Metaluxo
← Insights

vCISO

Does Your SME Need a Full-Time CISO? The Numbers Say Probably Not.

Designed graphic on a deep navy background showing 30–40 with the caption HOURS PER MONTH — all the security leadership most SMEs need.

The job posting sits open for six months. The salary band starts at £120,000. The requirements list includes CISSP, CISM, ten years in financial services, and experience with cloud architecture, compliance frameworks, and board reporting.

You are a 45-person fintech startup in London or a health-tech SME in Warsaw. You need someone accountable for security. You do not need someone who costs more than your entire engineering budget.

This is the gap the virtual CISO was built for.


What a CISO actually does

The title Chief Information Security Officer implies a corner office and a team of analysts. In practice, the role breaks down into five accountabilities:

  1. Risk ownership — maintaining a risk register, scoring threats, and presenting the top risks to the board with recommended treatments.
  2. Compliance roadmap — mapping regulatory requirements (GDPR, DORA, ISO 27001, SOC 2) to the company’s current state and plotting the path to closure.
  3. Policy and standards — writing the documents that say how the company protects information, and verifying that the documents match reality.
  4. Incident readiness — running tabletop exercises, maintaining the response playbook, and being the person who answers the phone at 2 a.m.
  5. Customer and supplier assurance — answering security questionnaires, conducting due diligence on third parties, and representing the company in procurement reviews.

For a company under 200 people, these five accountabilities do not require 40 hours a week. They require concentrated expertise, consistent attention, and someone who can speak to both engineers and auditors without translating through a middleman.


The math: full-time vs. fractional

Cost itemFull-time CISO (UK)Virtual CISO
Base salary£120K–£180K—
Employer NI, pension, benefits+£25K–£40K—
Recruitment fees£15K–£25K one-off—
Training and certification£3K–£5K/yearIncluded
Total annual cost£163K–£250K£36K–£72K
Monthly equivalent£13.5K–£21K£3K–£6K

The fractional model is not cheaper because the person is less experienced. It is cheaper because you are buying the exact hours you need, not the gaps between meetings.

A typical vCISO engagement for an SME runs 30–40 hours a month, structured as:

  • Week 1: Risk register review, compliance status update, board slide deck.
  • Week 2: Policy review, internal audit follow-up, supplier due diligence.
  • Week 3: Incident response tabletop, security awareness update, customer questionnaire.
  • Week 4: Architecture review, threat intelligence briefing, roadmap planning.

The remaining 120–140 hours in the month are when the company operates without a security person in the room — which is exactly what happens with a full-time CISO who spends most of their time in meetings anyway.


What a vCISO does not do

This is where some fractional arrangements fail: the scope is vague, the client expects 24/7 coverage, and the engagement collapses in month three.

A vCISO is not:

  • A helpdesk. They do not reset passwords or troubleshoot MFA lockouts. That is IT operations.
  • A penetration tester. They commission and manage pen tests, but they do not run them.
  • On call 24/7. They design the incident response playbook and train the team, but the first responder is usually an internal engineer or an external SOC.
  • A magician. If the company has no backups, no patch process, and no asset inventory, a vCISO will surface those gaps quickly. Fixing them requires budget and engineering time the vCISO does not control.

The value of a vCISO is accountability and direction, not execution of every security task. The best engagements pair a vCISO with an internal IT manager or outsourced MSP who handles the day-to-day.


When fractional stops being enough

There are three signals that a company has outgrown the vCISO model and needs a full-time hire:

  1. Volume exceeds capacity. If security work consistently runs past 60–80 hours a month — multiple parallel compliance programmes, daily customer audits, active incident response — one person on a fractional schedule cannot keep up.
  2. Regulatory proximity. If the company is under direct regulatory supervision (a bank, an insurer, a critical infrastructure provider), the regulator typically expects a named individual with daily availability.
  3. Board culture. Some boards want a CISO physically present at every meeting, available for corridor conversations, and visible to staff. This is a legitimate preference, but it is cultural, not technical.

For everyone else — the 95% of SMEs that need security leadership but do not generate 40 hours of CISO-level work a week — the fractional model is the rational choice.


How to scope a vCISO engagement

If you are considering a virtual CISO, scope the engagement around outcomes, not hours:

  • Deliverable 1: A risk register, reviewed monthly, with the top five risks scored and treatment-planned.
  • Deliverable 2: A compliance roadmap showing current state, target state, and milestones for the next 12 months.
  • Deliverable 3: Board-ready security reporting, quarterly, with metrics that mean something (mean time to patch, phishing simulation pass rate, control maturity scores).
  • Deliverable 4: Customer security questionnaire responses, turned around within five working days.
  • Deliverable 5: An incident response playbook, tested twice a year, with named roles and contact trees.

These five deliverables cover every accountability a full-time CISO would own. They also fit comfortably into 30–40 hours a month for a company under 200 people.


The real question

The debate is not “full-time or fractional?” The debate is “who is accountable, and can they prove it?”

A full-time CISO who spends their day in meetings and leaves the risk register untouched for six months is less valuable than a vCISO who updates it every month and presents the top three risks to the board with treatment options.

At Metaluxo we run virtual CISO engagements for SMEs across the EU — typically 30–40 hours a month, with the same accountability as a full-time hire. If your board is asking who owns security, and you are not sure what to tell them, book a free 30-minute consultation. We will scope exactly what you need and what it costs.

Common questions

What does a vCISO actually do?

A virtual CISO owns the security strategy, risk register, compliance roadmap, board reporting, and customer security reviews — the same accountability as a full-time CISO, on a part-time schedule.

How much does a vCISO cost compared to full-time?

A UK full-time CISO costs £120K–£180K plus benefits. A vCISO engagement typically runs £3K–£6K per month, or roughly 20–30% of the total cost.

When should a company hire a full-time CISO instead?

When security work consistently exceeds 60–80 hours a month, when regulatory scrutiny requires daily interaction, or when the board wants someone physically present at every meeting.

Related reading

Send us a message
Message us Book now