Skip to content
VITI Security

Services · vCISO

A security leader, on retainer. Not a freelancer, not a full-time hire.

Hiring a full-time CISO means a senior salary, benefits and recruiter fees, and months of searching before anyone starts. A vCISO from VITI Security gives you the same strategic security leadership - board-ready risk reporting, security roadmaps, compliance ownership, vendor management - for a fraction of the cost. We embed with your team, run your security program, and stand behind the work when auditors and customers ask.

Engagement tiers

Three tiers, picked to match your stage.

All tiers run as a monthly retainer with a three-month minimum, then month-to-month, 30-day exit either side. The starting price is published; every tier gets a fixed quote once we know your framework and deadline.

Strategic Advisor

4-8 hours / month

Starting from

$2,099/ month
  • Monthly security review with your leadership
  • Risk register maintained and prioritized
  • Quarterly board-ready security summary
  • Policy review (existing or new)
  • Escalation point for security incidents
  • Right for: 20-50 person teams that have basic security in place
Get a quote
Most popular

Engaged vCISO

15-25 hours / month

Quoted to your scope
  • Everything in Strategic Advisor, plus:
  • Security roadmap with quarterly milestones
  • Vendor security assessments (SaaS, infra)
  • Compliance ownership (ISO 27001, SOC 2, GDPR, PCI-DSS - pick what applies)
  • Incident response readiness drills
  • Customer security questionnaire responses
  • Architecture and cloud-config review
Get a quote

Full vCISO

40+ hours / month

Quoted to your scope
  • Everything in Engaged, plus:
  • Acts as your CISO in customer and investor conversations
  • Manages your security team and outside vendors
  • Owns your compliance certification process end-to-end
  • Available for breach response and crisis management
  • Onsite as needed
Get a quote

What it costs

The honest arithmetic on a vCISO.

A full-time CISO is a senior salary, before equity, benefits, recruiter fees and the months you spend not having one. For a company of 20 to 200 people that is rarely the right first security hire - not because the work is not needed, but because the work is not full-time yet. A retainer buys you the judgement without the headcount, and you can stop.

  • Priced as a retainer, not a salary: you pay for the hours the work needs, and you can stop.
  • Three-month minimum, then month-to-month with 30 days notice either side. No annual lock-in.
  • The fee is the fee. We do not bill hourly against a retainer and we do not invoice for the monthly review call.
  • No tooling markup. Where a client needs scanning, it runs on Vexta, which we own - so you are not paying a licence fee with our margin on top.
  • You keep everything. The risk register, the policies, the roadmap and the evidence pack are yours on day one and if you leave.
The honest arithmetic on a vCISO.

What moves the price

Why two companies of the same size get different quotes.

Headcount is the worst predictor of vCISO cost. These five things actually drive it.

Which framework, and how far off you are

SOC 2 from a standing start is a bigger programme than ISO 27001 when you already hold ISO 9001. We scope against your current evidence, not your headcount.

Whether there is a deadline

An audit date, a funding round, or an enterprise customer holding a signature is the single biggest cost multiplier. Compressed timelines need more hours per month, not more months.

How much you want us to do versus advise

Advising your team on policy is cheaper than us writing it. Both are legitimate. The Strategic tier assumes you have people to execute; Engaged assumes you need some of it done for you.

Regulatory exposure

Handling card data, health records or regulated financial data raises the floor on controls, evidence and review frequency. It is not an upsell, it is the standard.

How many vendors and systems are in scope

Thirty SaaS tools with no access review is a materially different programme from six. Vendor risk is usually the most underestimated line in a first quote.

What a vCISO actually does

The job in plain terms.

The word CISO gets thrown around. Here is what one actually owns.

The risk register

A live list of every security risk to your business - ranked by impact and likelihood, with owners and target dates. Without this, security is reactive.

The security roadmap

What you will fix in Q1, Q2, Q3 - and the trade-offs that requires (budget, time, hires).

Policies that match how you work

Not 50-page documents nobody reads. Lean, enforceable, written for your team size.

Board + customer reporting

Translating "we patched 47 CVEs" into language your board and your enterprise customers care about.

Vendor + contract review

Catching the SLA gaps, data residency issues, and breach notification clauses BEFORE you sign.

Compliance ownership

ISO 27001, SOC 2, HIPAA, PCI-DSS, GLBA - picking the right framework and getting you through it.

Incident readiness

Tabletop exercises. A runbook for ransomware, data breach, account takeover. So the day it happens, your team does not panic-Google.

The alternatives

Four ways to get security leadership. Only one of them is us.

