You've decided your organization needs a virtual CISO. You know the decision makes sense: you carry regulatory weight, your board is asking questions about cyber risk, and a full-time security executive is either unaffordable or more capacity than you need. Now comes the hard part — choosing the right person.
This isn't like hiring a consultant to tune your firewall or run a penetration test. A vCISO becomes your senior security leader. They shape your compliance program, advise your executive team, speak to your board, and make judgment calls that affect your risk posture and your ability to win business. Get this decision wrong and you'll spend months discovering that your "strategic advisor" is really just checking boxes, or that their expertise doesn't match your regulatory reality, or that they're too thinly stretched across too many clients to actually lead.
I've worked with organizations that hired the wrong vCISO before they hired me. The patterns are consistent. This article walks through what to look for, what questions expose the gaps, and what real fit looks like when you're evaluating candidates to serve as your fractional security leader.
Start with Regulatory Fit, Not General Security Experience
The first mistake buyers make is treating vCISO selection like hiring a general cybersecurity expert. They look at certifications, years of experience, and a broad portfolio of past clients. All of that matters, but none of it tells you whether the candidate understands your regulatory obligations.
A vCISO who spent a decade in financial services may be exceptionally skilled, but if you're a defense contractor facing CMMC certification or a healthcare provider managing HIPAA risk, that experience doesn't transfer cleanly. The frameworks are different, the audit expectations are different, and the consequences of getting it wrong are different.
Ask specific questions about the candidate's work in your industry. Not "Have you worked with regulated clients?" but "How many CMMC assessments have you led from scoping through certification?" or "What was the last HIPAA corrective action plan you built, and what did OCR actually accept?" If the candidate can't give you concrete answers with details, they're not bringing the regulatory depth you need.
In my own practice, I work almost exclusively with healthcare organizations, defense contractors, and federal vendors. That's not because I can't work in other sectors — it's because regulatory expertise is specific, and depth matters more than breadth. When a client asks me about CMMC readiness, I'm not Googling the framework. I've done the assessments. I know where organizations fail and why.
Certifications Are Helpful, But Experience Is What Matters
Most vCISO candidates will have certifications: CISSP, CISM, maybe a CISA or a certified CMMC professional credential. Those are useful signals that someone has studied the material and passed an exam. They are not proof that the person can actually run your compliance program or advise your CEO on risk trade-offs.
Look for evidence of applied work. How many compliance assessments has the candidate led? How many times have they built a security program from scratch for an organization like yours? How many board presentations have they delivered, and what were the outcomes?
Certifications tell you someone learned the theory. Experience tells you they can execute under pressure.
Evaluate Capacity and Attention, Not Just Availability
One of the most common failures I see in vCISO engagements is overcommitment. The candidate says yes to the engagement, quotes a reasonable monthly retainer, and then you discover three months in that they're stretched across twelve other clients and can't actually give you the time or attention your situation demands.
This is a structural problem in the fractional services model. A vCISO who charges $5,000 a month can't survive on one client. They need multiple engagements to make the economics work. The question is whether they've structured their practice to handle the load, or whether they're just saying yes to everything and hoping it works out.
Ask directly: How many active clients do you currently serve? How many hours per month are you committing to this engagement, and is that enough to do the work we've scoped? What happens if we have an incident or an unexpected audit — can you respond, or will we be waiting in line?
The right answer isn't "I only work with one client at a time." That's usually not realistic or even desirable — some of the best vCISOs I know serve a small portfolio of clients and bring cross-industry perspective from that work. The right answer is honest about capacity, clear about boundaries, and specific about how the vCISO structures their time to ensure responsiveness.
I typically work with three to five clients at a time, depending on the intensity of each engagement. That's enough to stay sharp and bring diverse experience, but not so many that I'm unavailable when a client needs a decision or a board presentation on short notice. If a candidate can't give you a straight answer about their current load, assume they're overcommitted.
Beware the Subcontractor Model
Some vCISO providers operate as firms rather than individuals. You think you're hiring a senior security leader, and what you get is a project manager who farms out the actual work to junior consultants or subcontractors. This model can work if it's disclosed and structured well, but more often it's a bait-and-switch.
