, is where a vCISO lives. This post covers what one is, why so many people suddenly sell the service, what one really costs, what they should and shouldn’t do for you, who carries the risk when something goes wrong, and the triggers that tell you it’s time. Along the way we’ll pull in what practitioners actually say about this on Hacker News, in talks and in the essays security people pass around, including the skeptical takes.

"You could get either an advisor that you trust or a fractional CISO who can come in and jumpstart your program as well."

Yash Kosaraju, CISO at a16z, on episode 104

The player opens at 3:57, where I ask Yash when a startup should make its first security hire, and who that hire should be. The fractional CISO answer comes about three minutes later. Watch on YouTube.

What is a vCISO? The two-sentence version

A vCISO, short for virtual chief information security officer, is an experienced security leader you bring in part-time or on demand to do the job a full-time CISO would do: own your security strategy, your compliance program and your answers to customers. You get executive-level security judgment without an executive-level salary, and you use it when the work shows up.

TechTarget defines the model as “the outsourcing of CISO (chief information security officer) and information security leadership responsibilities to a third-party provider” (TechTarget, CISO as a service). A Hacker News commenter put the economics more plainly years ago: “one senior level person serves several companies none of which could afford their services full time” (rietta on Hacker News, 2020).

The important word in the TechTarget definition is leadership. A good vCISO isn’t a scanner, a policy template or a quarterly slide deck. It’s a person who decides what matters, makes the risk calls, and can sit across the table from your customer’s security team and hold the conversation.

vCISO vs. fractional CISO vs. CISO-as-a-service: is there a difference?

Mostly, no. The three names get used interchangeably, including by the firms that sell them. FRSecure describes “a virtual CISO, otherwise known as CISO as a service or a fractional CISO” in a single breath (FRSecure).

Where vendors do draw a line, it’s convention rather than a standard. Cynomi, for example, describes a fractional CISO as “part-time, often on-site” and “deeply embedded,” and a vCISO as “primarily remote, on-demand” (Cynomi). No standards body defines either term, so the label on the proposal tells you very little.

What tells you a lot is the answer to three questions:

  • Who is the person? A named security leader, or a rotating bench.
  • How much of them do you get? Hours, days, or “as needed,” and what happens when a deadline doubles the need for a month.
  • Do they do the work, or advise on it? This is where the category splits, and we’ll come back to it below.

Why is everyone suddenly selling vCISO services?

If it feels like every security firm, managed service provider and LinkedIn profile added “vCISO” in the last two years, that’s because a lot of them did. Cynomi’s 2025 State of the Virtual CISO report found 67 percent of managed service providers now offer vCISO services, up from 21 percent a year earlier (Help Net Security). Cynomi sells a platform for those providers, so take the exact number with salt, but the direction matches what founders see in their inbox. Three forces are pushing supply up at the same time, and it’s worth understanding them, because they explain both why the good vCISOs exist and why the bad ones do.

The full-time job is grinding people down. In Proofpoint’s 2026 Voice of the CISO report, 77 percent of CISOs said they face excessive expectations, and 79 percent said they’re expected to manage AI risk “without proportional resources” (Proofpoint, September 2026). Splunk’s 2025 State of Security survey found 52 percent of security leaders had considered leaving the field because of job stress (Cisco newsroom, May 2025). Some of those people leave security. Plenty of them go fractional instead, and the best of them are exactly the leaders a startup couldn’t otherwise afford.

The personal risk of the title went up. We’ll get to the SolarWinds and Uber cases below, but the short version is that for a few years the CISO title looked like it came with a subpoena attached. Going fractional, with a clear contract and a narrower remit, is one way senior people keep doing the work while managing that exposure.

Independent senior work is growing everywhere. Upwork’s 2026 Future Workforce Index found skilled freelancers make up 38 percent of US knowledge workers, up from 28 percent a year earlier (Upwork via GlobeNewswire, July 2026), and MBO Partners counts 5.6 million US independents earning more than $100,000 a year, up 19 percent on 2024 (MBO Partners, September 2025). Fractional security leadership is one slice of a much bigger shift in how senior people sell their time.

Meanwhile the demand side has its own problem: there aren’t enough experienced security people to hire. In ISC2’s 2025 Cybersecurity Workforce Study of more than 16,000 professionals, 88 percent said their organization had suffered at least one significant consequence from a shortage of security skills (ISC2 via PR Newswire, December 2025).

Put a fast-growing supply of sellers next to buyers who can’t evaluate them, and you get a quality problem. James Rees of Razorwire Cybersecurity made that exact point this summer, noting that some organizations post fractional CISO roles at £20 to £26 an hour “and wondering why they are not getting experienced security professionals.”

James Rees on why fractional CISOs can work, what makes a good one, and why "Getting the wrong fractional CISO will cost you far more than paying for a good one." Razorwire Cybersecurity, August 2026. Watch on YouTube.

That’s the backdrop for everything that follows. The model is sound. The market is noisy. Most of this post is about telling the difference.

