CONTACT

What Is a Virtual CISO, and Do You Need One?

virtual ciso

A virtual CISO is an experienced security leader you bring in part-time rather than employ full-time. They set the security strategy, own the risk decisions and report to the board on an agreed number of days each month. The role is governance rather than hands-on security work, and that difference decides whether you need one.

Most UK businesses say they take this seriously. Far fewer have made anyone accountable. The government’s Cyber Security Breaches Survey found cyber security was a high priority for senior management in 72% of businesses, while only 31% had a board member taking explicit responsibility for it. That gap is why this market exists.

A virtual CISO buys you security leadership without a permanent hire. It does not buy you the monitoring, patching and testing that leadership exists to direct.

What Does a Virtual CISO Actually Do?

A virtual CISO does the governance work: deciding what risks the business accepts, setting the security strategy, planning for incidents, and giving the board evidence that controls work. The NCSC and DSIT Cyber Governance Code of Practice sets out five areas boards need to take ownership of, and a fractional hire is usually brought in to cover them.

Those five areas are risk management, strategy, people, incident planning and response, and assurance and oversight. None of them is a technical task. They are decisions, and someone has to be senior enough to make them and accountable enough to sign them off.

The Code is voluntary, and it is written for boards rather than for the people running security day to day. Read it and the job description writes itself. If nobody in your business does those five things, you have a gap. Whether you fill it with a fractional hire, a permanent one or an existing board member is a separate question, and this post is mostly about telling those apart.

Does UK Law Require You to Have One?

No. No UK law requires a business to appoint a CISO, virtual or permanent. What the law requires is the outcome. UK GDPR expects personal data to be protected by appropriate technical and organisational measures, with breaches reported within 72 hours. How you staff that is left to you.

Directors carry the duty personally. Under section 172 of the Companies Act, directors have to act in the way they consider most likely to promote the success of the company, including the long-term consequences of their decisions. A board that cannot describe its own cyber risk is not meeting that duty, whoever it employs.

A Cyber Security and Resilience Bill is going through the House of Lords and is not yet law. It targets essential services such as healthcare, water and energy, and it tightens incident reporting duties. It does not create a requirement for a CISO either. Transputec has written separately on cyber resilience strategy for security leaders if the governance side is what you are weighing up.

Need the Security Work Behind the Plan?

Transputec runs six cyber security services under one accountable UK SOC: 24/7 managed SOC with human analysts on every shift in London, MDR, penetration testing and vulnerability management, with escalation under contracted MTTR and monthly reporting your auditor and board can both read. That is the delivery a CISO, virtual or permanent, exists to direct. Talk to our team about the security work behind your board reporting.

Get a Strategic Consultation

When Does a Business Need a Virtual CISO?

Usually when the security decisions have outgrown the person making them. A capable IT manager can run tools well and still not be the right person to tell the board which risks the business is accepting. The trigger is rarely a breach. It is more often a customer, an insurer or a regulator asking a question nobody can answer.

The common triggers look like this. A tender or supplier questionnaire asks who owns information security. An insurer wants evidence of governance rather than just controls. You are moving into a regulated sector or bidding for public sector work. You have grown past the point where one person can hold it all in their head. Or a board member has read the Code of Practice and asked an uncomfortable question.

Size changes the picture. Among large businesses, 68% have a board member responsible for cyber security. Across the whole business population it is 31%. The distance between those two numbers is roughly the market this role sells into.

Hiring is the other pressure. DSIT’s 2026 labour market research found 30% of UK businesses reported skills gaps in more advanced technical areas, and put the cyber workforce gap at around 3,800 people. Senior security experience is the hardest part of that market to buy, which is exactly why fractional versions of the job exist.

Virtual CISO, Full-Time CISO or Managed Security?

These three solve different problems, and businesses often buy the wrong one. The fractional version gives you decisions. A full-time CISO gives you decisions plus daily presence and internal authority. A managed security provider gives you the work getting done. Most mid-sized businesses need the third before they need either of the first two.

Virtual CISOFull-time CISOManaged security provider
What you getStrategy, risk decisions, board reportingThe same, plus daily presence and internal authorityMonitoring, detection, response, testing, patching
TimeAgreed days per monthFull timeContinuous, under contract
Best whenYou need governance but not a permanent salarySecurity is core to the business model, or a regulator expects a named officerThe controls need running, whoever sets the strategy
Does not give youAnyone to do the workCapacity to run the tools aloneAccountability for the risk decisions

The row that matters is the last one. Someone senior who arrives to find no monitoring, no patching cycle and no tested backups will spend three months writing a plan for work somebody else has to do. If that somebody does not exist, the plan sits there. This is the most common way the arrangement disappoints people.

What Does a Virtual CISO Cost in the UK?

There is no published benchmark, and the ranges quoted online vary widely enough to be unhelpful. UK pricing is normally a monthly retainer set by the number of days, the seniority of the person and whether incident support is included. What you can compare honestly is the structure rather than the headline number.

Three things drive the price. Days per month, because the role scales with how much decision-making you need. Seniority, because someone who has held the job in a regulated business costs more than a consultant who has read the framework. And scope, because governance on its own is cheaper than governance plus being on call when something happens.