Ask: Will you personally be doing this work, or will it be delegated? If I call you with an urgent question, am I reaching you or a junior team member? Who will be presenting to my board?
If the answer involves "my team" or "our associates," push for specifics about who those people are, what their qualifications look like, and how much direct access you'll have to the senior person you're evaluating.
Need a vCISO Who Shows Up When It Matters?
Fractional security leadership works when the engagement is structured for real accountability and the vCISO has the capacity to deliver. Learn about Carl's vCISO services.
Talk to Carl About vCISO Services
Test for Strategic Judgment, Not Just Technical Knowledge
A vCISO is not a senior security engineer. The role is about leadership and judgment: understanding your business context, advising on risk trade-offs, building programs that match your maturity and budget, and communicating security in terms your executive team and board can act on.
Many candidates who present themselves as vCISOs are actually very strong technical practitioners who haven't made the shift to strategic leadership. They can configure a SIEM, design a network architecture, or write an incident response playbook. That's valuable work, but it's not the work of a CISO.
During your evaluation, ask scenario-based questions that require judgment rather than technical recall. For example: "We're a healthcare provider considering adopting an AI scribe tool. What's your process for evaluating the risk and making a go/no-go recommendation?" or "Our board is asking whether we should get cyber insurance. How do you advise us?"
The wrong answer focuses entirely on controls and checklists. The right answer starts with questions about your business model, your risk appetite, your regulatory obligations, and what you're trying to protect. A strong vCISO doesn't give you the same answer they'd give every other client — they tailor their advice to your situation.
I've worked with organizations where the previous vCISO delivered a 40-page security policy template and called it strategy. Policies matter, but they're outputs of a program, not substitutes for one. If a candidate can't articulate how they'd approach building your compliance program from the top down, they're not ready to serve as your security leader.
Ask About Communication and Influence
A large part of the vCISO role is communication: translating technical risk into business language, getting buy-in from executives who don't have security backgrounds, and delivering board reporting that's useful rather than overwhelming. Technical depth means nothing if the vCISO can't influence decisions.
Ask: How do you typically present risk to a board? What's an example of a time you had to convince a leadership team to fund a security initiative they didn't think was necessary? How do you handle situations where business priorities and security priorities conflict?
The answers should demonstrate empathy for the business side, respect for competing priorities, and an ability to make the case for security without fearmongering or jargon. If a candidate talks about "educating" the board or "making executives understand," that's a red flag. Your executives aren't stupid — they're busy and they're optimizing for different variables. A good vCISO knows how to work within that reality.
Look for Evidence of Real Program-Building, Not Just Assessments
Many vCISO candidates come from audit or assessment backgrounds. They've spent years evaluating other people's security programs, writing findings, and issuing recommendations. That experience is valuable, but it's not the same as building and running a program yourself.
Ask: Have you ever built a compliance program from scratch? What was the organization, what was the regulatory requirement, and how long did it take to get them audit-ready? What parts of the program required the most work, and where did you run into resistance?
The difference between someone who has done this work and someone who has only assessed it is immediately obvious in the specificity of the answer. A true program-builder will tell you about trade-offs, about scrappy solutions that worked in resource-constrained environments, about the politics of getting buy-in from department heads who didn't want to change their workflows.
An assessor will tell you what the framework says and what findings they typically see. That's not useless, but it's not leadership.
In my own work, I've led more than 200 compliance assessments across healthcare, defense, and federal contracting. But the assessments are context for the program-building — they show me what fails under pressure and what actually holds up when auditors dig in. That's the perspective a vCISO should bring: not just "here's what the standard requires," but "here's what actually works."
Understand How the Engagement Will Be Structured
Not all vCISO engagements are structured the same way, and the structure matters as much as the person. Some vCISOs work on monthly retainers with a fixed scope of hours. Others work project-based. Some include incident response in their retainer; others charge separately for after-hours work.
Before you sign anything, get clarity on what's included and what's not. What happens if you have a breach or a regulatory inquiry — is the vCISO available, or is that out of scope? If you need to prep for an audit, is that covered under the retainer or billed separately? How are board presentations, policy development, and vendor assessments handled?