What does a vCISO actually do?

The job description is the same as a full-time CISO’s, scaled to the size of your company and the deals in front of you. In practice, for a startup selling to enterprises, it breaks into six parts.

  1. Strategy and a roadmap. A baseline risk assessment, then a short, ranked plan tied to the revenue it unblocks. The first question a good vCISO asks is which deals are waiting on security, not which framework you like.
  2. Compliance ownership. Scoping, policies, controls, evidence and the auditor relationship for SOC 2, ISO 27001, ISO 42001, HIPAA, HITRUST, or, if you sell to government and defense, CMMC Level 2, FedRAMP and ITAR. Someone has to own the observation window from start to finish. (New to SOC 2? Start with What Even Is a SOC 2?)
  3. Customer-facing security. Security questionnaires, due diligence questionnaires (DDQs), trust documentation, and showing up on the call when your buyer’s security team wants to talk to a security person. This is the part of the job that closes deals, and it’s why we built Sales Support as its own service.
  4. Incident readiness. An incident response plan people have actually read, a tabletop exercise before you need it, backups that survive ransomware (we wrote about why 3-2-1 isn’t enough anymore), and a decision about who watches your systems at 3 a.m., whether that’s your team or a 24/7 monitoring and response service.
  5. Vendor and AI risk. Deciding which tools touch customer data, finding the ones nobody approved (shadow AI detection is often the first surprise), writing an AI acceptable-use policy, and checking what your AI agents can actually reach through an AI access control audit.
  6. Board and investor reporting. A one-page security story for the board, and clean answers when diligence arrives.

If you want a neutral yardstick for that list, NIST’s Cybersecurity Framework 2.0 added a sixth core function, Govern, in 2024, and defined it as making sure “The organization’s cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored” (NIST CSWP 29). NIST’s announcement framed the reason bluntly: “cybersecurity is a major source of enterprise risk that senior leaders should consider alongside others such as finance and reputation” (NIST, February 2024). Govern is close to a job description for a vCISO. The other five functions (Identify, Protect, Detect, Respond, Recover) are the work the vCISO makes sure gets done.

Diagram of what a vCISO owns and what they don't: a vCISO owns strategy, compliance, customer security reviews, incident readiness, vendor and AI risk, and board reporting; a vCISO does not issue the SOC 2 report, provide 24/7 monitoring, practice law, or replace your whole security team
Solid is the job. Dashed is work a vCISO coordinates but someone else is on the hook for.

What a vCISO doesn’t do

Here’s the clearest way to draw the line. A vCISO doesn’t automatically run every security tool, fix every finding, watch your systems around the clock, give legal advice, or perform your SOC 2 audit. That’s why your contract should separate four things: leadership, implementation, operations and attestation.

That separation matters most on the word “implementation.” A lot of vCISO offerings stop at leadership: a policy pack, a roadmap, a monthly call, and a list of findings for your engineers to fix. That’s fine if you have engineers to spare. Most startups don’t, which is why the most useful question on any proposal is who actually closes the gaps. Our operators do the implementation as well (in your cloud, your codebase and your Slack), because a roadmap nobody has time to execute is just a nicer-looking to-do list.

Advisor or operator: why do so many vCISO engagements disappoint?

This is the underlying issue with the whole category, and practitioners are candid about it. One Hacker News commenter who spent three years as a virtual CISO for a friend’s company described “giving up in frustration,” and put the failure precisely:

"Automated report generators made for very pretty graphics for the C level executives but failed us on actionable items for the managers and staff who had to actually fix exposures."

A former virtual CISO, in a Hacker News thread on compliance reporting tools, May 2025

The failure mode is structural, not personal. The security writer Michal Zalewski (lcamtuf), who ran security at Google and Snap, described it in a piece on how security teams fail: “None of these groups owns any clear business outcome per se. They run projects” (lcamtuf, February 2025). An advisory-only vCISO is that problem in its purest form. They can recommend. They can’t ship.

Working vCISOs describe the other half of the trap from their side. Ayman Elsawah, who writes a newsletter about the job, notes that clients “may have reluctantly made the budget to bring you on for SOC 2 or sales enablement,” and then the vCISO starts recommending work the client sees as a slowdown (Last Week As A vCISO, July 2025). He’s also frank that the model is hard on the people doing it: “Most fractional executives burn out actually, and go back to FTE life.” For a buyer, that’s a real risk: the person who knows your program may not be around in a year.

And sometimes the problem is the buyer’s expectations. In a long Hacker News thread about startups hiring security leaders, one commenter described a company where “the company sincerely believed that hiring the security person is all the resources required” (Kalium on Hacker News, 2022). A vCISO without engineering time, budget or executive backing is a title, not a program.

