Services · vCISO
A security leader, on retainer. Not a freelancer, not a full-time hire.
Hiring a full-time CISO means a senior salary, benefits and recruiter fees, and months of searching before anyone starts. A vCISO from VITI Security gives you the same strategic security leadership - board-ready risk reporting, security roadmaps, compliance ownership, vendor management - for a fraction of the cost. We embed with your team, run your security program, and stand behind the work when auditors and customers ask.
Engagement tiers
Three tiers, picked to match your stage.
All tiers run as a monthly retainer with a three-month minimum, then month-to-month, 30-day exit either side. The starting price is published; every tier gets a fixed quote once we know your framework and deadline.
Strategic Advisor
4-8 hours / month
Starting from
- Monthly security review with your leadership
- Risk register maintained and prioritized
- Quarterly board-ready security summary
- Policy review (existing or new)
- Escalation point for security incidents
- Right for: 20-50 person teams that have basic security in place
Engaged vCISO
15-25 hours / month
- Everything in Strategic Advisor, plus:
- Security roadmap with quarterly milestones
- Vendor security assessments (SaaS, infra)
- Compliance ownership (ISO 27001, SOC 2, GDPR, PCI-DSS - pick what applies)
- Incident response readiness drills
- Customer security questionnaire responses
- Architecture and cloud-config review
Full vCISO
40+ hours / month
- Everything in Engaged, plus:
- Acts as your CISO in customer and investor conversations
- Manages your security team and outside vendors
- Owns your compliance certification process end-to-end
- Available for breach response and crisis management
- Onsite as needed
What it costs
The honest arithmetic on a vCISO.
A full-time CISO is a senior salary, before equity, benefits, recruiter fees and the months you spend not having one. For a company of 20 to 200 people that is rarely the right first security hire - not because the work is not needed, but because the work is not full-time yet. A retainer buys you the judgement without the headcount, and you can stop.
- Priced as a retainer, not a salary: you pay for the hours the work needs, and you can stop.
- Three-month minimum, then month-to-month with 30 days notice either side. No annual lock-in.
- The fee is the fee. We do not bill hourly against a retainer and we do not invoice for the monthly review call.
- No tooling markup. Where a client needs scanning, it runs on Vexta, which we own - so you are not paying a licence fee with our margin on top.
- You keep everything. The risk register, the policies, the roadmap and the evidence pack are yours on day one and if you leave.

What moves the price
Why two companies of the same size get different quotes.
Headcount is the worst predictor of vCISO cost. These five things actually drive it.
Which framework, and how far off you are
SOC 2 from a standing start is a bigger programme than ISO 27001 when you already hold ISO 9001. We scope against your current evidence, not your headcount.
Whether there is a deadline
An audit date, a funding round, or an enterprise customer holding a signature is the single biggest cost multiplier. Compressed timelines need more hours per month, not more months.
How much you want us to do versus advise
Advising your team on policy is cheaper than us writing it. Both are legitimate. The Strategic tier assumes you have people to execute; Engaged assumes you need some of it done for you.
Regulatory exposure
Handling card data, health records or regulated financial data raises the floor on controls, evidence and review frequency. It is not an upsell, it is the standard.
How many vendors and systems are in scope
Thirty SaaS tools with no access review is a materially different programme from six. Vendor risk is usually the most underestimated line in a first quote.
What a vCISO actually does
The job in plain terms.
The word CISO gets thrown around. Here is what one actually owns.
The risk register
A live list of every security risk to your business - ranked by impact and likelihood, with owners and target dates. Without this, security is reactive.
The security roadmap
What you will fix in Q1, Q2, Q3 - and the trade-offs that requires (budget, time, hires).
Policies that match how you work
Not 50-page documents nobody reads. Lean, enforceable, written for your team size.
Board + customer reporting
Translating "we patched 47 CVEs" into language your board and your enterprise customers care about.
Vendor + contract review
Catching the SLA gaps, data residency issues, and breach notification clauses BEFORE you sign.
Compliance ownership
ISO 27001, SOC 2, HIPAA, PCI-DSS, GLBA - picking the right framework and getting you through it.
Incident readiness
Tabletop exercises. A runbook for ransomware, data breach, account takeover. So the day it happens, your team does not panic-Google.
The alternatives
Four ways to get security leadership. Only one of them is us.
An honest comparison, including where the other options genuinely win.
| Feature | Full-time CISO | Independent freelancer | Big-four advisory | VITI vCISO |
|---|---|---|---|---|
| Cost per month | A senior salary, plus benefits and hiring costs | Day or hourly rates | Advisory day rates, scoped per project | From $2,099 a month |
| Time to productive | Months to hire | Weeks | Weeks | 30 days |
| Full attention on your business A full-time hire wins this outright. Anyone fractional is splitting attention, including us - the question is whether the work needs a full week. | ✓ | ∼ | ✕ | ∼ |
| Cover when they are unavailable | ✕ | ✕ | ✓ | ✓ |
| Named person your auditor can call Large advisories may rotate staff between engagements. | ✓ | ✓ | ∼ | ✓ |
| Owns their own testing tooling Most providers license a third-party scanner and pass on the cost. We wrote ours, so there is no markup and we can show you the check behind any finding. | ✕ | ✕ | ✕ | ✓ |
| Vendor-neutral tool recommendations We hold no reseller agreements, so nothing we recommend pays us a referral fee. | ✓ | ∼ | ✕ | ✓ |
| Can be stopped in 30 days | ✕ | ✓ | ✕ | ✓ |
The first 90 days
What actually lands, and when.
