What a CISO does
A CISO sets the security strategy, decides how risks are treated, owns the policies, reports to management and coordinates the response when something goes wrong. Regulations like NIS2 make management accountable for cybersecurity, which raises the need for someone who can advise them.
How a vCISO works
A vCISO covers the same responsibilities with a defined dedication, for example a set number of days per month. Typical work includes running the risk assessment, leading ISO 27001 or ENS projects, preparing for audits, answering customer security questionnaires and reporting to management on progress and risk.
When it makes sense
Small and mid sized companies often reach a point where customers, tenders or regulations demand a security programme, but a full time CISO is not justified. A vCISO also helps when a certification project has stalled for lack of an owner, a common situation covered in how to restart a stalled ISO 27001 project.
What to check
Relevant experience in your sector and frameworks, how much time is committed, who carries out the technical work, and how the vCISO reports to management. A vCISO advises and leads, while the company remains accountable for its security decisions.




