Black Shard

Insights22 August 2026

What a vCISO costs in Australia

vCISO quotes contradict each other because they price different shaped engagements. What actually moves the number, the models the Australian market sells, broad ranges to sense-check a proposal against, when a retainer earns its cost over ad-hoc consulting, and the questions worth asking before you sign.

A set of graduated brass weights beside an idle steel balance scale on dark slate, lit cold with a cyan edge

Why one figure never answers the question

Ask five vCISO providers what they charge and the five numbers will not describe the same thing. One quotes a monthly retainer. Another quotes an hourly rate. A third answers with a package price for a defined project. None of them are being dishonest; they are pricing different shapes of work, and the shape is set mainly by three things: how much of the role you are actually buying, how often the person shows up, and what your industry and regulator expect them to own. Settle those three before comparing numbers, or the comparison tells you nothing.

This note works through what actually moves the price, the engagement models the Australian market sells, broad ranges those models cluster around, when a standing retainer earns its cost over ad-hoc consulting, and the questions worth asking a provider before you sign anything. It does not include a price for Black Shard's own vCISO practice. An honest number for that follows a scoping conversation about your business, the same as it should for anyone quoting you.

What actually moves the price

Five variables explain most of the variation in what providers quote, and the provider's name is not one of them.

  • Scope: whether the engagement covers strategy and reporting alone, or extends to policy drafting, a live risk register, vendor questionnaires, and incident leadership
  • Cadence: a few hours a month against a weekly working session. More contact time costs more, and cadence is usually the single biggest lever on price
  • Industry obligations: a business under APRA's CPS 234, handling health records, or answering enterprise procurement questionnaires needs a heavier evidence trail than one that mainly wants a competent, accountable owner of the risk register
  • Existing groundwork: a business with no policies, no register and no incident plan pays for all three to be built. A business that already has them pays mainly for review and continuity
  • Seniority required: a named lead who has actually carried these obligations in a production environment costs more than a generalist consultant, and the market prices that difference

The models the Australian market sells, and what they cost

Providers package vCISO work into a small number of recognisable shapes. None is inherently better; each suits a different starting point. The ranges below are broad observations of what the Australian and comparable international market currently charges for each shape, not a quote for your business and not Black Shard's pricing. Any specific number depends on the five variables above, and a real quote only exists after a conversation about your systems.

ModelHow it is billedWhat it suitsBroad range seen in the market (AUD)
Ad-hoc or hourly consultingBy the hour or the day, no standing commitmentA defined, bounded piece of work: a single policy, a board briefing, an incident debriefRoughly $150 to $350 an hour
Light-touch advisory retainerA fixed, small number of hours a month, usually remoteA business that mainly needs a named, accountable owner for board reporting and oversight, with the volume work done in-houseRoughly $2,500 to $5,000 a month
Working retainerA regular weekly or fortnightly working session, plus reportingA business building or running a real program: policies, a live risk register, vendor questionnaires, an uplift roadmapRoughly $5,000 to $10,000 a month
Full-scope retainerHeavier weekly involvement, often with incident leadership and compliance program ownership includedA regulated business, a heavier audit or procurement load, or a board that wants near-executive coverage without the hireRoughly $10,000 to $20,000 a month, sometimes more in complex or heavily regulated environments

vCISO engagement models seen in the Australian market

How does that compare to hiring a full-time CISO?

For context, a full-time CISO is a genuine executive hire. Base salary and superannuation for the role commonly land between $250,000 and $400,000 or more a year in the Australian market, before the cost of the search itself and before the seat is filled. Even the top of the retainer ranges above sits well under that, because a retainer buys a defined slice of a senior person's time rather than the whole of it, spread across more than one client. That trade-off is real in both directions: a retainer does not give you a person in the building every day, and a full-time salary does not automatically buy the breadth that comes from working across more than one environment. Where the line actually falls for a given business is a longer question than pricing alone answers, and we work through it on its own page.

When a retainer earns its cost over ad-hoc consulting

Ad-hoc consulting is the right call for a single bounded deliverable: a policy needs writing, a board wants one briefing before a renewal, an incident has just happened and someone senior needs to run the debrief. Paid by the hour or the project, scoped tightly, it does exactly what it says and nothing continues after it is delivered.

A retainer earns its cost when the work does not stop being true the day it is delivered. A risk register drifts out of date within a quarter if nobody owns updating it. A policy written once and filed answers an auditor's checklist and nothing else. Board reporting on a cadence is worth more than the same content delivered as a single briefing, because a board tracks direction across sittings, not one data point. And obligations that run continuously, a prudential standard, the Notifiable Data Breaches scheme, a customer contract carrying a security schedule, need someone still there when the next questionnaire, the next audit, or the actual incident arrives, not someone who delivered a report months ago and moved on.

The tell is whether the value compounds. A retainer used the way a hire would be used, decisions tracked across sittings, a register that stays honest, a relationship the board and a regulator both recognise, earns the ongoing cost. A retainer that exists on the invoice and nowhere else, because nobody on the client side is turning up to the sessions either, does not, and that failure mode is common enough to check for before signing.

The questions worth asking before you sign

A scoping conversation with a competent provider answers most of these before you have to ask. If it does not, ask directly.

  • What is included in the retainer hours, and what triggers additional billing: a specific project, an incident, an unscheduled board request?
  • Who is the named person, what have they actually run before, and can you speak with them before signing rather than only their sales lead?
  • Is the cadence written into the agreement, with a defined session length and frequency, or is it a verbal understanding that can quietly slip?
  • If the roadmap calls for a penetration test, a cloud review or engineering work, does the same firm deliver it, or does the vCISO hand you to a separate vendor at that point?
  • Does the retainer include incident leadership, or is that a separate rate agreed only once something has already gone wrong?
  • What access does the engagement need, and is it granted deliberately and reviewed, or is it a standing administrator account issued on day one?
  • What is the notice period, and what do you keep, the register, the policies, the roadmap, if the engagement ends?
  • Who checks the recommendations the vCISO makes? A person who can also sell you the remediation work should be able to explain how that is kept honest.

Where this sits in our work

Black Shard runs its vCISO practice on an ongoing monthly retainer: a named lead, a regular cadence, and the deliverables that make a retainer worth its cost, a strategy the business actually follows, a risk register kept honest between sittings, and board reporting a director can read and act on. We do not publish a rate card, for the same reason none of the figures above should be read as a quote: an honest number follows a scoping conversation about your business, not a template. What we do publish is how the engagement runs and what we hold ourselves, SMB1001:2026 Gold, independently issued and verifiable on the public CyberCert registry, and production systems we design, build and operate under obligations we also advise on.

If you are deciding between a retainer and a full-time hire, that decision is worked through against six criteria on its own page. If you want to see whether the shape fits before committing to a cadence, the usual first step is a posture assessment: a gap analysis against the Essential Eight and CIS Controls that gives both sides an honest picture first.

Put a security lead at your table.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a brief[email protected]