The fix isn’t to avoid vCISOs. It’s to buy the version that does the work: someone who opens pull requests, changes cloud configurations, fills in the questionnaire and joins the call, and whose success is measured in deals closed and audits passed rather than documents delivered. That’s the whole reason we run YSecurity as an on-demand security team rather than an advisory shop. If your gaps are in the product itself, that’s product security and secure AI SDLC work, and a vCISO who can’t do it will hand it back to your engineers.

Is a vCISO just compliance theater?

It can be, and 2026 gave the skeptics fresh ammunition. In March, TechCrunch reported whistleblower allegations that Delve, a Y Combinator-backed compliance startup, had “falsely” convinced “hundreds of customers they were compliant”; Delve responded that “Final reports and opinions are issued solely by independent, licensed auditors, not Delve” (TechCrunch, March 2026). A later analysis reported that 493 of 494 reports examined were nearly identical, and concluded that “The question ‘Does this vendor have a SOC 2?’ was always the wrong question” (Corporate Compliance Insights, May 2026).

The Hacker News thread on the story is worth reading in full. Two comments stand out for anyone buying security leadership:

"If the SOC2 report is just a pre-populated template, it is meaningless."

emilycg, in the Hacker News thread on the Delve allegations, March 2026

"None of their ISO 27001 certificates, aside from the premium one-offs with the vCISO, are accredited by any reputable ISO accreditation body."

Qasaur, in the same Hacker News thread, March 2026

That second comment is the interesting one. In the commenter’s telling, the only version that held up was the one with a real human security leader involved. Automation can collect evidence. It can’t supply the judgment that makes the evidence mean something.

The deeper critique is older and comes from people who build real programs. Latacora’s widely shared essay on SOC 2 draws the line that every founder should internalize: “Compliance is a byproduct of security engineering. Good security engineering has little to do with compliance.” It also names where the pressure comes from: “Eventually you’ll run into big-company clients demanding a SOC2 report to close a sale” (Latacora, The SOC2 Starting Seven). Thomas Ptacek, one of Latacora’s founders, went further this year in an Ask HN thread about getting SOC 2 as a solo founder:

"Do not ever do a SOC2 speculatively, in the hopes that it will improve your sales prospects."

tptacek, in an Ask HN thread on SOC 2 Type 2 for solo founders, May 2026

A working vCISO replied in the same thread with the nuance we’d add ourselves:

"chasing SOC 2 without a deal on the table is expensive theater. That said, there's a real inflection point where it flips."

al3d1n, replying in the same Hacker News thread, May 2026

We agree with both of them. A SOC 2 bought as a marketing badge, from a template, with nobody accountable for the controls, is theater. A SOC 2 you pursue because a named buyer needs it, with controls that actually run, is a sales asset and a real security improvement at the same time. The difference is almost entirely who’s running it. When we took Robust Intelligence through SOC 2 Type 2, the report came back with zero deviations, and when Augment Code went from zero to SOC 2 in five months, enterprise lead growth followed. Neither outcome came from a template. We made the same argument about AI-assisted engineering in Agentic Code Review and Your SOC 2 Type 2 Audit: the controls have to be real, whoever writes the code.

A practical test falls out of this: if a provider offers ISO 27001 or ISO 42001 certification, ask which accreditation body stands behind the certification body (in the US, look for ANAB; in the UK, UKAS). If they can’t answer, you’ve learned something.

Who carries the risk when something goes wrong?

This is the question founders rarely ask and security leaders always do. It’s also where the fractional model gets misunderstood in both directions.

The fear is real. On a Hacker News thread about fractional jobs, one commenter summed up the case against the model from the security leader’s side:

"CISO is famously a "sacrificial lamb" sort of job, and it's certainly never one I would take on on a fractional basis (all of the risk but a lot less of the reward)."

hn_throwaway_99, in the Hacker News "Show HN: Fractional jobs" thread, August 2025

Another commenter pushed back in the same thread, saying they know someone who enjoyed the fractional CISO role and see it “as less of the risk and more of the reward” (jcims on Hacker News, August 2025). Both can be true. It depends on how the engagement is set up.

Two cases shaped how every security leader thinks about this:

  • SolarWinds. In October 2023 the SEC charged SolarWinds and its CISO, Timothy Brown, with fraud and internal control failures tied to security disclosures made from the company’s 2018 IPO onward (SEC, October 2023). A federal court threw out most of the claims in July 2024, and in November 2025 the SEC dismissed the rest of the case, while noting the dismissal “does not necessarily reflect the Commission’s position on any other case” (SEC Litigation Release LR-26423).
  • Uber. Joe Sullivan, Uber’s former chief security officer, was convicted in 2022 of obstructing an FTC investigation and concealing a breach, and sentenced in 2023 to three years of probation and a $50,000 fine (US Department of Justice, May 2023). The Ninth Circuit affirmed the conviction in 2025 (United States v. Sullivan, No. 23-927).

Brown’s own takeaway, after the case ended, is the one we’d underline for startups: “Normal operating procedures became proof, from [the SEC’s] perspective, of negligence” (TechTarget, March 2026). Internal risk memos, board decks and the security page on your website are all evidence. So are the answers in your security questionnaires.

