Black Shard

vCISO vs full-time CISO: where the line sits

Past a certain scale, headcount and regulatory weight a full-time CISO is the right hire; below that line, a fractional security lead gives you senior coverage without carrying an executive salary.

Every business past a certain size needs someone accountable for security. The question is whether that someone is an executive on your payroll or a senior practitioner on a retainer. Black Shard sells the vCISO side; where the answer is to hire, we say so.

Past a certain headcount, regulatory weight and operational tempo, a full-time CISO is the right call and no retainer substitutes for one. Below that line, which is where most Australian small and mid-market businesses sit, a fractional lead delivers the senior work that matters: strategy, policy, a live risk register, board reporting, incident readiness. None of it requires paying an executive package for a role that fills a fraction of the week.

Side by side.

vCISO compared with Full-time CISO
CriteriavCISOFull-time CISO
Cost basisAn ongoing monthly retainer sized to you, or a one-off assessment to start. You pay for senior attention in the volume you need.A full executive package: salary, superannuation, incentives, and the search cost to land the person. The cost runs at the same rate whether the quarter was quiet or on fire.
Seniority you can affordThe retainer buys senior time in slices. The lead comes from a firm that builds and operates production software for a law firm, a capital-markets firm, and a clinical-voice product used by private-hospital specialists.At a true executive package, you get what the title claims: someone who has carried security through incidents, audits and board cycles. Stretch a mid-level budget over the same title and you get someone who has not carried security through any of those.
Continuity and coverageA named lead with a firm behind them. Leave, illness and resignation do not empty the seat. Nobody is on your floor every day.Full-time presence and deep single-person context. The flipside: when that person resigns, the security function walks out the door with their notice period, and the rebuild starts from their head, because there is no document to start from.
Board accountabilityReporting the board can act on, delivered on a regular cadence, and a security voice in the room when the board needs one. Accountability for cyber risk stays with your directors in either model.An executive who owns security on the org chart and answers for it in person. Where a regulator expects a named accountable owner, this is often the deciding fact.
Incident leadershipAn incident response playbook your team can run, a tabletop exercise to pressure-test it, and senior direction during an incident. The first hour is still executed by your people, from a plan they have rehearsed.A leader in the building for the whole incident lifecycle, who has drilled with the exact people who will respond. If incidents are frequent or existential to the business, this is what the salary buys.
Hiring timelineNo executive search required: scope the engagement, agree the cadence, start. If the seat is urgent because someone just resigned, it can hold the line while you run the executive search properly.An executive search, then a notice period, then onboarding before the first strategy decision lands. Plan for the leadership gap in between.

When a vCISO is the right call

  • The security workload exists but does not fill a week: policies, a risk register, vendor questionnaires, board reporting, and an uplift program that needs an owner.
  • There is no security hire yet, and the current owner of the problem is a director or the head of engineering doing it on the side.
  • You are working toward Essential Eight, SMB1001, ISO 27001 or Privacy Act readiness and need someone senior to run the program to a date.
  • The board wants security reporting on a regular cadence.
  • You are between security leaders and need the seat held, and the function documented, while the executive search runs.
  • Clients and procurement teams are asking security questions the business cannot yet answer well.

When to hire the full-time CISO

  • You operate under a heavy compliance regime that expects a named, accountable security executive.
  • There is a security team to manage: analysts, engineers, an operations function of your own. People management is a full-time job before any strategy gets done.
  • The operational tempo is round-the-clock: your own monitoring, on-call rotations, and incidents as routine.
  • Security is core to the product and the market position, and buyers audit you as a condition of doing business.
  • The organisation is large enough that security decisions get made daily, in rooms a fractional lead is not in.

The signals that settle it

The signals that you have crossed into full-time territory are specific. Security headcount that needs a manager. A regulator that expects a named accountable executive. Incidents as a routine operational fact rather than a rare emergency. Buyers who audit your security as a condition of the contract. Any two of those together and the answer is headcount: hire the CISO, pay the executive package, and give them the authority the title implies.

Below that line the security work looks different. It is episodic and strategic rather than daily and managerial: a policy set that needs writing and then maintaining, a risk register that needs to stay current, an uplift program toward a framework, board reporting on a regular cadence, procurement questionnaires that keep arriving. That is senior work, and it deserves a senior head. It is not forty hours a week of work.

The mistake in the middle

The most common failure is the compromise between the two options: the budget will not stretch to a security executive, so the business hires someone cheaper and gives them the CISO title anyway. The result is a title without the experience the role assumes, a single person with no bench behind them, and a board that now believes the risk is owned when it is not. That hire costs more than either option.

If the daily workload exists but the executive budget does not, the better structure is usually inverted: a security engineer or analyst in-house doing the volume work, with a fractional lead above them setting direction, reviewing the output, and fronting the board. Senior judgement on a cadence, sitting over in-house capacity for the daily work, covers more than a mid-level generalist with an executive title.

How we run the fractional seat

Black Shard's vCISO service is a named security lead on a regular cadence. The deliverables: a security strategy the business follows, policies and a risk register kept current between board meetings, and reporting a board can act on. An engagement can open with a posture assessment, so the first conversation starts from the current position.

The firm builds and operates production software under the obligations those industries carry. The firm's certification position is on our trust page, and every engagement runs least-privilege, with only the access the work requires.

The engagement shape is an ongoing monthly retainer, or a one-off assessment to start if you want to see the quality of the thinking before committing to a cadence. Delivered Australia-wide from our Brisbane head office.

Questions, answered

What does a vCISO do?
A named security lead who owns your security program. The work: security strategy, policies and a risk register kept current, reporting your board can act on, incident readiness including a response playbook and a tabletop exercise to pressure-test it, and ownership of compliance programs toward Essential Eight, SMB1001, ISO 27001 or Privacy Act readiness. An engagement can start with a posture assessment: a structured gap analysis against the Essential Eight and CIS Controls that says where you stand, what is exposed, and what to fix first.
How much does a vCISO cost?
We do not publish figures. The number follows the scope of the work and the cadence the board wants. A one-off assessment is the cheapest way to find out, and it stands on its own whether or not a retainer follows.
Can a vCISO run our incident response?
A vCISO makes your team ready to run it, and provides senior direction during an incident. A retainer is not a round-the-clock monitoring service. The workable model is a playbook your people can execute in the first hour, a tabletop that proves they can, and a senior head engaged for the decisions that follow.
Is a vCISO enough to get us to ISO 27001 or Essential Eight readiness?
Yes. A fractional lead can own the whole readiness program: the gap analysis, the remediation plan, and the evidence trail an assessor expects. We self-assess against the Essential Eight and have run these programs on our own environment.
Can we start with a vCISO and hire a full-time CISO later?
It is one of the most sensible paths available. The fractional lead builds the function, then helps you scope the executive role and hands the incoming CISO a working risk register and policy set instead of a blank page. A new CISO who inherits a documented function is productive in their first month.

A posture assessment shows which side of the line you are on.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au