Fractional CISO vs. vCISO vs. Full-Time CISO
What each option actually means, what it costs in commitment and accountability, and how growing and regulated companies choose between them.
The business problem
These three terms get used interchangeably in conversation, in job postings, and in vendor pitches — and that looseness costs companies real money and real risk. An organization that budgets for a "vCISO" without asking what that specific provider actually delivers can end up with a few advisory hours a month when what the business needed was a leader accountable for risk decisions and board communication. One that defaults straight to a full-time executive search can spend six figures and six months on a role a part-time relationship would have filled adequately for less than half the cost and in a fraction of the time.
What each term actually means
Three real, distinct arrangements hide behind these labels, and the differences matter more than the names suggest.
- Full-time CISO — a permanent executive hire, fully dedicated to one organization. The right call when cybersecurity has become a large, complex, full-time function on its own — but it carries the cost, timeline, and commitment risk of any executive search.
- vCISO (virtual CISO) — a broad, largely unregulated term covering everything from a single consultant offering a few advisory hours a month to a full leadership relationship. The quality and depth vary enormously between providers, and the label alone tells you almost nothing about which end of that range you are buying.
- Fractional CISO — a senior CISO engaged part-time but with real, ongoing accountability for security strategy, risk decisions, and board communication, not just advisory hours on a timesheet. This is the model My CISO Partner operates on.
“The question that actually separates these options is not how many hours a week someone works. It is whether a specific person is accountable for your next risk decision, or whether you are buying hours with no one clearly on the hook for the outcome.”
Why it matters
Getting this choice wrong shows up in two different ways. Overbuying (a full-time hire before the function justifies it) means paying executive-level compensation for a role that spends real time under-utilized. Underbuying (a vague "vCISO" engagement with no defined accountability) means the organization believes it has executive security ownership when, in practice, no one is actually on the hook for the next risk decision — a gap that usually only surfaces during an audit, an incident, or a board question nobody can answer.
Signs the organization should pay attention now
- The organization describes itself as having a "vCISO" but cannot say specifically what that person is accountable for, versus simply available for
- Security decisions get made by committee or by whoever is available, with no single named owner
- A full-time executive search is underway mainly because no one considered a fractional or interim alternative, not because the workload was actually sized
- The current advisory relationship has no defined scope of accountability — just a retainer for hours
- Board members or investors have started asking directly who owns cybersecurity, and the honest answer is unclear
Want to see what the Fractional CISO model actually includes?
Explore Fractional CISOWhat good looks like
Whichever model an organization chooses, a defensible arrangement has the same two characteristics: a specific named individual accountable for security strategy and risk decisions — not a pool of hours — and a defined scope covering strategy, risk decisions, and board communication, not just technical advisory. A full-time hire, a fractional engagement, and a well-run vCISO relationship can all clear that bar; a vague "vCISO" retainer with no defined accountability cannot.
Practical guidance
Before committing to any of the three, ask any provider under consideration exactly what they are accountable for versus simply available for, whether one named individual owns strategy and risk decisions or the work is spread across a rotating team, and how the relationship handles board or investor reporting. If those questions produce a vague answer, that vagueness — not the hourly rate — is the real cost of the arrangement.
My CISO Partner's perspective
We built the Fractional CISO model specifically to close the gap between "a few advisory hours" and "a full-time executive salary" — real, ongoing accountability for strategy, risk, and board communication, sized to what a growing or regulated company actually needs before it needs a full-time hire.
Where to go from here
If you are choosing between these three options and cannot yet say who would be specifically accountable for your next security decision, that is the question worth resolving first — before the budget or headcount conversation.
Questions, answered directly.
Yes — many engagements scale up in scope as the organization grows, and some transition into a permanent hire when it makes sense.
The relationship carries defined accountability and scope for as long as it runs — commitment is structural, not a function of hours worked.
"vCISO" describes a very wide range of arrangements, from a few advisory hours a month to a full leadership relationship. Fractional CISO, as My CISO Partner runs it, means ongoing accountability for strategy, risk decisions, and board communication — it is worth asking any vCISO provider directly which end of that range they actually deliver.
There is no fixed headcount cutoff. The decision turns on whether cybersecurity has become a full-time, dedicated function in its own right, or whether experienced executive leadership at a part-time scope still fits where the organization is today.
Talk to a CISO about which model fits.
30 minutes. No obligation. No sales pitch.