An honest comparison, including where the other options genuinely win.

FeatureFull-time CISOIndependent freelancerBig-four advisoryVITI vCISO
Cost per monthA senior salary, plus benefits and hiring costsDay or hourly ratesAdvisory day rates, scoped per projectFrom $2,099 a month
Time to productiveMonths to hireWeeksWeeks30 days
Full attention on your business
A full-time hire wins this outright. Anyone fractional is splitting attention, including us - the question is whether the work needs a full week.
✓∼✕∼
Cover when they are unavailable✕✕✓✓
Named person your auditor can call
Large advisories may rotate staff between engagements.
✓✓∼✓
Owns their own testing tooling
Most providers license a third-party scanner and pass on the cost. We wrote ours, so there is no markup and we can show you the check behind any finding.
✕✕✕✓
Vendor-neutral tool recommendations
We hold no reseller agreements, so nothing we recommend pays us a referral fee.
✓∼✕✓
Can be stopped in 30 days✕✓✕✓

The first 90 days

What actually lands, and when.

Every deliverable below is yours to keep, including if you stop at the end of the minimum term.

  1. Weeks 1-2

    Assessment and a written risk register

    Your vCISO reviews the stack, the policies you already have, your vendor contracts and your access model. You get a ranked risk register with owners and target dates. This is the document most companies have never had, and it is the one that makes every later decision arguable rather than instinctive.

  2. Weeks 3-4

    Quick wins and the customer-facing answer

    MFA and access gaps closed, a security page your sales team can send to prospects, and a first pass at the security questionnaire that keeps stalling your deals. Visible progress in month one, because a programme nobody can see gets defunded.

  3. Month 2

    The roadmap and the framework decision

    Which framework you are actually going for, why, and what it will cost in budget and engineering time. Quarterly milestones with named owners. If the honest answer is that you are not ready to start a certification this year, that is what the roadmap will say.

  4. Month 3

    Policies, drills and board reporting

    Lean, enforceable policies matched to how your team already works. A tabletop exercise against the incident most likely to hit you. And a board-ready summary that translates the technical work into the two or three sentences your directors will actually retain.

Why VITI for vCISO

Why our vCISO retainer beats hiring a single freelancer.

Fractional pricing

A full-time CISO is a senior salary plus benefits. A retainer gives you the strategic work for the hours it actually needs.

Recognized methodology

Our consultants follow the standards your regulators and auditors recognize for incident response and security audits, mapped to ISO 27001 and SOC 2.

Cross-framework experience

ISO 27001, SOC 2, HIPAA and GDPR readiness draw on the same underlying controls. We work across all of them rather than specialising in one, because picking the wrong framework first is the expensive mistake.

A firm, not a single person

A freelancer who goes quiet takes your programme with them. Your risk register, policies and evidence live with us and are handed over intact, and the founder is on every quarterly review, so continuity does not rest on one calendar.

No tool kickbacks

Our vCISO recommends the tool that fits your stack, not the one that pays us a referral fee. We have no commercial partnership with any security vendor.

When not to hire us

Four situations where a vCISO is the wrong purchase.

We would rather lose the deal on the call than six weeks in. If any of these describe you, say so and we will tell you what to do instead.

You need one specific thing done

If the actual need is a penetration test, a gap assessment or a single policy set, buy that. A retainer is for ongoing ownership, and paying monthly for a one-off is the most common way companies waste money on security.

Nobody internally can execute

A vCISO decides what to fix and in what order. Someone still has to do it. If you have no engineering capacity at all, the honest sequence is managed IT first, security leadership second - otherwise you are buying a roadmap nobody will drive.

You already have a security manager

If someone in-house already owns risk and reports to the board, a second voice usually creates friction rather than progress. Targeted advisory hours or a peer review will serve you better than a retainer.

You need an empanelled or accredited signature

We are not a CERT-In empanelled firm and we are not a certification body. If your regulator or contract requires that specific signature, you need the firm that holds it. We will happily prepare the work so their engagement is shorter and cheaper.

How a vCISO engagement starts

From scoping call to embedded leadership in 30 days.

01

30-minute scoping call

We understand your business, current security state, and immediate pressures (audit deadline, customer ask, near-miss incident).

02

Two-week assessment

Your assigned vCISO reviews your stack, policies, contracts, and team. You get a written risk register at the end - yours to keep even if you do not engage further.

03

Engagement begins

Tier chosen based on the assessment. Monthly retainer, three-month minimum, then month-to-month.

