The call usually comes after something has already gone slightly wrong. A promising enterprise deal has stalled three weeks into the customer's security review, or the cyber-insurance renewal has arrived with forty questions nobody in the building can answer, or there was a near-miss that everyone would rather not talk about. Whatever the trigger, a company that has been running on good instincts and a capable IT team suddenly realizes it carries real security risk, and that nobody actually owns it.
The instinct at that point is to hire a Chief Information Security Officer, and the sticker shock lands about a minute later. A full-time security executive is a serious salary, plus bonus and equity and benefits, and for a company of twenty or eighty or a hundred and fifty people that is a lot of money for a role you are not yet sure how to keep busy. That gap, too big to ignore the risk and too small to fund a full-time executive, is where a virtual CISO fits.
A vCISO is fractional security leadership. You get the same executive judgement, the strategy and the hard prioritization calls and the board-level translation, without the cost or the commitment of a full-time hire. What follows is what those first ninety days should actually look like, including the parts that never make it onto the tidy deliverables slide.
The first thirty days: listen, then map
The first month is mostly listening, and resisting the urge to start fixing things before anyone understands them. A good vCISO sits down with people across the business, not only IT, because real risk crosses org charts. Leadership explains what the company is actually trying to do over the next year. Legal and operations point to where the sensitive data lives and which contracts have security obligations buried in them. The IT team is the one to really listen to. They usually know exactly where the soft spots are, and this is their chance to name what they have been asking for and not getting for years.
Alongside the interviews comes a gap analysis against a real framework, usually NIST CSF 2.0, sometimes ISO 27001 or CIS Controls if that is what your customers or auditors are asking for. Month one is not the time for a perfect asset inventory or a gold-plated policy set, and chasing either is how these engagements stall before they start. The job is narrower and more useful: find where the bodies are buried, put out whatever is actively on fire, and show the client that a plan is taking shape.
Days thirty to sixty: a roadmap that survives contact with your budget
With a real picture of the environment, the work shifts to a plan. The roadmap should be risk-based, tied to your business priorities and the budget you actually have, rather than the wishlist a vendor would hand you. Some of it is governance, the policies and the board-ready reporting that turn security from a vibe into something you can show an auditor or an insurer. Most of it is sequencing.
Sequencing is where a vCISO earns the fee, and it is the part the checklists gloss over. Security work stalls in the gray areas, in the arguments about what to fix first, what to simply accept, and what to stop doing entirely. Someone has to make those calls with a clear head when the facts are messy and everyone in the room has an opinion. That judgement is most of what you are paying for, far more than any single document.
I saw this done well once, up close. Years back I was the cybersecurity program manager at Air Canada, running the security projects under a CISO whose approach surprised me at first. He did not chase the loudest threat of the month. He started with the basics and the people on the ground, reinforced the habits that actually prevent incidents, and spent a finite budget against the risks the business genuinely could not absorb. The gaps that mattered got filled. The ones that carried less risk got documented and deferred, on purpose, because the money only stretched so far and pretending otherwise would have helped no one. That discipline is what carried the program through COVID, about as brutal a stretch as the airline industry has ever had. It taught me that most of security leadership is the nerve to say "not yet" to something real, so you can say "now" to something that matters more.
Days sixty to ninety: start, and prove it
In the final stretch the work turns to executing the roadmap, beginning with the changes that close the most risk for the least disruption. That often means multi-factor authentication everywhere, tightening who holds administrator access, adding endpoint detection where it is missing, and writing a policy or two that were overdue. Alongside that comes a plain-language risk register and a small set of metrics, so the first board update shows what changed and what decisions are still waiting on you.
Ninety days does not finish security, and anyone who tells you otherwise is selling something. It does finish the hardest part, though: the shift from no owner and no plan to a clear picture, a ranked roadmap, and a couple of early wins the whole company can see. From there the engagement settles into something steadier and a good deal less dramatic.
Two things that decide whether it works
Two conditions make or break the whole ninety days, and both of them sit on your side of the table rather than the vCISO's. The first is locking the scope before the engagement starts, so everyone agrees on what it is and is not, and nobody is surprised in month two. The second matters even more, and it is having a real counterpart inside the company who is allowed to make decisions.
Without that counterpart, even a strong roadmap stalls, because the vCISO ends up spending weeks chasing people for answers instead of reducing risk. A vCISO can carry the expertise and the judgement, and cannot carry a decision that only an owner or a founder is allowed to make. The engagements that go well are the ones where someone on your side is genuinely bought in.
Do you even need one yet?
Sometimes it is genuinely not yet, and a good advisor will tell you so rather than take on a retainer you do not need. If you are a handful of people with no sensitive customer data and no contracts demanding security governance, your money is better spent elsewhere for now. The picture changes when you start handling data that would hurt if it leaked, when PIPEDA or Quebec's Law 25 obligations enter the room, when SOC 2 lands on the roadmap because a customer requires it, or when deals start stalling on security questionnaires you cannot answer. Those are the moments a vCISO stops being a nice idea and starts paying for itself.
None of this is mysterious, and it is not meant to be. The first ninety days with a good vCISO buy you a clear-eyed map of your risk, a plan you can afford, and the judgement to work through it in the right order. If that sounds like the thing your company is missing, that is the work our team does. If you would rather start by seeing where you stand before you bring anyone in, the self-hosted assessment we build runs the same kind of gap analysis a vCISO would begin with, on your own infrastructure.