Ask to see a sample engagement agreement or statement of work. The document should be specific about deliverables, response times, and how the relationship scales if your needs change. Vague language like "strategic security advisory services" is a warning sign. You should know exactly what you're paying for.
I structure my engagements with a monthly retainer that includes a defined number of hours for program leadership, board reporting, policy work, and day-to-day consultation. Incident response and audit prep are included up to a reasonable threshold, with clear terms for how additional work is scoped and billed. Clients know what they're getting, and I know I'm not overcommitting.
Clarify the Termination Terms
This is uncomfortable to discuss upfront, but it's critical. What happens if the engagement isn't working? Are you locked into a year-long contract, or can you terminate with 30 or 60 days' notice?
A vCISO who resists reasonable termination terms is either inexperienced or worried that clients will leave once they see the work quality. A confident vCISO knows that if they're delivering value, clients will stay.
I include 60-day termination clauses in my agreements. It's long enough to avoid chaos if a client suddenly exits, but short enough that nobody feels trapped. If I'm not delivering, I don't want to force a client to stay. And if a client isn't a good fit, I'd rather know early and part professionally.
Structure Matters as Much as Expertise
The best vCISO engagements are clear about scope, deliverables, and how success is measured from day one. That clarity protects both sides and ensures the relationship delivers what you actually need.
See How a vCISO Engagement WorksRed Flags That Should Make You Walk Away
Some warning signs are subtle. Others should end the conversation immediately. Here are the red flags I'd watch for if I were hiring a vCISO for my own organization:
- No regulatory specialization. If the candidate's experience is all over the map — a little healthcare, some retail, a manufacturing client, maybe some finance work — they're a generalist. Generalists can't give you the depth you need in a regulated environment.
- Overpromising on timeline. If a candidate says they can get you CMMC-certified in 60 days or HIPAA-compliant in a month, they either don't understand the work or they're lying. Real compliance programs take time to build, and anyone who says otherwise is setting you up for failure.
- Selling tools or vendor relationships. Some vCISOs get kickbacks from security vendors or operate as resellers. This creates a conflict of interest. Your vCISO should recommend tools based on your needs, not based on who's paying them a commission.
- No references or case studies. Any vCISO worth hiring should be able to provide references from past or current clients, or at least case studies that demonstrate their work. If they can't or won't, assume there's a reason.
- Resistance to direct access. If the candidate hedges when you ask about response times or direct availability, or if they keep talking about "the team" instead of their own involvement, they're planning to delegate the work and hope you don't notice.
I've seen organizations hire vCISOs who checked all these boxes and then spent six months undoing the damage. The cost isn't just the retainer you paid — it's the lost time, the compliance deadlines you missed, and the credibility hit when your board realizes you hired someone who couldn't deliver.
What Good Looks Like in the First 90 Days
One way to evaluate a vCISO candidate is to ask them what they'd do in the first 90 days of the engagement. The answer will tell you a lot about their process and their priorities.
A weak answer focuses on deliverables: "I'll write your policies, update your risk assessment, and get you compliant." That's task-oriented thinking, not leadership.
A strong answer focuses on discovery and alignment: "I'll spend the first few weeks understanding your business model, your regulatory obligations, and your current risk posture. I'll interview your leadership team to understand where security friction is happening and where you need the most help. I'll review your existing documentation and controls, identify gaps, and prioritize what needs to happen first based on your audit timeline and risk tolerance. Then I'll build a roadmap and present it to you and your executive team for buy-in before we start execution."
That's how I approach the first 90 days of a vCISO engagement. I don't show up with a one-size-fits-all plan. I listen, I assess, and I tailor the program to what the organization actually needs. If a candidate can't articulate a similar approach, they're not thinking like a CISO — they're thinking like a vendor.
Expect Transparency About What's Broken
A good vCISO will tell you hard truths. If your environment is a mess, if your policies are copy-pasted from the internet and don't match your actual practices, if your leadership team has unrealistic expectations about what compliance costs — you need to hear that.
During the evaluation process, pay attention to whether the candidate is willing to be direct. If they're telling you everything is easy and it'll all be fine, they're either not looking hard enough or they're afraid of scaring you off. The right vCISO will tell you what's broken and what it will take to fix it, and they'll do it in a way that's clear and actionable rather than alarmist.
