When startups actually need a vCISO, based on trigger events rather than headcount

TL;DR

  • Headcount is a lagging indicator. Companies hire a vCISO because of a stuck deal, a questionnaire deadline, or an investor question, not a milestone.
  • Deal volume scales fast. Series A to B companies field two to five questionnaires a month, and Series C to D companies can hit twenty to thirty.
  • A vCISO typically runs $60K to $180K a year versus $350K to $600K or more for a full-time CISO, and starts in days or weeks instead of months.
  • A well-scoped vCISO owns the program day to day. It's a lot more than a monthly check-in call.
  • You outgrow a vCISO once you hit the size where you need an internal security team, which can look more like a transition in scope of work than the end of an engagement.

A lot of guidance on when to hire a vCISO starts with company size or funding stage. Cross somewhere around 80 to 100 employees, the advice goes, and it's time to think about security leadership. It isn't wrong, exactly, just not the first thing worth watching.

In practice, companies rarely sign on because they hit a headcount milestone. They sign on because hundreds of thousands of dollars are stuck on an enterprise deal, a near miss security incident occurred, or an investor asked a question nobody in the room could answer.

Company size is a lagging indicator. The thing that actually triggers a vCISO conversation happens somewhere else entirely.

What triggers the conversation

Headcount correlates with security need, loosely, the way age correlates with experience. It's not nothing, but it's not the mechanism. In practice, the moment a company actually picks up the phone tends to be one of a handful of things:

  • An enterprise deal enters diligence and legal sends over a security questionnaire nobody on the team can answer with a straight face
  • An investor, during a raise, asks what the company's security posture actually looks like
  • A customer requires SOC 2 or ISO 27001 as a condition of the contract, and the deadline is suddenly real
  • Something breaks, or almost breaks, and the founder realizes nobody actually owns the response plan
  • The team quietly adopted a pile of SaaS tools and nobody can say with confidence what data lives where anymore

None of those are headcount events. A 15-person company mid-Series-B-diligence needs this conversation more urgently than a 100-person company with no enterprise deals, audits, or investor pressure on the calendar.

That pattern holds up in practice, and it's rarely one dramatic event. More often it's cumulative. A company keeps hitting the same question on vendor questionnaire after vendor questionnaire: do you have a SOC 2, do you have ISO 27001. Enough rounds of answering no is usually what pushes the decision, because at some point you just want to answer yes.

Some engagements start from investor due diligence questionnaires specifically, which run on a similar track to vendor security questionnaires but get less attention as a trigger.

Deal volume also scales the pressure predictably: a Series A–B company typically fields two to five vendor security questionnaires a month; a Series C–D company can see twenty to thirty, close to one every business day.

At that volume, not having a real answer bank, tooling, or a clear owner stops being an occasional annoyance and starts being an operational tax that shows up on every deal.

What a vCISO costs vs. a full-time CISO

The dollar gap is the other reason the headcount framing doesn't hold up. It implies a threshold where suddenly you can "afford" a CISO. In practice, most companies never need to cross that line at all.

Fractional / vCISOFull-time CISO
Typical annual cost Roughly $60,000 to $180,000, depending on scope and compliance complexity, with deep interim engagements running higher Roughly $350,000 to $600,000 or more, including salary, benefits, and equity
Time to start Often days or weeks for a fractional engagement Executive searches for a senior CISO commonly run several months, if you can even find the right fit in the first place.
Best fit Companies that need senior judgment without daily, in-house ownership Companies with a security workload big enough to need a team and someone to manage them day to day.

That comparison isn't perfectly apples-to-apples. One is a contracted scope of work. The other is a full-time employee with the broader responsibilities that come with headcount, board relationships, and long-term institutional ownership.

But for most early- and growth-stage companies, the cost gap is still wide enough that hiring full-time before the workload justifies it means paying six figures a year to solve a problem a fraction of that budget already handles.

What a solid first week looks like

A vague "we'll do an assessment" answer is a signal to keep shopping. By the end of the first week, you should know what the engagement is producing, what gets assessed first, and what decisions are coming next.

For most companies that means a real picture of where sensitive data actually lives, an early read on gaps against whatever standard matters to you (SOC 2, ISO 27001, HIPAA, FedRAMP, and CMMC are genuinely different things, but they all start from this same picture), and a straight answer on what's urgent versus what can wait.

A more complex company might spend the first week just nailing down scope, stakeholders, and evidence access, and that's a legitimate use of the time too. If a firm can't tell you what you'll have in hand after week one, that's worth asking about directly before signing anything.

