vCISO vs full-time CISO: where the line actually sits
Past a certain scale, headcount and regulatory weight a full-time CISO is the right hire; below that line, a fractional security lead gives you genuinely senior coverage without carrying an executive salary.
Every business past a certain size needs someone accountable for security. The question is whether that someone is an executive on your payroll or a senior practitioner on a retainer. Most advice on this question is written by people selling one of the two options. We sell the vCISO side, so read this page with that in mind. When the honest answer is to hire, we say so.
Past a certain headcount, regulatory weight and operational tempo, a full-time CISO is the right call and no retainer substitutes for one. Below that line, which is where most Australian small and mid-market businesses sit, a fractional lead delivers the senior work that matters: strategy, policy, a live risk register, board reporting, incident readiness. None of it requires paying an executive package for a role that fills a fraction of the week.
This page works the decision through six criteria, names the situations where each option wins, and answers the questions buyers actually ask. How we run any engagement is on our approach page; what we hold and what we deliberately do not claim is on our trust page.
Side by side.
| Criteria | vCISO | Full-time CISO |
|---|---|---|
| Cost basis | An ongoing monthly retainer sized to you, or a one-off assessment to start. You pay for senior attention in the volume you need, not a salary for the hours in between. | A full executive package: salary, superannuation, incentives, and the search cost to land the person. The cost runs at the same rate whether the quarter was quiet or on fire. |
| Seniority you can afford | The retainer buys genuinely senior time in slices. The person setting your strategy ships and operates production software for a law firm, a clinical product, and a capital-markets firm. | At a true executive package, you get what the title claims: someone who has carried security through incidents, audits and board cycles. Stretch a mid-level budget over the same title and you get a manager with an inflated business card, which is the worst outcome available. |
| Continuity and coverage | A named lead with a firm behind them. Leave, illness and resignation do not empty the seat. Nobody is on your floor every day, and pretending otherwise would be dishonest. | Full-time presence and deep single-person context. The flipside: when that person resigns, the security function walks out the door with their notice period, and the rebuild starts from their head, not from a document. |
| Board accountability | Plain-English reporting the board can act on, delivered on a regular cadence, and a security voice in the room when the board needs one. Accountability for cyber risk stays with your directors in either model. | An executive who owns security on the org chart and answers for it in person. Where a regulator expects a named accountable owner, this is often the deciding fact. |
| Incident leadership | An incident response playbook your team can run, a tabletop exercise to pressure-test it, and senior direction when something real happens. The first hour is still executed by your people, from a plan they have rehearsed. | A leader in the building for the whole incident lifecycle, who has drilled with the exact people who will respond. If incidents are frequent or existential to the business, this is precisely what the salary buys. |
| Hiring timeline | No executive search required: scope the engagement, agree the cadence, start. If the seat is urgent because someone just resigned, it can hold the line while you run the executive search properly. | An executive search, then a notice period, then onboarding before the first strategy decision lands. Plan for the leadership gap in between, because attackers do not pause for it. |
When a vCISO is the right call
- The security workload is real but does not fill a week: policies, a risk register, vendor questionnaires, board reporting, and an uplift program that needs an owner.
- There is no security hire yet, and the current owner of the problem is a director or the head of engineering doing it on the side.
- You are working toward Essential Eight, SMB1001, ISO 27001 or Privacy Act readiness and need someone senior to run the program to a date.
- The board wants credible security reporting on a regular cadence, not a reassuring slide once a year.
- You are between security leaders and need the seat held, and the function documented, while the executive search runs.
- Clients and procurement teams are asking security questions the business cannot yet answer well.
When to hire the full-time CISO
- You operate under a heavy compliance regime that expects a named, accountable security executive.
- There is a security team to manage: analysts, engineers, an operations function of your own. People management is a full-time job before any strategy gets done.
- The operational tempo is round-the-clock: your own monitoring, on-call rotations, and incidents as a routine fact rather than a rare event.
- Security is core to the product and the market position, and buyers audit you as a condition of doing business.
- The organisation is large enough that security decisions get made daily, in rooms a fractional lead is not in.
