vCISO or Full-Time CISO: Which Does Your Company Need?
Most companies asking this question are not close to needing a full-time CISO, and the reason is not the salary. It is that at your size the job does not generate a full week of executive decisions, so a full-time hire spends a large share of their hours doing work a fractional arrangement covers. We publish $415,000 as the average total compensation for a full-time CISO at a small or midmarket organization, per IANS Research and Artico Search, in our vCISO guide, and the tiers for the fractional alternative in the in-house versus outsourced comparison; this article does not restate either as a market survey, because the trigger that actually decides the question is not a price. Go full-time when security leadership needs daily attention: a security team to manage, more than one regulator, a board that carries security as a standing agenda item, and incident volume that cannot wait for Thursday's call. Funding stage is a weak signal. The first enterprise deal that arrives with a security questionnaire is usually the real one.
The rest of this piece is the four triggers, the cost arithmetic worked honestly, the hybrid path most companies actually take, and the cases where fractional leadership is the wrong answer and you should hire.
Key takeaways
- The deciding variable is how often security leadership has to make a decision, not how many employees you have or how much revenue you book.
- Four triggers point at a full-time hire: a security team to manage, multiple regulators, a board that meets on security, and incident volume that cannot wait for a scheduled call.
- The cost saving from a fractional arrangement is real but smaller than the category advertises once you compare the top of one band with the bottom of the other.
- Public CISO compensation surveys report large-cap numbers; quoting them at a 150-person company misleads in both directions.
- The most common good outcome is not either pole: a fractional leader builds the program, defines the role, and helps recruit the person who inherits it.
What each arrangement actually buys you
A full-time CISO buys availability and ownership. They are in the room when product decides to store a new category of customer data, they see the Slack thread where an engineer asks whether it is fine to grant a contractor production access, and they own the outcome without anyone having to schedule them. That presence is the product. It is also the reason the role is expensive: you are paying for capacity you may not consume.
A fractional or virtual CISO buys judgment and structure on a defined cadence. You get a security program, a risk register that is maintained rather than written once, a roadmap with a sequence and a budget, framework ownership, and someone who presents to your board without needing a briefing first. What you do not get is somebody watching your Slack. The trade is deliberate: less presence, similar or better seniority per hour, and a cost that scales with what you actually use.
Both roles do the same category of work. The difference is not sophistication, and any provider or recruiter who frames it that way is arguing their own book. The difference is the shape of the demand.
The four triggers that mean full-time
You have a security team to manage. Once two or more people report into security, someone has to run performance reviews, set priorities weekly, unblock work, and be accountable for the team's output. A fractional leader can mentor an engineer and can hold a program; they cannot be an effective people manager on a part-time schedule, and pretending otherwise is how good security engineers quit. If you have hired your second security person, start the CISO search.
You have more than one regulator. One framework is a project. Two frameworks with overlapping evidence is still a project. A bank examiner, a state insurance regulator, and a healthcare auditor all wanting different narratives about the same control set is a standing job, because regulatory relationships are relationships and they do not pause between engagements. Our cross-framework work exists precisely to compress the overlap, and it compresses effort, not the relationship management.
Your board carries security as a standing agenda item. Not "the board asked about the breach in the news", which is a question a fractional leader answers well. A standing item means quarterly reporting against approved thresholds, follow-up questions between meetings, and a director who wants a hallway conversation. That is executive-calendar work.
Incidents arrive faster than your call schedule. If your team is triaging something real more than a few times a quarter, a leader who is available on a cadence is structurally the wrong shape. Note the trigger carefully: it is not "we might have an incident". Everyone might. It is incident volume that has already outgrown scheduled attention. If you are unsure where you sit, our piece on when to call an incident response firm separates the events that need a retainer from the ones that need a leader.
Notice what is not on that list. Revenue is not on it. Employee count is not on it. Series B is not on it. Those correlate with the four triggers loosely enough that using them as a proxy produces both mistakes: the 400-person services business that never needed a CISO, and the 60-person fintech that needed one two years ago.
The arithmetic, and why the saving is smaller than the category claims
Here is the honest version, worked rather than asserted.
As of August 2026, our published tiers for fractional security leadership run $4,000 to $6,000 a month at the base tier and $10,000 to $12,000 a month for the dedicated tier that carries a named vCISO, per the in-house versus outsourced comparison. Annualize the dedicated tier across twelve months and set the result against the total compensation band above. At the expensive end of the fractional tier and the cheap end of the in-house band, the fractional route costs roughly three-quarters as much. At the cheap end of the fractional tier and the expensive end of the in-house band, it costs under a third. So the range of honest answers runs from roughly a quarter saved at one extreme to about 70 percent saved at the other, depending entirely on which end of each band you land on.
That is a real saving. It is not the 80 or 90 percent the category advertises, and the advertised figure is usually manufactured by comparing the cheapest fractional package against the most expensive in-house package, which is a comparison of two things nobody buys together.
Two adjustments make the arithmetic more honest still, and they push in opposite directions.
Against the fractional case: a full-time hire absorbs work you would otherwise buy. Vendor questionnaire responses, security awareness administration, access review chasing. Under a fractional arrangement some of that lands on a manager, an office lead, or an engineer who is worse at it and resents it. That is a real cost even though it never appears on an invoice.