The hours-per-month conversation should work the same way. It should scale to what's actually driving the engagement: an active audit needs more hours than steady-state maintenance, not a fixed package regardless of your situation. If the scope doesn't change when your circumstances do, that's a fair thing to push back on.

The biggest myth about what a vCISO does

The myth is that a vCISO is basically an advisor who shows up once a month, nods at a slide deck, and leaves. That model exists, and it's usually a bad deal.

"vCISO" isn't a standardized engagement, though, so the myth cuts both ways. Some engagements really are that thin. A well-scoped vCISO engagement looks more like a part-time executive than an outside consultant:

  • They own the security roadmap and advise on key hard decisions
  • They can coordinate evidence and work directly with your auditor during a SOC 2 or ISO 27001 examination
  • They write the underlying policies themselves and keep them matched to what's actually running in the environment, so when a customer's security questionnaire lands, most of it is already answered instead of starting from a blank page
  • They're the one who gets looped in when a customer's security team pushes back on a questionnaire answer
  • They're reachable when something actually goes wrong

That's the kind of engagement worth paying for, though it's not automatically what every vCISO firm delivers. Worth asking about directly rather than assuming.

The title is fractional. The accountability, in a well-scoped engagement, generally isn't.

How do you know when you've outgrown it?

The switch to full-time often makes sense once the workload needs a dedicated internal security team, and when clients reach that point, we help them hire for it. That means managing a team, sitting in daily standups, and meeting with the executive team on a regular basis.

Those are not the only legitimate reason to hire full-time, though. Internal political authority, a formal seat at the leadership table, direct board relationships, and deep institutional knowledge built up over years are all real reasons a company might want a full-time CISO before the day-to-day workload strictly requires one.

The claim that holds up is narrower than "you don't need a CISO until the workload is overwhelming." You don't need a full-time CISO simply because you crossed some employee count.

The workload argument is one path to that conclusion, but it isn't the only one. A vCISO worth keeping should still be willing to tell you honestly when you've crossed whichever line applies to your situation, even though it means their own engagement ends.

The number that matters

Security leadership becomes worth paying for when the absence of ownership starts blocking revenue, compliance, fundraising, or risk decisions, not when the org chart crosses some round number. That can happen at 10 employees or 250.

What shouldn't be on the list of reasons to make the call is simply hitting 50, 80, or 100 employees with nothing else going on. The calendar, the contracts, and the actual risk will tell you more than the headcount ever will.

FAQ: hiring a vCISO

At what company size should we hire a CISO?

Headcount is a weak predictor on its own. A 15-person startup mid-diligence for a Series B often needs security leadership more urgently than a 100-person company with no active deals, audits, or enterprise customers pushing on it. Watch what's happening around the business, not the org chart.

What's the difference between a vCISO and a CISO?

The responsibilities are largely the same: strategy, risk management, compliance oversight, board and customer communication. The difference is employment structure and time. A CISO is a full-time employee dedicated to one company. A vCISO is a senior security leader who works with your company on a retainer, typically a set number of hours per month, and often serves a small number of clients at once.

How much does a vCISO cost compared to a full-time CISO?

Fractional CISO retainers commonly fall around $5,000 to $15,000 a month, roughly $60,000 to $180,000 a year, though deep interim engagements can run higher. A full-time CISO's total annual cost, including salary, benefits, and equity, typically lands between $350,000 and $600,000 or more. The comparison isn't perfectly apples-to-apples, one is a contracted scope, the other a full-time employee, but for most early-stage companies the gap is still wide.

How do I know if we're ready for a full-time CISO instead of a vCISO?

It usually comes down to volume and complexity, not a single headcount number. If your security workload has grown into something that genuinely needs someone in the room every day, managing a team, sitting in daily standups, and making real-time calls, that's a different job than a retained advisor can do well. A good vCISO engagement should be able to tell you honestly when you've outgrown it.

What does a vCISO do day to day?

Not just show up for a monthly call and hear your problems. A working vCISO engagement typically includes building and maintaining your security program, and depending on scope, owning compliance documentation, responding to customer security questionnaires, preparing for audits, and being the person who actually answers when a deal stalls over a security concern.

Not sure if you need a vCISO yet, or if you're already past the point of needing one?

We'll tell you honestly, including if the answer is "not yet." Let's talk through what's actually happening at your company, not what a generic headcount chart says.

Book a call with Amomitto →