SolarWinds CISO Tim Brown with G Mark Hardy at Black Hat, on the breach, the response, and the evolving regulatory landscape for CISOs. Watch on YouTube.

The underlying issue, in the words of Knostic CEO Gadi Evron after the SolarWinds dismissal: “We have a lot of the responsibility and very little of the authority.” Joe Sullivan, in the same piece, drew the conclusion: “It’s really important that we not sit in the corner and just let all the risks sit on our shoulders” (CSO Online, December 2025). A Hacker News commenter on the Verizon breach report asked the same question more sharply: does the CISO have the authority to change the risk they’re blamed for? “If not, then the CISO is merely compensated to play the scapegoat when luck is down” (dantillberg on Hacker News, May 2024).

Protection for security leaders is also uneven. IANS and Artico Search found directors and officers (D&O) insurance coverage for CISOs rose to over 50 percent in 2025, from 40 percent (IANS, November 2025), and a CSO Online report on an RSAC survey found 88 percent of Fortune 1000 CISOs are indemnified by their employer, against 53 percent at companies with more than 500 employees (CSO Online). In plain English: the further you are from the Fortune 1000, the less protection your security leader probably has.

What this means for a startup, in practice (and we’re not lawyers, so talk to yours):

  • Risk is owned by the business. A good vCISO recommends, documents and escalates. The CEO or the executive who owns the product accepts the risk, in writing, in a risk register. That’s not passing the buck. It’s how governance is supposed to work, and it’s what NIST’s Govern function asks for.
  • Say only what’s true. Questionnaire answers, trust pages and investor decks should match what your controls actually do. This is where a vCISO who does the work earns their keep, because they know.
  • Plan for the SEC even if you’re private. The SEC’s 2023 rules require public companies to disclose material cybersecurity incidents on Form 8-K, “generally due four business days after a registrant determines that a cybersecurity incident is material,” and to describe board oversight and management’s cybersecurity expertise in annual reports (SEC, July 2023). Your public-company customers live under those rules, which is part of why their questionnaires got longer, and you will too if you IPO. Kayne McGladrey unpacked the 10-K side of this on episode 56 of the podcast.
  • Read the contract. Check who the vCISO works for (you, or a firm), what indemnification and insurance cover, and which decisions are theirs versus yours.

The honest answer to “who carries the risk” is: the company does, and a good security leader, fractional or full-time, makes sure the right executive knows exactly what risk they’re carrying. Andrew Gontarczyk’s conversation about building a security team at Pure Storage and our more recent episode, CISO does not spell CEO, both get at the same idea from different sides: the security leader’s job is to inform the business’s risk decisions, not to make them alone.

How much does a vCISO cost?

Published vCISO pricing clusters in a fairly tight band, with one caveat before the numbers: every figure below comes from providers’ own pricing pages, not an independent survey, so read it as directional.

  • Startup tier. SideChannel lists $1,500 to $4,000 a month for companies with 1 to 50 employees, or $18,000 to $48,000 a year, with hourly work at $200 to $400 (SideChannel, April 2026).
  • By the hour block. Breach Craft prices light advisory, 10 to 20 hours a month, at $3,500 to $7,500, and heavier engagements of 30 to 45 hours at $10,500 to $15,000 (Breach Craft, April 2026).
  • By the day. BD Emerson puts retainers at $3,000 to $25,000 a month “depending on how many days of leadership you are buying,” with blended day rates “between $1,200 and $2,500” (BD Emerson, July 2026).

That lines up with what we wrote after Twin Cities Startup Week: roughly $3,000 to $6,000 a month at the startup stage and $6,000 to $12,000 at growth stage.

What a full-time CISO costs instead

The comparison founders usually make is against a hire, so here’s that side with better data. IANS Research and Artico Search surveyed 363 CISOs at companies under $1 billion in revenue: average total compensation was $415,000, with $330,000 in cash. At companies under $50 million in revenue, cash compensation was about $260,000, against an average security budget of $600,000 (IANS, June 2025). Add a recruiter, typically “25 to 30 percent of first year compensation” (BD Emerson, above), and the months it takes to find one: in ISACA’s 2025 State of Cybersecurity survey, 39 percent of organizations said a non-entry-level security role takes three to six months to fill (ISACA).

The role has also moved up the org chart, which pushes the price up. Heidrick & Struggles’ 2025 global CISO survey found that 42 percent of CISOs now report directly to the CEO, three times the share in the previous year’s survey (Heidrick & Struggles, February 2026). That’s an executive hire, with an executive’s search, equity and expectations.

