
Virtual CISO Pricing: What You Pay For and What You Should Get
Retainer, project or fractional. What each model costs, what it should deliver, and the warning signs that you are buying a document mill.
GuardsArm Team
Security Experts

A virtual CISO exists because the gap between "our IT manager handles security" and "we employ a CISO" is enormous, and most organisations sit in it. A full-time security executive commands a salary that only makes sense above a certain size; below it, you need the judgement without the headcount.
The pricing question is really a question about what you are buying: hours, outcomes, or documents.
The three models
Monthly retainer — a fixed number of days per month. Suits organisations needing continuity: a programme to run, a board to report to, a compliance deadline to steer toward. Most common, and generally the right default.
Project-based — a defined deliverable with a start and end. A risk assessment, a framework implementation, certification readiness. Cheaper and bounded, but leaves nobody accountable afterwards.
Fractional day rate — pay per day as needed. Flexible, and the worst value per hour. Reasonable for occasional expert input, poor for a programme.
What drives the price
| Driver | Effect |
|---|---|
| Days per month | The primary variable — 1-2 days is a common starting point |
| Regulatory environment | Healthcare, financial services and critical infrastructure demand more |
| Programme maturity | Starting from nothing needs more time than maintaining |
| Board and audit obligations | Formal reporting and audit support add a fixed load |
| Incident involvement | Usually outside the retainer — check |
| Team size to manage | Supervising security staff is different from advising |
The most common structure is a monthly retainer for a set number of days, with a clear statement of what falls outside it. Incident response almost always does, which is why a vCISO engagement and an incident response retainer are separate purchases.
Against a full-time hire
A vCISO is not a discounted CISO. It is a different shape of resource.
| Full-time CISO | Virtual CISO | |
|---|---|---|
| Cost | Salary, benefits, equity, recruitment | Retainer only |
| Availability | Every day | Contracted days |
| Breadth of experience | One organisation at a time | Many, across sectors |
| Institutional knowledge | Deep | Builds more slowly |
| Team leadership | Direct | Advisory unless agreed |
| Time to productive | Months to recruit and onboard | Weeks |
The honest trade is availability and institutional depth against cost and breadth. Below roughly a hundred staff, or without a security team to lead, a full-time hire is usually hard to justify. See vCISO versus a full-time CISO.
What you should actually receive
If twelve months of engagement have produced a policy set and nothing else, you bought documents rather than leadership. A real engagement changes what the organisation does, and that shows up as decisions made, risks closed, and someone credible in front of the board.
Warning signs
- Templates with your name substituted in, arriving faster than anyone could have assessed your environment
- No named individual, or a different person each month
- No measurable objectives for the engagement
- Everything is out of scope once you ask for something specific
- The provider also sells the tools they recommend, without disclosing it
Questions to ask before signing
| Question | What a good answer sounds like |
|---|---|
| Who is the named lead, and what have they run? | A person, with comparable organisations named |
| How many days a month, and what happens if we need more? | A number, and a stated overage rate |
| What is explicitly out of scope? | Incident response, hands-on engineering, tool administration |
| What will exist in 90 days that does not today? | Specific artefacts and decisions |
| How do you report to our board? | A format they can show you from another engagement |
| What happens if the lead leaves? | A named continuity arrangement |
The fourth question does most of the work. A provider who answers it with a list of documents is selling documents; one who answers with decisions, risk closures and a governance rhythm is selling leadership.
When a vCISO is the wrong purchase
Be honest about this. A vCISO is not the answer when what you actually need is hands: someone to configure MFA, tune the SIEM, patch the estate. Strategic advice delivered to an organisation with nobody to execute it produces a roadmap and no movement.
If you have no internal capacity at all, pair the advisory engagement with either managed services or a defined implementation budget. See managed security services.
Where to start
Write down the three outcomes you want in the next twelve months — a certification, a board-ready risk picture, a programme that survives an audit. Price against those. A vCISO engagement without defined outcomes drifts into a monthly meeting, which is the most expensive way to buy reassurance.
GuardsArm provides vCISO engagements with named leads and defined outcomes. See virtual CISO services or book a scoping call.
Written by GuardsArm Team
Our team of cybersecurity experts brings decades of combined experience in penetration testing, compliance auditing, and incident response. We're dedicated to helping organizations strengthen their security posture.
Take the next step on this topic
Talk to the GuardsArm team about how these services apply to your environment.