For the fractional case: the total compensation band is not the total cost of the hire. Recruiting a security executive takes months, the search itself costs money, and the first quarter is ramp. A fractional leader is operating in weeks. If a customer contract or a certification deadline is the thing forcing the decision, the calendar difference is often worth more than the money difference.
Public compensation surveys, and how to read them
Compensation data for this role is genuinely published. Heidrick and Struggles' 2025 Global Chief Information Security Officer Compensation Survey surveyed 371 CISOs worldwide and is the sixth in an annual series, which makes it the most citable dataset in the category.
Read it with the methodology in mind. The data is self-reported and aggregated, the respondents are in the United States and Europe, and the totals include annualized equity or long-term incentive pay and joining bonuses rather than salary alone. Quoting them at a 150-person company overstates what you would pay, and quoting the bottom of a national job-board range understates what a credible candidate accepts. That gap between two published, honestly collected numbers is why we publish a band for the size of company we work with rather than repeating a survey median as though it applied to everyone.
The hybrid path most companies actually take
The version that works, and the one we see most often, is sequential rather than either-or.
A fractional leader builds the program: control environment, risk register, framework ownership, the incident response plan and the tabletop that proves it works, the board reporting rhythm. Twelve to twenty-four months later the four triggers have started firing, and the company hires. The person they hire inherits a program with documentation, a roadmap, and a board that already knows what security reporting looks like, which is a dramatically better first day than the alternative.
Two details make this work rather than turn into a handover mess. First, write the job description while the fractional leader is still engaged, because they know what the role actually consumes. Second, keep them on for a defined overlap after the hire starts, then end it on a date. Open-ended overlaps blur accountability, and the new CISO needs the authority to disagree with the program they inherited.
When a vCISO is the wrong answer
This is the part that costs us work, so read it as such.
If you already have two or more security people, hire. We can support a team; we should not be its manager, and an arrangement where a part-time external leader is nominally responsible for full-time employees produces confused reporting lines and slow decisions.
If your security work is genuinely daily, hire. A leader available on a cadence will be the bottleneck in every decision that cannot wait, and you will feel it as slowness that nobody can quite locate.
If you want a name on a customer questionnaire and nothing else, do not buy either. A titled leader with no hours behind them is a misrepresentation risk, not a control, and it is exactly the kind of overstatement that becomes a problem when an insurer or an enterprise buyer checks. Answering a cyber insurance questionnaire honestly covers what happens when that check comes.
And if what you actually need is a compliance program rather than security leadership, say so and buy that instead. The two get conflated constantly, and the distinction is worked through in hire a compliance manager or outsource.
Where Top Floor fits
Our vCISO practice is built for the middle of this decision: companies with real security obligations, no security team to manage yet, and a program that needs an owner rather than a headcount. Engagements are senior-led, the operator is named before you sign, and the tiers are published rather than quoted after a discovery call.
Where the driver is a certification or an attestation rather than leadership as such, the work usually belongs in compliance as a service instead, and we will tell you that rather than sell the bigger engagement.
How to decide this week
Take the four triggers and mark each one yes or no against the last ninety days, using evidence rather than intent. Count the security people who report into the function. Count the regulators and enterprise auditors who have asked you for something. Look at your board minutes for a standing security item. Count the incidents your team actually triaged.
Zero or one trigger: a fractional arrangement is almost certainly right, and the question is scope, not shape. Two triggers: run fractional now and write the CISO job description this quarter. Three or four: start the search, and consider a fractional leader for the interim, because the search will take longer than you think and the program should not stall while it runs.
Frequently asked questions
At what company size do we need a full-time CISO?
There is no reliable size threshold, which is why the good advice is behavioural rather than numeric. The four practical triggers are a security team of two or more people reporting into the function, more than one regulator or examiner to maintain a relationship with, a board that carries security as a standing agenda item, and incident volume that outgrows a scheduled call. Companies hit those at wildly different headcounts: a 60-person fintech often hits three of them, and a 400-person services business can hit none.
Is a vCISO cheaper than hiring a CISO?
Yes, but by less than the category advertises. Comparing our published fractional tiers with our published band for a full-time in-house security leader's total compensation, the fractional route lands between roughly a quarter and about 70 percent cheaper depending on which end of each band applies to you. The advertised 80 or 90 percent figures come from comparing the cheapest possible package against the most expensive possible hire. Factor in the work a full-time hire absorbs that you would otherwise buy, and the gap narrows further.
Can a vCISO manage our security engineers?
Not well, and we would decline the arrangement. A fractional leader can mentor engineers, set technical direction, and review work. Line management is different: it needs weekly unblocking, performance conversations, and availability that a cadence-based engagement does not provide. Once two or more people report into security, that is the clearest single signal in this whole article that it is time to hire.
Should we hire a CISO before our first SOC 2 audit?
Usually not. A first SOC 2 engagement is a program with a defined scope and end state, which is exactly the shape of work a fractional leader or a compliance team handles well, and hiring an executive to run one project is expensive sequencing. Hire when the obligations become continuous and plural rather than when the first one arrives.
Related Services
Need help with your compliance program?
Our team of senior practitioners can help you navigate complex compliance requirements and build a security program that holds up under scrutiny.
Schedule a Free ConsultationGet insights like this in your inbox
Practical compliance and security guidance for teams preparing for their next audit. No spam, unsubscribe anytime.
Ask to be added to our mailing list for practical compliance and security guidance. We add you by hand, we confirm before sending anything, and we never share your address.