Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
A virtual CISO, also called CISO as a service or a fractional CISO, gives an organisation named security leadership for a fraction of the cost of a permanent hire. Engagement models range from ad hoc day rates to fixed days each week, and the right choice depends on mandate, authority and workload. This guide explains the role, pricing structure and limits, and when a permanent hire fits better.
Checking a proposal against these five points keeps the engagement focused on outcomes.
A permanent CISO is the textbook answer, though most mid-market organisations lack the budget or the volume of work to justify one. A virtual CISO fills the gap with named leadership on a part-time basis, and our enterprise cyber risk management service shows how that leadership connects to a wider risk programme. The same role appears under several names, including CISO as a service and fractional CISO, and proposals use them interchangeably.
You see, the useful first step is a baseline before a hire. A cyber risk assessment shows where exposure sits and what a leader would need to own, which also makes the mandate for a vCISO easier to write. Organisations that define the mandate first tend to get more from the engagement than those that sign a retainer and work out the scope later.
Confirm which of these a proposal actually includes and ask what hours each one is expected to consume, because proposals often list all nine and resource two. Responsibilities that sit outside the retainer, such as audit support or incident involvement, should appear as separately priced items. Our GRC overview explains how governance, risk and compliance functions fit together, which helps you judge what a given proposal covers.
| Model | How it works | Typical commitment | Best suited to | Main limitation |
| Day rate, ad hoc | The organisation books the vCISO for specific days or tasks and pays for time used. | There is no standing commitment, and work happens when the organisation requests it. | It suits organisations that need occasional advice, a second opinion or a single decision. | Nobody holds standing accountability between engagements. |
| Retained monthly hours | The organisation pays a monthly fee for a defined allocation of hours and agreed responsibilities. | A multi-month commitment with a set cadence of meetings and reporting is common. | It suits organisations that want steady leadership at a predictable cost. | Hours can run out in a busy audit period, so overage terms matter. |
| Fractional, fixed days per week | The vCISO works set days each week or month and operates as part of the leadership team. | A recurring schedule gives a consistent presence, with the days written into the contract. | It suits organisations that need a visible, regular leader across teams and the board. | Fixed days price continuity even in quiet periods, so cost is higher than ad hoc work. |
| Project or programme based | The provider delivers a defined outcome, such as a gap assessment or audit readiness programme, for a fixed scope. | The engagement ends when the deliverables are accepted. | It suits organisations preparing for a specific audit, tender or certification. | A project does not create standing accountability once it ends. |
Match the model to the problem you are solving. A one-off tender or audit points to a project, steady governance points to a retainer or fixed days, and a gap before a permanent hire points to an interim arrangement. Our cyber risk management service describes how Microminder supports ongoing risk oversight alongside any of these models.
Seniority and sector experience move the rate more than anything else. A leader with regulated-sector experience and a bench of specialists behind them costs more than a generalist, and that experience usually shows up in audits and regulator conversations. Deliverable load also matters, because an engagement that includes customer-facing security calls and questionnaire ownership consumes more hours than the calendar suggests.
Several items are commonly excluded from the base fee. Audit support, incident involvement beyond escalation, travel and implementation work such as writing policies in bulk often attract separate charges. Certification costs, such as a certification body's fees, are paid to third parties and sit outside any retainer, as our ISO 27001 certification guide explains.
Ask each provider to state hours per month, what falls inside them, the overage rate and the minimum term. Ask also whose calendar the work lands on when the roadmap creates tasks, since a retainer that buys leadership still leaves implementation to your own teams or to a separately priced service. That question tends to separate a clear proposal from a vague one.