OptionWhat it typically costsHow fast it startsBest fit
Nobody owns security$0, until a deal stalls on a questionnaireAlready herePre-revenue, no sensitive data
vCISO on a monthly retainerAbout $1,500 to $15,000 a month in published pricingWeeksSteady, predictable security work
On-demand team billed on usageOnly the time you use, under a cap you setDaysBursty work: questionnaires, audits, diligence
Full-time CISOAbout $260,000 cash under $50M revenue; $415,000 average total at companies under $1BThree to six months or more to hireA security program big enough to need a team
Bar chart comparing annual cost: a vCISO retainer at about $18,000 to $180,000 a year in published pricing, versus a full-time CISO at about $260,000 in cash at companies under $50 million in revenue and $415,000 average total compensation at companies under $1 billion
Annual cost, published ranges. The dashed line is where BD Emerson says fractional spend starts buying full-time money for part-time presence.

The retainer problem

Most vCISO pricing is a monthly retainer: a block of hours or days, billed whether you use them or not, with overage on top. Minimum terms range from 90 days to 12- and 24-month commitments, depending on the provider.

Startup security work doesn’t arrive in monthly blocks. A long security questionnaire lands the same week as audit fieldwork, then nothing much happens for three weeks, then an investor sends a diligence list. A retainer sized for the busy month wastes money in the quiet ones, and a retainer sized for the quiet month leaves you short when the deal is on the line. Working vCISOs feel the same swing from their side of the table; Ayman Elsawah calls the business “very feast or famine” (Last Week As A vCISO, above).

That’s why we bill in 15-minute increments with a clear description of every task, with no long-term contracts or minimums. You can set a monthly cap so the bill stays predictable.

When your security work does become steady, at 30 or more hours a week, that’s the signal to start planning a full-time hire. BD Emerson puts the tipping point at around “$180,000 to $220,000 a year, at which point you are paying full time money for part time presence.” We’ll help you write that job description and hand the program over, so the person you hire inherits a working program instead of a blank page.

When does a startup need a vCISO? Seven triggers

On day zero, you don’t. A five-person team with no customers and no sensitive data should be building the product, and we made the case for that in In-House, On-Demand, or YOLO?. Venture in Security’s field guide for security people who join startups puts the founder’s view well: “Security is important, but it’s not urgent until there’s something worth protecting” (Venture in Security). The trouble is that the moment you need a security leader rarely announces itself. It shows up as one of these.

  1. The first serious security questionnaire. It’s not a one-off. In Vanta’s State of Trust 2025 survey of 3,500 IT and business leaders, organizations said they spend 9 working weeks a year on vendor security reviews and risk assessments, up from 7 the year before (Vanta via Business Wire). That’s a vendor survey, so read it as directional, but the reason buyers keep asking is not: Verizon’s 2026 Data Breach Investigations Report found a third party was involved in 48 percent of breaches (Verizon, 2026). You are the third party. Sales Support exists for exactly this moment.
  2. A buyer asks for your SOC 2. Now there’s an audit, an observation window and a deadline on someone else’s schedule. Here’s what that request actually means, and here’s how we run SOC 2 Type 2. Healthcare buyers ask for HIPAA or HITRUST instead; defense buyers ask for CMMC.
  3. The buyer’s security team wants a call. This is the moment from the top of this post. A questionnaire can be answered by a diligent engineer. A live conversation with a CISO needs someone who can speak as one.
  4. Investor diligence. When a lead investor sends a diligence list, security is on it, and “we’re working on it” is a harder answer to give an investor than a customer. A recent penetration test and a one-page security story go a long way. (We looked at whether AI pentesting can replace human testers if you’re weighing the options.)
  5. Cyber insurance renewal. Carriers ask for controls like multi-factor authentication, backups and identity and access management before they’ll write or renew a policy (Coalition), and someone has to attest that they’re real.
  6. Your first incident, or near miss. A phished account, a leaked key, an exposed bucket. IBM’s 2026 Cost of a Data Breach study put the global average breach at $4.99 million (IBM, July 2026), and small companies are hit differently: in Verizon’s 2025 report, ransomware showed up in 88 percent of breaches at small and midsize businesses, against 39 percent at large organizations (Verizon 2025 DBIR SMB snapshot). Nobody should find out who owns incident response during the incident. If you don’t have someone watching, that’s what 24/7 Monitoring & Response and AI-accelerated cloud detection and response are for.
  7. AI goes into the product. Enterprise AI committees now ask how you govern models, data and agents. The auditor A-LIGN reports that “4 out of 5 organizations face customer inquiries about their AI risk management” (A-LIGN 2026 Compliance Benchmark), and some buyers want ISO 42001 before they sign. If you sell into Europe, the EU AI Act’s high-risk obligations now land on December 2, 2027 for stand-alone systems and August 2, 2028 for AI built into products (Council of the EU, June 2026), which is what our AI EU Compliance Program prepares for. That’s a new framework, a new set of questions and a new owner, and often new testing too: AI red teaming, a secure MCP review for agent tools, and the governance work we covered in AI Agent Governance Starts at Onboarding.
Timeline of when startups typically need security leadership: at seed, nobody owns security; the first enterprise questionnaire and SOC 2 request bring in a vCISO or on-demand team; Series A and B diligence, insurance renewals and AI governance keep it busy; a full-time head of security comes much later, as the team grows
The triggers stack up long before a full-time head of security makes sense. That stretch is what a vCISO is for.

