vCISO Cost: Full Time CISO, Agency, or One Person

Most people who ask me what a vCISO costs are really choosing between three things. Hire a chief information security officer full time, sign with an agency or managed provider, or work with one practitioner. The prices are not close, and neither is what you get.

I will give you real numbers where I have them and tell you plainly where I could not find a number worth trusting. That second part turned out to be the more useful half of this post.

What a vCISO Actually Is

The v stands for virtual. Most of the time virtual also means fractional, so you are buying part of a person’s month instead of all of it, though that is not always true.

Here is the part nobody mentions when you start collecting quotes. vCISOs are not interchangeable. Some are almost entirely consulting. Others live in policy and documentation. A few are deeply technical. Plenty do very little except vulnerability work. Two quotes at the same dollar figure can buy completely different work, so find out what kind of vCISO you are talking to before you compare anything else.

My own month right now is compliance consulting, mostly CMMC Level 2. The first month of an engagement is the heaviest. I send questionnaires and read everything you already have. The second month I build what is missing, including your plan of action and milestones. By the third month you have every tool you need from me, and pushing the changes becomes your job. Through all of it we meet weekly or every other week, and you can email, call, or text me in between.

Option One: Hire a CISO Full Time

Federal wage data does not track chief information security officer as its own job. The closest category the Bureau of Labor Statistics publishes is computer and information systems managers, code SOC 11-3021, at a median annual wage of $171,200 as of May 2024. That category also holds IT directors and infrastructure managers, so treat it as a floor rather than a CISO salary.

At the size of company I work with, a real CISO salary runs $250,000 to $350,000. That is what I have seen, and it moves with geography. The same job pays very differently in Arkansas than in New York.

Then add everything the salary line does not show you. Benefits and payroll taxes. The cost of marketing the position and sitting through interviews. A recruiter fee if you use one, which is normally a percentage of first year pay. Whatever you budgeted, year one costs more than the offer letter.

One more thing that has nothing to do with money. One person is one person. They take vacation, they get sick, and eventually they leave. If your business generates security work every single day, though, a full time hire is still the right answer and I will say so.

Option Two: An Agency or Managed Provider

The name is real, the reputation is real, and the staff is real. That is worth something and I am not going to pretend otherwise.

The question is who you actually get. I have seen proposals full of senior titles turn into an account run day to day by a junior specialist. I have met clients who had been with a provider for five years and could not name the director of security on their account. They met him once, at the beginning.

The other thing to watch is scope. A common setup is one agreement covering vulnerability management and a separate agreement covering patching, sold as though the pair covers everything. It does not. I have watched findings that were handled one quarter fall into the gap the next quarter, with the client finding out when the scan report was already in front of them. Spoofing findings on a local network are a favorite thing to quietly drop, because they are only exploitable from the inside. Your cyber insurance carrier does not grade on that curve.

That is the mistake I see most often. Businesses buy the title instead of the work. Comparing on price is fine and I have no problem with it. Comparing on letterhead is where people get hurt.

Where an Agency Genuinely Wins

Scale. If you have 10,000 employees, one person cannot do your risk assessment without taking hours away from everybody else on the calendar. An agency has bench depth, a help desk, and enough people to absorb a large environment. That is a real advantage and it is exactly why I turn that work down.

What Happens When One Person Is Unreachable

Fair question, so here is exactly how I run it. If I am going on vacation, you get notified the same week I know. Right now, at my size, vacation is not a true blackout. Responses might be delayed by cell service and connection, but once I have a moment to sit down, you will hear from me, and you will have a number to call if something urgent comes up. I cannot promise I will always answer, and yes, that is the honest downside of one practitioner. A full time hire has the same downside with one difference. Legally, on vacation, they do not have to answer you. I do not either, but my name is the business, so I will. If I am out sick or something sudden comes up, you get an email, and if we are mid project and it is during work hours, a call or text instead, because projects are time sensitive.

If something breaks while I am truly unreachable, the play is the same one I would give you on the phone. Isolate the incident, and if it is bad enough, get your cyber insurance carrier involved immediately. If it is small, like a single compromised user, lock the account and resolve it. And past my client cap, the people I bring in have carried the same role I do with their own clients, so an active engagement does not stall because I am down for a week.

Option Three: One Practitioner

My vCISO tiers run $60,000 to $180,000 a year. Treat that as an estimate rather than a price list, because the quote depends on your size, your framework, and how much of me you actually need.