04

Continuous + reviewable

30-day exit either side. We would rather you find the right CISO than feel locked in.

vCISO FAQ

How much does a vCISO cost?
Strategic Advisor starts from $2,099 a month; Engaged and Full vCISO are quoted to your scope. The variables that actually move a quote are which framework you are targeting, how far off you are, whether there is a deadline, your regulatory exposure and how many vendors are in scope - not your headcount. Retainers are billed monthly in advance; annual prepay gets 10% off.
Why is your pricing on the website when most firms hide it?
Because the first question every buyer has is the one most security firms refuse to answer until they have you on a call. Publishing the range costs us the deals we were never going to win and saves everyone the two weeks of discovery it takes to find that out. The number you see is the number we quote.
Is a vCISO cheaper than hiring a CISO?
For most companies under about 200 people, yes: a retainer costs a fraction of a full-time senior hire, and you avoid recruiter fees, equity and the months spent searching. The point at which a full-time hire wins is when the work genuinely fills a week, every week. When you reach that point we will tell you, and helping you hire well is a better outcome than keeping a retainer that has outlived its usefulness.
How is a vCISO different from a security consultant?
A consultant delivers a project, hands you a report and leaves. A vCISO owns the programme. When your customer asks who your CISO is, the vCISO is the named answer. When an auditor needs to talk to leadership, the vCISO takes that call. Continuity is the product; expertise alone is available by the hour from anyone.
Do we really need this? We have an IT lead already.
An IT lead manages systems. A CISO manages risk. They are different jobs. If your IT lead is filling out customer security questionnaires, handling vendor due diligence and answering board questions about ransomware exposure, that is the gap. The IT lead keeps running operations; the vCISO owns the security story and the decisions behind it.
How quickly is a vCISO effective?
Weeks one and two produce a written risk register. Weeks three and four close the visible gaps and give your sales team something to send a prospect. Month two produces the roadmap and the framework decision. Month three brings policies, a tabletop exercise and board reporting. The 90-day timeline above is what we work to, and every artefact in it is yours to keep.
Can a vCISO get us through SOC 2 or ISO 27001?
That is the most common reason companies engage a vCISO, and it is the work the retainer is built around: gap assessment, control implementation, evidence collection and audit liaison. We run the readiness programme. The audit itself is performed by an independent firm you retain separately - we are not a certification body and cannot audit work we implemented. Typical readiness runs 4-6 months for ISO 27001 and 9-12 months for a SOC 2 Type 2 observation window, depending entirely on your starting point.
What happens if we get breached during the engagement?
The Engaged and Full tiers include incident response readiness: a runbook, a tested escalation path, and your vCISO on the bridge when something fires. Being honest about the boundary - readiness and coordination are in the retainer; a large forensic investigation is a separate engagement, and for anything requiring a regulator-recognised signature you may need an accredited firm alongside us. See our incident response page for how that works.
What is the minimum commitment?
Three months, then month-to-month with 30 days notice from either side. Three months exists because a shorter engagement cannot produce anything durable - the first month is largely assessment. After that, if it is not working, leaving should be easy, and everything produced is yours.
Do you resell security tools?
No. We hold no reseller agreements and take no referral fees, so a tool recommendation from us carries no commercial interest. Where an engagement needs vulnerability scanning it runs on Vexta, which we built ourselves - which means no third-party licence cost in your fee, and we can show you the exact check behind any finding rather than pointing at a vendor.
Who actually does the work?
A named senior engineer owns your engagement and the founder is on the kickoff call and every quarterly review. You are told who before anything starts, and if that person changes you hear it from us first. We are deliberately small, so the person who scoped the work is the person doing it.
Where are your vCISOs based, and can you work our hours?
India-based, working remotely. We take engagements in the US, UK, UAE, Singapore and Australia and agree the time-zone overlap in writing before we start rather than promising round-the-clock availability we would not hold to. Onsite is straightforward within India and arranged as needed elsewhere.
What do we get to keep if we stop?
Everything. The risk register, policies, roadmap, evidence pack, runbooks and any documentation produced are yours from the day they are written, not on exit. There is no clause that makes leaving expensive and nothing is held hostage in a tool only we can log into.

Next steps

Pick the next step.

Pick whichever fits how far along you are - we will meet you there.

Get a quote

Four fields. A fixed quote within one business day.

No sales call required to get a number. Tell us what triggered this and when you need it by, and we will come back with a fixed price for vCISO.

A fixed quote within one business day. No CRM funnel, no SDR call.

Get a security leader on your team.

30-minute scoping call. We assess whether a vCISO is the right move, recommend a tier, and quote a fixed monthly fee. No commitment to book the call.