What do practitioners say about the first security hire?

The fractional question is really a sequencing question: what do you need now, and what do you hire later? The people who have built startup security programs agree on more than you’d expect.

The first hire is hands-on, and usually not a CISO. Thomas Ptacek’s rule of thumb is the one most often quoted:

"the startup industry norm is to make a first security hire somewhere between engineer #20 and #40. That hire is usually not a CISO: your first security hire needs to be a hands-on-keyboard person, and CISOs are not that."

tptacek, in the Hacker News thread on an IT security checklist for startups, August 2022

That matches what Yash told us on episode 104, and it matches First Round Review’s benchmark: “Onboard your first, full-time security hire between 30-100 employees,” with a warning that “Wait six months too long to make your first security hire and the person will start with 1-2 years of security debt” (First Round Review).

Timing is about distraction, not headcount. Rami McCarthy’s compilation of practitioner rules of thumb lands on the cleanest version: “You should hire your first security person when security is an unavoidable distraction from scaling your business.” Until then, he notes, “You can defray hiring by using contract security expertise” (Rami McCarthy, November 2024).

Get an adviser first. Ryan McGeehan, who led security at Facebook and Coinbase, gave founders the same advice nearly a decade ago: “Your startup should find a local security firm, or bring an expert into an adviser role.” He was equally clear about the endpoint: “You will need to hire a CSO at some point” (Ryan McGeehan, You don’t need a Chief Security Officer).

Pick the hire that matches the work. Frank Wang splits first security hires into three types: a compliance operator, a cloud security engineer, and a security-minded software engineer, and warns that “The first security hire will shape how security works at your company for the next few years” (Frankly Speaking, September 2025). Evan Johnson, then a senior security engineer at Cloudflare, put the engineering version bluntly in a talk on starting a security program at a startup: “If you want to make a difference at a startup with the way people are building software, you need to build software” (tl;dr sec write-up of his talk). That’s also why we think shift-left security keeps failing when it’s run as a policy rather than as engineering.

Evan Johnson at AppSec California on what it's like to be the first security person at a startup, and how to integrate security with the rest of the company. OWASP Foundation. Watch on YouTube.

In the meantime, name an owner. The most practical advice for the stretch before anyone is hired is also the simplest: “Name an Acting Security Owner for the next two quarters” (Northwoods Security Notes, October 2025). Usually that’s the infrastructure or DevOps lead, who is already doing the job without the title. A vCISO works best alongside that person, not instead of them. We’ve heard versions of this from security leaders on the podcast for years, from Colin Bitterfield on serving as an acting CISO to our episode on the critical security stage every startup skips.

Put those together and the shape is clear. Early on, you need judgment more than headcount, so you borrow it. As the work becomes steady and technical, you hire a hands-on engineer. The executive comes last, when there’s a team to lead. A vCISO or on-demand team is the bridge across the first two stages, and a good one is building toward the handoff from day one.

vCISO vs. full-time CISO vs. MSSP vs. Vanta and Drata: who does what?

Founders often compare a vCISO to things that do a different job. Here’s how the pieces fit.

OptionWhat it’s forWhat it won’t do
vCISO or on-demand security teamLeadership: strategy, compliance ownership, customer security reviews, risk decisionsIssue your SOC 2 report or watch your systems 24/7
Full-time CISOThe same leadership, full-time, plus building and managing a security teamStart next week, or cost less than $260,000 a year
MSSP or managed detection and responseRound-the-clock monitoring and responseSet your security strategy or answer your buyer’s questionnaire
Compliance automation (Vanta, Drata)Continuous config checks, evidence collection, policy templatesMake judgment calls: data classification, vendor approvals, what an auditor will accept
Auditor (a CPA firm)Issuing the SOC 2 reportAdvise you on how to pass (independence rules keep them out of it)

The compliance tools deserve a special note, because “we bought Vanta” is the most common reason founders think they don’t need anyone. The tools are excellent at what they do. They don’t make decisions, and they don’t sit in the audit. As one comparison put it, “the dashboard score and the audit outcome are not the same metric” (Atlant Security). Hacker News commenters make the same point from the engineering side: one described the platforms as “somewhere in-between checkbox compliance and real security,” and another replied that “you can be fully compliant despite having made stupid decisions” (Hacker News, June 2024). Plenty of startups use one of the platforms and have a security leader run it, which is the combination auditors like best. A recent commenter described the future of the category the same way: “a smart Fractional (CISO, in the compliance case) paired with good AI. The purchaser gets proper human judgement” (te_chris on Hacker News, July 2026).

How to choose a vCISO: six questions to ask

Given how crowded the market is, these questions separate the operators from the template shops.