  • Tier 1: annual NIST CSF 2.0 risk assessment, 10 hours a month of ad hoc support, vulnerability report support, basic compliance consulting, meetings every other week.
  • Tier 2: everything above, 20 hours a month, detailed compliance consulting, policy and procedure development, weekly meetings.
  • Tier 3: everything above, 30 hours a month, vendor risk assessments, and a compliance based risk assessment under whichever framework applies to you.

Those monthly hours are for work that is not already included. Your annual risk assessment does not eat into them. If you want something outside your tier you can spend hours on it, and I will tell you when that is a bad idea. Vendor risk assessments are the usual example. You can chip at one with monthly hours and receive a piece at a time, or buy it as a project and get the whole thing.

Everything is month to month with 30 days notice to cancel. A one year or three year agreement is available at a discount if you want one, but I am not going to make you sign anything to get started.

I can personally carry about 15 clients and I have carried that load before. Past that I bring in help, and it will be people I already know who have done this job, not a junior analyst who was handed your account that morning.

Why a Real Risk Assessment Is Its Own Line Item

A proper risk assessment takes 20 to 40 hours, which is why it sits outside your monthly hours instead of inside them. Anyone who hands you a finished assessment right away is not reassessing anything. They copied last year’s, took your previous vendor’s, or fed the framework to an AI tool.

Reassessing means starting over. If last year’s assessment says your firewall rules are in good shape and you have since replaced the firewall, that finding is worth nothing. The rules changed. A real assessment goes and looks.

What About Just Using AI

People ask, and it is a fair question when you are watching a budget. You can hand an AI an entire framework and it will know how to walk you through it. What it cannot do is tell whether the answers it is getting back are accurate.

I am not trying to catch anyone lying. I am trying to make sure the result is true. AI still misreads scope, and access control is where I see it most. It asks something broad about requiring multi factor authentication and locking down users, you say yes, and it treats that as the whole control family handled. What it needed to know was whether you onboard and offboard properly, whether MFA is enforced by policy instead of habit, whether you run background checks, and whether you are genuinely doing authentication, authorization, and accounting.

Two Numbers I Will Not Use

You have probably seen the claim that 60 percent of small businesses close within six months of a cyberattack. The National Cyber Security Alliance, the organization that number is almost always credited to, published a statement in May 2022 saying it did not produce the statistic, cannot verify where it came from, removed it from its own materials, and does not recommend anyone keep using it. It traces to an unsourced claim from 2011. So I am not using it.

You have probably also seen $120,000 given as the average breach cost for a small business. That traces to a 2018 vendor survey that measured recovery spending rather than total breach cost, and that counted companies with up to 999 employees as small or medium. The same vendor’s figure fell in the years after. It is not a number I can defend.

Here is what I can point at. The 2025 NetDiligence Cyber Claims Study analyzed 10,402 real cyber insurance claims from incidents between 2020 and 2024. Across that data the average total incident cost at a small or medium enterprise was about $264,000, with average insurer payouts near $183,000. Read the label carefully though. That study counts any company under $2 billion in revenue as small or medium, which is far larger than the businesses I serve. It is real claims data instead of a survey, and it is the honest top of the range rather than a number for a company your size.

The line I have repeated my whole career still holds. The cost of a breach will exceed what you are paying me. I just do not need an invented number to say it.

Who Should Not Hire Me

I aim at companies with 200 employees or fewer that do not already have a security officer on staff. If you have 10,000 employees I am going to decline, and it is not personal. The hours your environment would take would come out of everyone else’s engagement, and that is not a trade I am willing to make. What I will do instead is sit with you as a project, work out what you actually need, and help you interview providers until you find one that will really do it.

The same honesty applies before you ever sign. If you need someone 24 hours a day, every day of the year, I am not going to trick you into an agreement with me. This is for people who know they need someone every once in a while, projects here and there, and advice when they need it. If you need someone 40 hours a week, hire someone, and I will say so in the first call.

The other case is quieter. If you are paying for a tier and barely using it, I will tell you to move down to the security advisory retainer, which is really just someone to call, text, or email with a quick question, plus enough on paper to answer a cyber insurance question about having an advisor available. I am not a movie subscription. If you are not using it, do not keep paying for it.

Key Takeaway

You are not buying a person on the org chart. You are buying peace of mind, a consultant who cares, and somebody you can call when something in your environment does not look right.

Want a real number for your situation? Email CISO@thecyberfriend.com with your employee count and the framework you are chasing, or see where you stand first.

Take the Free Assessment