Every deliverable below is yours to keep, including if you stop at the end of the minimum term.
Weeks 1-2
Assessment and a written risk register
Your vCISO reviews the stack, the policies you already have, your vendor contracts and your access model. You get a ranked risk register with owners and target dates. This is the document most companies have never had, and it is the one that makes every later decision arguable rather than instinctive.
Weeks 3-4
Quick wins and the customer-facing answer
MFA and access gaps closed, a security page your sales team can send to prospects, and a first pass at the security questionnaire that keeps stalling your deals. Visible progress in month one, because a programme nobody can see gets defunded.
Month 2
The roadmap and the framework decision
Which framework you are actually going for, why, and what it will cost in budget and engineering time. Quarterly milestones with named owners. If the honest answer is that you are not ready to start a certification this year, that is what the roadmap will say.
Month 3
Policies, drills and board reporting
Lean, enforceable policies matched to how your team already works. A tabletop exercise against the incident most likely to hit you. And a board-ready summary that translates the technical work into the two or three sentences your directors will actually retain.
Why VITI for vCISO
Why our vCISO retainer beats hiring a single freelancer.
Fractional pricing
A full-time CISO is a senior salary plus benefits. A retainer gives you the strategic work for the hours it actually needs.
Recognized methodology
Our consultants follow the standards your regulators and auditors recognize for incident response and security audits, mapped to ISO 27001 and SOC 2.
Cross-framework experience
ISO 27001, SOC 2, HIPAA and GDPR readiness draw on the same underlying controls. We work across all of them rather than specialising in one, because picking the wrong framework first is the expensive mistake.
A firm, not a single person
A freelancer who goes quiet takes your programme with them. Your risk register, policies and evidence live with us and are handed over intact, and the founder is on every quarterly review, so continuity does not rest on one calendar.
No tool kickbacks
Our vCISO recommends the tool that fits your stack, not the one that pays us a referral fee. We have no commercial partnership with any security vendor.
When not to hire us
Four situations where a vCISO is the wrong purchase.
We would rather lose the deal on the call than six weeks in. If any of these describe you, say so and we will tell you what to do instead.
You need one specific thing done
If the actual need is a penetration test, a gap assessment or a single policy set, buy that. A retainer is for ongoing ownership, and paying monthly for a one-off is the most common way companies waste money on security.
Nobody internally can execute
A vCISO decides what to fix and in what order. Someone still has to do it. If you have no engineering capacity at all, the honest sequence is managed IT first, security leadership second - otherwise you are buying a roadmap nobody will drive.
You already have a security manager
If someone in-house already owns risk and reports to the board, a second voice usually creates friction rather than progress. Targeted advisory hours or a peer review will serve you better than a retainer.
You need an empanelled or accredited signature
We are not a CERT-In empanelled firm and we are not a certification body. If your regulator or contract requires that specific signature, you need the firm that holds it. We will happily prepare the work so their engagement is shorter and cheaper.
How a vCISO engagement starts
From scoping call to embedded leadership in 30 days.
30-minute scoping call
We understand your business, current security state, and immediate pressures (audit deadline, customer ask, near-miss incident).
Two-week assessment
Your assigned vCISO reviews your stack, policies, contracts, and team. You get a written risk register at the end - yours to keep even if you do not engage further.
Engagement begins
Tier chosen based on the assessment. Monthly retainer, three-month minimum, then month-to-month.
Continuous + reviewable
30-day exit either side. We would rather you find the right CISO than feel locked in.
vCISO FAQ
How much does a vCISO cost?
Why is your pricing on the website when most firms hide it?
Is a vCISO cheaper than hiring a CISO?
How is a vCISO different from a security consultant?
Do we really need this? We have an IT lead already.
How quickly is a vCISO effective?
Can a vCISO get us through SOC 2 or ISO 27001?
What happens if we get breached during the engagement?
What is the minimum commitment?
Do you resell security tools?
Who actually does the work?
Where are your vCISOs based, and can you work our hours?
What do we get to keep if we stop?
Next steps
Pick the next step.
Pick whichever fits how far along you are - we will meet you there.
Run a free website scan
Point it at a website you own and get a findings summary - no sales call needed.
Get a quote
Four short fields below. A fixed quote back within one business day.
Book a call
30 minutes, no deck, no pre-qualification. Bring the actual problem.
Get a quote
Four fields. A fixed quote within one business day.
No sales call required to get a number. Tell us what triggered this and when you need it by, and we will come back with a fixed price for vCISO.
Get a security leader on your team.
30-minute scoping call. We assess whether a vCISO is the right move, recommend a tier, and quote a fixed monthly fee. No commitment to book the call.