  1. Who does the work, and how many other clients do they carry? Purple Shield Security puts it well: ask for “the client load of the specific person assigned to you, because that number governs whether you get judgment or output” (Purple Shield Security, July 2026).
  2. Do they go into the cloud and the codebase, or only the documents? If the answer is documents, budget engineering time for everything they find.
  3. Will they fill in the questionnaire and join the security call? Or hand the spreadsheet back with comments.
  4. Who else pays them? A vCISO who resells security tools has a reason to recommend them.
  5. What do we keep when we stop? Policies, risk register, incident response plan and audit evidence, in editable formats, owned by you, with admin access to every account in your name rather than theirs.
  6. What’s the minimum term, and what happens to unused hours? Also ask for proof of errors and omissions insurance. “A firm advising on risk while carrying no coverage for its own advice has told you something” (Purple Shield, above).

And a few red flags, drawn from everything above:

  • The deliverable is a document set. If the proposal lists policies and a roadmap but no implementation, you’re buying advice, and your engineers are buying the work.
  • The certificate can’t be traced. Unaccredited ISO certificates and templated SOC 2 reports are the Delve lesson. Ask who the auditor or certification body is, and look them up.
  • Nobody will name the person. A “team of experts” with no named lead usually means a rotating bench.
  • No exit plan. A good engagement plans for its own end: the handoff to your first hire, or to a steady-state rhythm you can run yourselves.
  • They want to call themselves your CISO on day one. Ptacek’s line is worth remembering here too: “willingness to be called a “CISO” at a startup when you have low-single-digit reports is probably a mild red flag” (tptacek on Hacker News, August 2022). Titles are cheap. Outcomes aren’t.

What should the first 90 days with a vCISO look like?

If you’re hiring one, here’s roughly what good looks like, so you can hold whoever you pick to it.

Week 1: intake. Which deals are waiting on security, what the buyers have asked for, and what’s due when. An inventory of cloud accounts, code repositories, identity providers, SaaS tools and AI tools (the shadow ones included). Admin access, in your name. A shared Slack channel.

Days 1 to 30: close what’s blocking revenue. Answer the open questionnaires. Build a reusable answer library and a trust page so the next ten go faster. Stand up a risk register with named owners. Fix the handful of findings buyers always ask about: multi-factor authentication everywhere, single sign-on, access reviews, backups, logging. Pick the framework the pipeline actually needs, and no more.

Days 31 to 60: make the controls real. Policies that match how you work, not how a template thinks you work. Controls running in your cloud and your CI pipeline. A penetration test scheduled, with time reserved to fix what it finds (our AI-accelerated vulnerability remediation program exists because the fixing is usually the bottleneck). An incident response plan and a first tabletop exercise.

Days 61 to 90: start the clock and tell the story. The SOC 2 Type 2 observation window, or the ISO 42001 audit, underway. A one-page security story for the board and investors. A plan for the next two quarters, including when to hire in-house and what that hire should do.

That’s the shape of our own engagements. We got Augment Code ISO 42001 certified in 93 days, and Robust Intelligence had its SOC 2 in three months. Your timeline will depend on your stack, your deadline and how much of the work already exists, but a vCISO who can’t sketch a plan like this in the first week isn’t the one.

When should a startup hire a full-time CISO instead?

Later than most people think, and probably not as your first security hire. Yash was specific when we talked on episode 104: the first security hire is “mostly a staff level, senior staff level engineer that can be independent, but isn’t your true head of security person who’s building the team.” The timing is “a risk decision between what data do you have, how many customers do you have, and what’s at risk.” The first head of security, in his words, “comes much later.”

That leaves a long middle stretch where you need security leadership but not a security executive. A vCISO or on-demand team covers it, and a good one should be building toward the handoff from day one: documented decisions, a program your first hire can inherit, and help writing that hire’s job description. We covered what that handoff looks like in the failure modes of on-demand security. When you do hire a CISO, a16z’s guide on the subject makes a point worth building in from the start: “Most candidates will likely want to report to the most senior executive possible in order to ensure that they have the latitude they need” (a16z, Hiring a Chief Information Security Officer). Authority, again, is the whole game.

The practical signals that it’s time to hire: your fractional spend is heading toward that $180,000 to $220,000 range, you need someone managing a team of security engineers rather than doing the work, or your buyers and board want a security executive with their name on the org chart. The board side of that is changing too: the 2026 edition of the NACD and Internet Security Alliance’s cyber-risk oversight handbook tells directors to “Establish Board Oversight Structures and Access to Expertise” (NACD, April 2026). Until you have a CISO, a vCISO is how a startup board gets that access. If you’re not sure which side of that line you’re on, the ten-question quiz runs the framework on your situation, and yes, one possible answer is “go hire in-house.”

The short answer to “Do we need a CISO yet?”