The signals that settle it
The signals that you have crossed into full-time territory are concrete. Security headcount that needs a manager. A regulator that expects a named accountable executive. Incidents as a routine operational fact rather than a rare emergency. Buyers who audit your security as a condition of the contract. Any two of those together and the answer is headcount: hire the CISO, pay the real executive package, and give them the authority the title implies.
Below that line the security work looks different. It is episodic and strategic rather than daily and managerial: a policy set that needs writing and then maintaining, a risk register that needs to stay honest, an uplift program toward a framework, board reporting on a regular cadence, procurement questionnaires that keep arriving. That is senior work, and it deserves a senior head. It is not forty hours a week of work, and paying an executive salary for it means paying a CISO to do a great deal of waiting.
The mistake in the middle
The most common failure is not choosing the wrong column. It is the compromise between them: the budget will not stretch to a genuine security executive, so the business hires someone cheaper and gives them the CISO title anyway. The result is a title without the scar tissue, a single person with no bench behind them, and a board that now believes the risk is owned when it is not. That hire costs more than either honest option and delivers less than both.
If the daily workload is real but the executive budget is not, the better structure is usually inverted: a security engineer or analyst in-house doing the volume work, with a fractional lead above them setting direction, reviewing the output, and fronting the board. Senior judgement in slices, sitting over junior capacity in bulk, beats a mid-level generalist wearing an executive title.
How we run the fractional seat
Black Shard's vCISO service is a named security lead on a regular cadence. The deliverables are unglamorous on purpose: a security strategy the business actually follows, policies and a risk register that stay true between board meetings, and reporting in plain English that a director can read and act on. An engagement can open with a posture assessment, so the first conversation is about where you actually stand rather than where a template assumes you do.
The advice comes from operating, not just advising. We build and run our own software, under the obligations those industries carry, so the recommendations have been tested against production reality before they reach your risk register. We hold SMB1001:2026 Gold, verifiable on the public CyberCert registry, and we work least-privilege during every engagement: we get only the access the work requires, and no more.
The engagement shape is an ongoing monthly retainer, or a one-off assessment to start if you want to see the quality of the thinking before committing to a cadence. Delivered Australia-wide from our Brisbane head office.
Questions, answered
- What does a vCISO actually do?
- A named security lead who owns your security program. The work: security strategy, policies and a risk register kept current rather than written once and shelved, plain-English reporting your board can act on, incident readiness including a response playbook and a tabletop exercise to pressure-test it, and ownership of compliance programs toward Essential Eight, SMB1001, ISO 27001 or Privacy Act readiness. An engagement can start with a posture assessment: a structured gap analysis against the Essential Eight and CIS Controls that says where you stand, what is exposed, and what to fix first.
- How much does a vCISO cost?
- We do not publish figures, because a published figure would be invented for a business we have not seen. The number follows the scope of the work and the cadence the board wants. A one-off assessment is the cheapest way to find out, and it stands on its own whether or not a retainer follows.
- Can a vCISO run our incident response?
- A vCISO makes your team ready to run it, and provides senior direction when something real happens. What a retainer is not: a round-the-clock monitoring service. We do not operate a twenty-four-hour SOC and we will not pretend a retainer is one. The workable model is a playbook your people can execute in the first hour, a tabletop that proves they can, and a senior head engaged for the decisions that follow.
- Is a vCISO enough to get us to ISO 27001 or Essential Eight readiness?
- Yes. A fractional lead can own the whole readiness program: the gap analysis, the remediation plan, and the evidence trail an assessor expects. We hold SMB1001:2026 Gold ourselves, and we self-assess against the Essential Eight, so the advice comes from having done the work on our own environment first.
- Can we start with a vCISO and hire a full-time CISO later?
- It is one of the most sensible paths available. The fractional lead builds the function, then helps you scope the executive role and hands the incoming CISO a working risk register and policy set instead of a blank page. A new CISO who inherits a documented function is productive in their first month rather than their first year.
A posture assessment shows which side of the line you are on.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

