Back to Blog
Managed Services
4 min read

Virtual CISO Pricing: What You Pay For and What You Should Get

Retainer, project or fractional. What each model costs, what it should deliver, and the warning signs that you are buying a document mill.

GuardsArm Team

Security Experts

September 25, 2026

Virtual CISO pricing models

A virtual CISO exists because the gap between "our IT manager handles security" and "we employ a CISO" is enormous, and most organisations sit in it. A full-time security executive commands a salary that only makes sense above a certain size; below it, you need the judgement without the headcount.

The pricing question is really a question about what you are buying: hours, outcomes, or documents.

Retainer is the default
Continuity is the point; day rates suit one-off input
Incident work sits outside
Almost always a separate retainer
Documents are not leadership
A policy set alone means you bought the wrong thing

The three models

Three ways vCISO work is boughtA monthly retainer suits an ongoing programme. Project pricing suits a bounded deliverable. Day rates suit occasional expert input.Monthly retainerFixed days, continuity, board reporting — the usual fitProject-basedBounded deliverable; nobody accountable afterwardsFractional day rateMost flexible, worst value per hour for a programme
The model should follow whether you need a programme or an answer.

Monthly retainer — a fixed number of days per month. Suits organisations needing continuity: a programme to run, a board to report to, a compliance deadline to steer toward. Most common, and generally the right default.

Project-based — a defined deliverable with a start and end. A risk assessment, a framework implementation, certification readiness. Cheaper and bounded, but leaves nobody accountable afterwards.

Fractional day rate — pay per day as needed. Flexible, and the worst value per hour. Reasonable for occasional expert input, poor for a programme.


What drives the price

DriverEffect
Days per monthThe primary variable — 1-2 days is a common starting point
Regulatory environmentHealthcare, financial services and critical infrastructure demand more
Programme maturityStarting from nothing needs more time than maintaining
Board and audit obligationsFormal reporting and audit support add a fixed load
Incident involvementUsually outside the retainer — check
Team size to manageSupervising security staff is different from advising

The most common structure is a monthly retainer for a set number of days, with a clear statement of what falls outside it. Incident response almost always does, which is why a vCISO engagement and an incident response retainer are separate purchases.


Against a full-time hire

A vCISO is not a discounted CISO. It is a different shape of resource.

Full-time CISOVirtual CISO
CostSalary, benefits, equity, recruitmentRetainer only
AvailabilityEvery dayContracted days
Breadth of experienceOne organisation at a timeMany, across sectors
Institutional knowledgeDeepBuilds more slowly
Team leadershipDirectAdvisory unless agreed
Time to productiveMonths to recruit and onboardWeeks

The honest trade is availability and institutional depth against cost and breadth. Below roughly a hundred staff, or without a security team to lead, a full-time hire is usually hard to justify. See vCISO versus a full-time CISO.


What you should actually receive

What a vCISO engagement should produceWhat a vCISO engagement should produce1Risk pictureFirst 90 daysA current, prioritised view of risk the executive actually recognises.2A roadmap with costsQuarter 1Sequenced, budgeted, and tied to business drivers rather than a framework index.3Governance that runsOngoingBoard and management reporting that happens on a cadence without chasing.4Decisions and closuresOngoingRisks actually retired, vendors actually assessed, controls actually live.5Audit and customer supportAs neededSomeone credible answering security questionnaires and auditors.
Judge the engagement on the last two rows, not the first.

If twelve months of engagement have produced a policy set and nothing else, you bought documents rather than leadership. A real engagement changes what the organisation does, and that shows up as decisions made, risks closed, and someone credible in front of the board.


Warning signs

  • Templates with your name substituted in, arriving faster than anyone could have assessed your environment
  • No named individual, or a different person each month
  • No measurable objectives for the engagement
  • Everything is out of scope once you ask for something specific
  • The provider also sells the tools they recommend, without disclosing it

Questions to ask before signing

QuestionWhat a good answer sounds like
Who is the named lead, and what have they run?A person, with comparable organisations named
How many days a month, and what happens if we need more?A number, and a stated overage rate
What is explicitly out of scope?Incident response, hands-on engineering, tool administration
What will exist in 90 days that does not today?Specific artefacts and decisions
How do you report to our board?A format they can show you from another engagement
What happens if the lead leaves?A named continuity arrangement

The fourth question does most of the work. A provider who answers it with a list of documents is selling documents; one who answers with decisions, risk closures and a governance rhythm is selling leadership.


When a vCISO is the wrong purchase

Be honest about this. A vCISO is not the answer when what you actually need is hands: someone to configure MFA, tune the SIEM, patch the estate. Strategic advice delivered to an organisation with nobody to execute it produces a roadmap and no movement.

If you have no internal capacity at all, pair the advisory engagement with either managed services or a defined implementation budget. See managed security services.


Where to start

Write down the three outcomes you want in the next twelve months — a certification, a board-ready risk picture, a programme that survives an audit. Price against those. A vCISO engagement without defined outcomes drifts into a monthly meeting, which is the most expensive way to buy reassurance.

GuardsArm provides vCISO engagements with named leads and defined outcomes. See virtual CISO services or book a scoping call.

Written by GuardsArm Team

Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.

Take the next step on this topic

Talk to the GuardsArm team about how these services apply to your environment.