Probably not a full-time one. You need security leadership the moment a buyer, an auditor or an investor starts asking questions only a security leader can answer, and that usually happens years before a full-time CISO makes financial sense. A vCISO gives you that leadership for the stretch in between, if it’s the right kind: a named, senior person who does the work as well as advises on it, keeps your security claims true, puts risk decisions in front of the right executive, and prices the time you actually use.

That’s exactly how we built YSecurity. Our operators are Silicon Valley security leaders who join your Slack and your stand-ups, work in your cloud and your codebase, and own outcomes: the questionnaire answered, the security call taken, the audit passed, the deal closed. We cover the whole middle stretch in one team, from Sales Support and SOC 2 Type 2 to ISO 42001, penetration testing, 24/7 Monitoring & Response and the AI security work your buyers are starting to ask about, and when it’s time for your first full-time hire, we help you make it and hand the program over. You can see how that’s played out in our case studies, or browse every service we offer.

If you’re a startup, the easiest way to start is to claim 8 free CISO hours and put them against whatever is blocking you right now. If a deal is already stuck on a security review, book a free 15-minute call. Tell us what’s blocking it and we’ll tell you what’s realistic, including a first-pass gap read at no cost. And if you’d rather hear it from a CISO first, Yash Kosaraju walks through exactly when to make the first security hire on episode 104.

The next time a buyer asks to talk to your security leader, you should have a name to give them. We’d like it to be ours.

vCISO frequently asked questions

What is a vCISO?
A vCISO, or virtual chief information security officer, is an experienced security leader who works for your company part-time or on demand instead of as a full-time employee. They own the work a CISO would: security strategy, compliance programs like SOC 2 and ISO 27001, customer security reviews, incident readiness and board reporting. Startups use them to get executive-level security judgment before a full-time CISO makes financial sense.
What's the difference between a vCISO and a fractional CISO?
In practice, very little. vCISO, fractional CISO and CISO-as-a-service are used interchangeably, and no standards body defines them. Some providers use "fractional" for an embedded, part-time leader and "virtual" for a remote one who serves several clients. The label matters less than who the named person is, how much of their time you get, and whether they do the work or only advise.
How much does a vCISO cost?
Published pricing generally runs from about $1,500 to $4,000 a month for companies with fewer than 50 employees, to $3,500 to $15,000 a month for 10 to 45 hours of work, with hourly rates around $200 to $400. Those figures come from providers' own pricing pages, so treat them as directional. At YSecurity, you pay for the time you use, with no long-term contract and a monthly cap you set.
How much does a full-time CISO cost?
According to IANS Research and Artico Search, CISOs at companies under $1 billion in revenue averaged $415,000 in total compensation, and about $260,000 in cash at companies under $50 million in revenue. Add recruiting fees of 25 to 30 percent of first-year compensation, and three to six months or more to fill the role.
Do we need a vCISO to get SOC 2?
Not strictly, but someone has to own it. A SOC 2 needs scoping, policies, working controls, evidence across an observation window, and an auditor relationship. Startups without a security leader usually pull senior engineers off the roadmap to do it, which is slower and more expensive than it looks. A vCISO or on-demand team owns the process, and we typically get first-time clients through SOC 2 Type 2 in about five months.
Can Vanta or Drata replace a vCISO?
No, they do different jobs. Compliance automation platforms run continuous configuration checks, collect evidence and provide policy templates, which saves a lot of time. They don't make judgment calls like how to classify your data, which vendors to approve, or what your auditor will accept, and they don't join your customer's security call. Most startups that do this well use a platform and have a security leader run it.
Is a vCISO personally liable if the company has a breach?
Case law on fractional CISOs is thin, and this isn't legal advice. The two cases every security leader knows are the SEC's suit against SolarWinds and its CISO, which the SEC dropped in November 2025, and the criminal conviction of Uber's former security chief for concealing a breach, which the Ninth Circuit upheld in 2025. The practical lessons are the same for full-time and fractional leaders: put risk decisions in writing, make sure the executive who owns the business accepts the risk, keep public security statements accurate, and check the contract's indemnification and insurance terms.
When should a startup hire a full-time CISO?
Usually well after the first security hire. a16z CISO Yash Kosaraju recommends making the first security hire a senior, independent engineer, with a head of security coming much later as the team grows. A practical signal is when fractional spend approaches $180,000 to $220,000 a year, or when you need someone to manage a team of security engineers.
How fast can a vCISO start?
Much faster than a hire. Hiring a senior security person commonly takes three to six months before they start, then ramp time. A vCISO or on-demand team can usually start within days. At YSecurity, we send the contract within one business day of approval, and a dedicated lead joins your Slack and stand-ups from kickoff.
What should we ask before hiring a vCISO?
Ask who does the work day to day and how many other clients that person carries, whether they work in your cloud and codebase or only on documents, whether they'll complete customer questionnaires and join security calls, whether they resell security products, what documentation you keep if you stop, what the minimum term is, and whether they carry errors and omissions insurance.
Written by the team behind The Security Podcast of Silicon Valley

Put it into practice.