vCISO, full-time CISO or MSSP: what each one actually covers
The board has asked who owns security. Three kinds of supplier answer the question and only two of them are answering it. The common and expensive mistake is buying operations when what was missing was leadership: a year later the alerts are handled, the questionnaire is still unanswered, and nobody has decided anything.
The short version
- A full-time chief information security officer is leadership, permanently and internally.
- A virtual or fractional CISO is the same leadership function bought on a defined cadence, with a named senior person doing it.
- A managed security services provider is operations: monitoring, detection, response and, often, the running of specific security tooling.
A managed security provider runs detection and response; it does not set your risk appetite, decide what gets built, answer a customer’s security review or own the roadmap. Those are leadership tasks and they stay unowned unless somebody is appointed to them.
What a full-time CISO gives you
Presence is the real product. Somebody is in the room when the product roadmap is set, when an acquisition is discussed, when an incident is running and when the budget is argued. They build relationships across engineering, legal, finance and sales that a part-time arrangement cannot replicate, and they carry context that never gets written down.
The cost beyond compensation is the part organizations underestimate. A security leader without a team is a leader who ends up doing the work personally, which is the most expensive way to run a vulnerability programme. Recruitment takes months, the market is competitive, and a mis-hire at that level sets a security programme back further than having nobody, because the organization concludes the function does not work.
What a vCISO gives you
A named senior owner on a defined cadence, with the scope written down: which decisions they make, which they recommend, what they attend, and what they are accountable for producing. The value is continuity and judgement — the same person, month after month, who knows why last quarter’s decision was taken and can say so when it is questioned.
It suits organizations where security decisions arrive weekly rather than daily: a growing software business, a regulated firm with a small technology function, a company whose customers have started sending security reviews. It is a poor fit where the work is genuinely continuous, or where the role is mostly managing a security team, because managing people part-time works badly for the people being managed. Our own arrangement is described under the security programme.
A large share of the work, in practice, is making the organization legible to people outside it. A customer asks for evidence; a prospect sends a questionnaire; a partner asks who has access to their data. Some of those questions eventually resolve into a formal artifact — System and Organization Controls reporting is, in the words of the body that sets the professional standards for it, “a suite of service offerings CPAs may provide”, and deciding whether and when to go after one is a leadership decision with a budget attached. Most of them do not, and answering them well without over-committing is a skill in itself.
A fractional security leader can own decisions, write them down and be held to them, but accountability to a regulator or a board sits with an officer of the organization and cannot be contracted out. A good fractional arrangement makes that explicit in the engagement letter rather than leaving it comfortable and vague.
What an MSSP gives you
Scale and coverage. A managed provider watches your telemetry around the clock, triages what fires, escalates what matters, and often manages the detection tooling itself. Their analysts see patterns across many customers, which is an advantage no single organization can buy on its own, and they absorb the staffing problem of covering nights and weekends.
What they do not do is decide. The contract defines what is monitored, and what is outside it is nobody’s problem until it is everybody’s. Tuning is a shared responsibility that frequently ends up unshared. And the provider responds to what they can see: a business-logic abuse that produces perfectly ordinary log lines will not raise an alert.
To be plain about our own position: SecHB does not provide managed detection and response and does not run round-the-clock monitoring. The column above is described here because buyers are choosing between all three, not because it is on offer. Where an organization needs it, the useful contribution is helping write the requirements and read the contract.
Where do the gaps sit?
| Work | Full-time CISO | vCISO | Managed provider |
|---|---|---|---|
| Setting risk appetite and standards | Yes | Yes | No |
| Answering customer security reviews | Yes | Yes | Partially, for their own scope |
| Owning the roadmap and budget case | Yes | Yes | No |
| Round-the-clock detection | Only with a team | No | Yes |
| Triaging alerts | Only with a team | No | Yes |
| Declaring and running an incident | Yes | Yes, if the retainer says so | Technical response only |
| Managing security staff | Yes | Poorly | No |
| Being in the room continuously | Yes | No | No |
Read down the “No” column of whichever option you have bought. That is your gap list, and every item on it is work that still has to happen.
Have you outgrown a fractional arrangement?
Four signals, and one of them is usually enough.
- Decisions queue between sessions and the queue is never empty.
- You have hired security staff who need day-to-day management.
- A regulator, an insurer or a major customer expects a named internal officer.
- Security is now a product feature that sales talks about in every deal.
There is no headcount that triggers a full-time hire. The signal is workload and consequence: a security decision arriving most days, a regulated product, or a security function large enough that somebody has to manage the people in it. The reverse signals are just as clear: if the role would spend its first year writing policy and answering questionnaires, a full-time hire will be bored and gone within eighteen months.
Combining them
The arrangement that works is a named senior owner setting direction and standards, a managed provider running detection under a contract that owner wrote, and an internal engineer who owns the day-to-day changes. In that shape each part does what it is good at, and the relationship the fractional owner has with the provider is the thing that keeps coverage honest — somebody reads the monthly report and asks why nothing fired from the segment that was onboarded last quarter.
The shape that fails is a managed provider with no internal counterpart. Alerts are handled, nothing is decided, and the first time anyone notices is during an incident, when it turns out that the response plan was never written because the monitoring contract was mistaken for one.
Questions to ask each kind of provider
- Who, by name, will do this work, and what else are they doing? For leadership this is the whole question.
- What decisions do you make, and what do you only recommend? Get it in writing before the first disagreement.
- What is explicitly outside scope? A supplier who answers this crisply has thought about it.
- What happens at three in the morning, and who is called? Ask all three; the answers differ enormously.
- What will exist in writing after six months? If the answer is only meeting notes and dashboards, nothing is being built.
If your immediate pressure is enterprise buyers rather than operations, the sequence in security for SaaS selling to enterprise is probably a better map than any of these three, and our own range is set out under services.
How the work is bounded
The scope is agreed in writing before work starts, and the engagement is quoted in writing with it.
SecHB does not issue certifications, attestations or audit opinions: those come from accredited certification bodies, CPA firms and QSAs. The work here is what an organization does to be ready for them.
Nothing here is legal advice. Where a question turns on the law, the work is done alongside the client’s counsel, not instead of them.
Questions we are asked
Can a vCISO take accountability?
A fractional security leader can own decisions, write them down and be held to them, but accountability to a regulator or a board sits with an officer of the organization and cannot be contracted out.
Does an MSSP replace a security programme?
A managed security provider runs detection and response; it does not set your risk appetite, decide what gets built, answer a customer’s security review or own the roadmap. Those are leadership tasks and they stay unowned unless somebody is appointed to them.
What size company needs a full-time CISO?
There is no headcount that triggers a full-time hire. The signal is workload and consequence: a security decision arriving most days, a regulated product, or a security function large enough that somebody has to manage the people in it.
Can these be combined?
The arrangement that works is a named senior owner setting direction and standards, a managed provider running detection under a contract that owner wrote, and an internal engineer who owns the day-to-day changes.
Working out which one you need
Describe what is currently unowned and who is currently doing it. The reply says which of the three closes that gap. More of our writing is indexed at writing.