The Chemistry Question: Can You Work with This Person?
Technical fit and regulatory expertise matter most, but chemistry matters too. You're going to be working closely with this person. They'll be advising your CEO, presenting to your board, and making calls that affect your risk posture and your business operations. If you don't trust them or you find them difficult to communicate with, the engagement won't work no matter how qualified they are.
During the evaluation process, pay attention to how the candidate listens. Do they ask good questions? Do they try to understand your situation, or do they assume they already know the answer? Do they respect your constraints, or do they talk down to you?
I've turned down clients where the chemistry wasn't right. It's not that the client was bad or that I couldn't do the work — it's that I could tell we wouldn't communicate well, or that their expectations didn't match what I could realistically deliver. Those situations don't get better with time. It's better to recognize the misfit early and walk away professionally.
If you're the buyer, the same rule applies. If something feels off during the evaluation — if the candidate is defensive when you ask hard questions, or if they talk at you instead of with you — trust that instinct. Choosing between a vCISO and a full-time hire is a significant decision, and so is choosing which vCISO to work with.
Pricing Should Reflect Value, Not Just Hours
vCISO pricing varies widely. I've seen monthly retainers as low as $3,000 and as high as $20,000, depending on the scope, the industry, the organization's size, and the vCISO's experience level. The question isn't whether the price is high or low in absolute terms — it's whether the price reflects the value you're getting.
Ask what's included in the retainer. How many hours per month? What deliverables? Is the vCISO available for incidents and audits, or is that extra? Are you paying for strategic leadership, or are you paying for someone to execute tasks that could be done by a less expensive resource?
Cheap vCISO services are often cheap because the person isn't very good, or because they're overcommitted and can't give you real attention, or because the scope is so narrow that you're only getting surface-level coverage. Expensive doesn't always mean better, but it usually means the vCISO is experienced, in-demand, and structured their practice to deliver real value rather than just check boxes.
For a detailed breakdown of what drives vCISO pricing and what's reasonable to expect at different price points, I've written a separate guide on how much a vCISO costs and what drives the price.
Due Diligence: References, Track Record, and Verification
Before you make a final decision, do your due diligence. Ask for references and actually call them. Ask those references specific questions: Did the vCISO deliver what they promised? Were they responsive? Did they help you pass your audit or get certified? Would you hire them again?
If the candidate has published writing, speaking engagements, or visible work in the community, review it. Do they demonstrate depth and expertise, or are they just repeating vendor talking points? Are they respected in the industry, or are they unknown?
Check their LinkedIn and professional background. Have they held senior security roles before, or is this their first time positioning themselves as a CISO-level leader? Have they stayed with clients long-term, or do they churn through engagements every few months?
These signals aren't definitive on their own, but together they give you a sense of whether the candidate has a real track record or whether they're new to the fractional CISO model and hoping to figure it out as they go.
In my own background, I've been doing information security and compliance work for more than 30 years, with a focus on regulated industries. I currently serve as Chief Information Security Officer at Cleared Systems and provide fractional CISO services to a small number of clients in healthcare and defense. That depth of experience shapes how I approach every engagement, and it's the kind of background you should be looking for when you evaluate candidates. You can learn more about my experience and approach here.
Making the Decision: Fit Over Flash
At the end of the evaluation process, the decision often comes down to fit. Not the candidate who talked the best game or who had the most certifications, but the one who understood your situation, demonstrated real regulatory depth, and made you confident they could lead your program through whatever comes next.
The right vCISO doesn't sell you a pre-packaged solution. They listen, they assess, and they build a program tailored to your organization's maturity, risk tolerance, and regulatory obligations. They're transparent about what's broken, realistic about what it will take to fix it, and structured to give you the attention and responsiveness your situation demands.
Choosing the wrong vCISO wastes time, money, and credibility. Choosing the right one gives you the security leadership you need to manage risk, satisfy regulators, and earn the trust of your board and your customers. That's the difference between checking a box and actually solving the problem.
If you're evaluating whether a vCISO is the right model for your organization, or if you want to understand what a well-structured engagement should look like, I'm happy to talk through your situation. The conversation is free, and there's no pressure. Sometimes the best outcome is clarity about what you actually need, even if that's not me.