| Factor | Virtual CISO | Permanent CISO |
| Cost shape | Cost follows the days or hours bought and is usually a fraction of a full-time executive, though it scales up with workload. | Cost is a fixed salary and benefits package plus recruitment, and it rises with the seniority the role demands. |
| Time to productive | A provider can often start within weeks because it brings its own methods and templates. | Recruiting a senior security leader can take months, followed by an onboarding period. |
| Breadth of experience | A vCISO draws on experience from many organisations and sectors, which helps with benchmarks and frameworks. | A permanent CISO builds deep knowledge of one organisation, its systems, people and history. |
| Availability during an incident | Availability depends on contract terms, and a vCISO may be unavailable when a sustained incident needs daily leadership. | A permanent CISO is present and available throughout a sustained incident. |
| Authority over internal teams | A vCISO usually has influence and a reporting line to leadership but limited line authority over staff. | A permanent CISO can direct teams, set priorities and make decisions within the function. |
| Continuity risk | Continuity depends on the provider keeping the named person, so contract terms on substitution and notice matter. | Continuity depends on retention, and one departure can leave a gap that takes months to fill. |
| Suits organisations that | It suits organisations that need leadership, face a compliance driver and lack the volume of work for a full-time role. | It suits organisations where security is central to the product or business, regulators expect a full-time officer or workload exceeds fractional hours. |
Many organisations follow a hybrid path in which a vCISO builds the function, then helps write the role description, screens candidates and hands over to a permanent hire. That sequence can help reduce the risk of hiring before the organisation knows what it needs. Neither model is inherently better, and the right answer follows the organisation's size, regulatory exposure and appetite for building a team.
Limits also arise from capacity and presence. A part-time leader may be unavailable during a sustained incident, and the model depends on internal teams able to carry out the work the roadmap creates. A vCISO who is asked to write server configuration standards or build monitoring dashboards has drifted from leadership into engineering, which is a different service.
Accountability in a regulatory sense usually stays with the organisation and its board, even where a provider leads the function. Supplier assurance sign-off is one place where the line matters, and our third-party and supply chain risk management guide explains how a vCISO can lead the assessment approach while the business keeps the decision on risk acceptance. Stating these limits in the contract protects both parties.
NESA's Information Assurance Standard expects a security strategy approved by senior leadership and a documented risk management process, which a vCISO can lead but which senior management must approve and own. ISO 27001 likewise requires top management to assign responsibility and authority for information security and to receive reporting on its performance. Our NESA compliance guide covers the framework for covered entities.
ADHICS requires Abu Dhabi health entities to designate a Chief Information Security Officer or equivalent who reports to a governance committee, as covered in our ADHICS compliance guide. The Dubai Information Security Regulation goes further, since version 3 requires the information security function to be led by a UAE National serving as CISO and reporting to top management. An organisation under either framework should confirm with the authority or assessor how a contracted vCISO fits the named-role requirement before signing.
Review the brief at the end of the first quarter and adjust hours, scope or model based on what the engagement has actually consumed. Measurable outcomes can help show progress to leadership, and our guide to cyber risk quantification explains one way to express risk in financial terms. Results depend on how quickly the organisation acts on the vCISO's recommendations.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cloud Security | 07/10/2026
Cloud Security | 07/10/2026
Cyber Threats | 07/10/2026
What is a virtual CISO?
A part-time or contracted security leader who owns strategy, risk reporting and compliance oversight for an organisation.How much does a vCISO cost in the UAE?
Cost follows seniority, sector experience and the hours or days bought. Providers quote after scoping, so request a written scope.Is a vCISO the same as a fractional CISO?
In most proposals, yes. The terms vCISO, CISO as a service and fractional CISO usually describe the same arrangement.How many days a month does a vCISO work?
It varies by scope, from a few hours a month for advice to several days a week for compliance-heavy programmes.Can a vCISO sign off compliance?
A vCISO can lead the programme, but accountability usually stays with the organisation. See our GRC overview.Do UAE regulations require a CISO?
Some do. ADHICS expects a CISO or equivalent, and DESC ISR V3 requires a UAE National CISO. See our ADHICS compliance guide.Is a vCISO the same as a data protection officer?
They are usually separate roles. The DPO role has its own PDPL requirements. See our PDPL compliance guide.