The comparison people actually want is against a permanent hire, and that is not just salary. It is salary, employer costs, recruitment, the months the role sits empty while you search, and the risk that the person leaves. DSIT puts annual outflow from the UK cyber workforce at roughly 4%. For a business that needs the decisions made but not made every day, the fractional route is often cheaper for reasons that have nothing to do with the day rate.

Get the scope in writing before you compare prices. Days, what is in and out, what happens during an incident, and who owns the risk register.

What the Role Will Not Do

They will not run your security tools, and they cannot certify you. The virtual CISO sets direction and holds the risk decisions. It does not monitor your network at three in the morning, patch your servers or test your restores. It also cannot award Cyber Essentials or ISO 27001, because certification comes from an accredited body.

Two more limits are worth knowing before you sign anything.

They have no authority you do not give them. Someone in this role who reports to the IT manager will be overruled by the IT manager. It only works with a direct line to the board or the owner, because the job involves telling people things they would rather not hear.

They are not an incident response team. Some arrangements include incident support and some do not. Check which you are buying, because finding out during a ransomware event is expensive. Transputec keeps the two separate on purpose: incident response is a priority retainer with its own commitments, not something folded into an advisory day rate.

How Do You Get Value From the Arrangement?

Give them access, a mandate and something to direct. The arrangements that work share three features: the person reports to the board, they have a written remit covering the five governance areas, and there is a delivery capability underneath them that can act on what they decide. Remove any one of those and you get a document.

Set the first ninety days deliberately. Anyone good will want to know what you already have before recommending anything, so expect the first month to be a survey rather than a strategy. Ask for the risk register early, because it tells you whether they are describing your business or filling in a template.

Then make the reporting boring and regular. One page to the board each month, the same shape every time: what changed, what is open, what needs a decision. The Code of Practice calls this assurance and oversight, and it is the part most businesses skip. A plan nobody reviews is indistinguishable from no plan at all.

Your Checklist Before You Appoint Anyone

Work through these before you appoint anyone.

  • Write down the five governance areas and name who does each one today. If the answer is nobody, you have found your gap.
  • Decide whether you need decisions, delivery, or both. Buying governance when the gap is delivery is the most common mistake.
  • Check who the role would report to. If it is not the board or the business owner, fix that before you hire.
  • Agree days per month in writing, and what happens when an incident needs more of them.
  • Confirm whether incident response is in scope, and what the response time is if it is.
  • Ask to see an example board report, redacted. It shows you what you will actually receive.
  • Make sure there is someone to do the work. A strategy with no delivery underneath it does not reduce risk.

Conclusion

A virtual CISO is a sensible answer to a real gap. Most UK businesses treat cyber security as a senior priority and have still not made anyone accountable for it, and no law is going to force the issue. The decision comes down to one question: is your problem that nobody is making the security decisions, or that nobody is doing the security work?

If it is the decisions, this is a cheap way to get them made properly. If it is the work, buy that first, because a plan with nothing underneath it changes nothing. Transputec runs the delivery side through cyber security services, and the monthly board reporting that comes with it is usually what was missing in the first place. Talk to us about the security work behind your board reporting.

FAQs

It stands for virtual chief information security officer, and it means the same thing as the longer phrase. You will also see CISO as a service and outsourced CISO used for the same arrangement. The wording varies more than the service does. What genuinely differs between providers is the number of days, the seniority of the person and whether incident support is included, so compare those rather than the label.

A vCISO owns security risk. A virtual CIO owns technology strategy and spend. The two overlap on decisions like cloud platforms and supplier choice, but their reporting lines and priorities differ, and a business can genuinely need both or neither. Transputec covers the other role in a separate post on what a virtual CIO does.

There is no published benchmark. Pricing is a monthly retainer driven by days per month, the seniority of the person and whether incident support is in scope. Compare the structure rather than the headline figure, and be careful comparing it with a salary, because a permanent hire also carries recruitment cost, employer costs and the months the role sits empty.

Usually not yet. Smaller businesses tend to get more from fixing the basics first: patching, backups that have actually been tested, multi-factor authentication and someone monitoring. The five Cyber Essentials controls cover several of those and cost far less than a retainer. The governance role earns its money when the decisions get genuinely difficult, which is normally when a regulator, insurer or large customer starts asking.

No. Certification is awarded by an accredited certification body, and an advisor cannot award it to their own client. They can tell you what is missing and make sure the work gets scheduled, but the assessment itself has to come from outside. Treat any provider who blurs that line with caution.

This article was drafted with AI assistance and reviewed by the Transputec team. Featured image: AI-generated.

Ready to experience the Transputec difference?

Turn IT headaches into operational strength. Book a free consultation and see exactly what we can streamline inside your business. 

Get a Strategic Consultation

Sonny Sehgal

CEO & Co-Founder

Since co-founding Transputec, Sonny has guided hundreds of enterprises through every major shift in technology- from the birth of the PC to the rise of Global Cloud and now Generative AI. Known for his "straight-talking" approach to cyber security and IT strategy, he provides the bridge between complex technical infrastructure and boardroom-level business outcomes.

Share Blog »

← Blogs

Contact

Get in Touch