Some companies hire a full-time CISO who embeds security across the business. Others use a vCISO for senior security leadership without adding another full-time executive. For me, authority decides the model. That’s fine when the authority model is clear.

What a CISO Actually Owns When the Trade-Off Gets Expensive

The whole point of the CISO role is to make risk decisions the business can actually act on.

The security team can identify a critical vulnerability, and engineering can estimate the cost of taking a service down to patch it, but somebody still has to decide whether the company carries that exposure for another 24 hours. I want one accountable decision-maker here. That call belongs with an accountable security leader working against a risk threshold the business has already approved.

The CISO’s playbook:

  • Incident Response: Who Makes the Call When the Business Is Under Pressure? When an attack hits, the CISO helps determine whether the company contains the blast radius or spends months cleaning it up.
  • Security Teams and Culture: Who Makes Security Stick Day-to-Day? A CISO shapes internal processes and promotes security awareness across all operational teams.

The CISO as a link:

  • IT and Engineering: Who Can Turn Security Risk Into Engineering Priorities? A CISO builds security into the way engineering, infrastructure, and operations already work.
  • Legal and Regulatory Risk: Who Owns the Reporting Decision? A CISO keeps the security program ahead of the curve on regulatory and legal risk.

A CISO should be able to see continuously whether controls are actually holding up, with evidence coming directly from the operating environment: privileged-access reviews, patch latency, unresolved critical findings, backup restore results, incident response times, exception age, supplier risk, and whether required controls actually ran. I want evidence I can see without asking for a deck.

Gartner’s 2026 cybersecurity trends land in the same place. Its governance theme advises security leaders to formalize collaboration across legal, business, and procurement to establish clear accountability for cyber risk, and it names rapid incident reporting—sometimes within 24 hours—as the pressure that makes the ambiguity expensive.

My test is simple: does the program keep moving when the CISO leaves the room?

Once that authority is clear internally, the next question is what happens when the decision carries regulatory or personal exposure.

Understanding the distinction between internal leadership and fractional advice is especially critical when evaluating legal and regulatory accountability.

Decision dimension Full-time CISO vCISO Key Signal
Cost structure Fixed high salary, benefits, overhead, and staff costs. Flexible leadership cost; scales with needed scope. Weekly volume of executive decisions needed.
Adaptability Deeply embedded in internal systems and engineering flows. Quickly adapts contract scope to new markets or regulations. Whether operational changes require internal context or scope flexibility.
Field of view Deep knowledge of single surface and internal dependencies. Broad cross-industry patterns and immediate access to specialists. Location of primary risks (internal complexity vs. external landscape).
Crisis response Direct access to credentials; coordinates real-time containment. Advisory role unless explicit response rights are contracted. Who holds direct authority to act during an off-hours breach.
Notification authority In-house named executive responsible for regulatory calls. Requires explicit prior written authorization to notify on behalf of the company. Immediate presence of an accountable internal signer.
Speed of impact Slower start: recruitment and onboarding take months. Immediate start: operational within days. Whether urgency lies in discovering risks or implementing fixes.
Independence Navigates internal politics well, but bound by legacy culture. Unbiased external perspective; highlights difficult truths. Need for objective assessment over internal dynamics.
Culture Drives daily habits and integrates security into internal mindset. Establishes policies, but harder to build daily muscle memory remotely. Active cultural change across teams matters.

CISO Liability Has Changed. Accountability Hasn’t.

The personal-liability landscape split along two tracks. In October 2023, the SEC brought the first cybersecurity enforcement action against an individual CISO, naming SolarWinds and Timothy Brown. A district court dismissed most of the claims in July 2024. On 20 November 2025, the SEC dismissed the remaining claims with prejudice, exercising its discretion and without stating a position on any other case. That civil action closed without an individual CISO holding on the SEC enforcement line. The criminal track remains before the Supreme Court. The 2022 conviction of Uber’s former security chief Joseph Sullivan survived a unanimous Ninth Circuit panel on 13 March 2025 and a denial of rehearing en banc on 12 November 2025. On 12 March 2026, Sullivan petitioned the Court (No. 25-1082) to decide whether 18 U.S.C. § 1505 requires a jury instruction on nexus to a pending agency proceeding. Briefing closed in June 2026; the petition is pending.

The market had already priced in the exposure. Gartner predicted that by 2027 two-thirds of Global 100 organizations would extend directors and officers insurance to cybersecurity leaders specifically because of personal legal exposure, and named the SEC disclosure rules as the driver. That is a governance response to the question the boards still have to answer in writing: who signs the notice, and what happens to that person afterward.

Reporting duties kept tightening anyway. US public companies have disclosed material cybersecurity incidents under the SEC cyber rules since December 2023. In the EU, Cyber Resilience Act reporting started on 11 September 2026 for manufacturers placing products with digital elements on the EU market. From that date, an early warning goes to ENISA and the coordinating national CSIRT within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident, with a fuller notification within 72 hours. Filings run through ENISA’s Single Reporting Platform, which opened the same day. A final report follows within 14 days after a corrective measure is available for an exploited vulnerability, or within one month of the 72-hour notification for a severe incident. The remaining product-security duties under the Act apply from 11 December 2027.

CRA starts the clock for product manufacturers. NIS2 starts it for essential and important entities.

The EU pairs the reporting clock with named accountability. Under Article 23 of NIS2, essential entities file an early warning within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within a month. Article 20 puts the obligation to approve and oversee those risk-management measures on the management body itself. Article 32(5) lets member states temporarily bar individuals from managerial functions at essential entities where oversight failure contributed to the incident. The clock and accountability arrive together, which is why the authority question has to be settled in advance.

The ugly case is when the reporting clock starts before anyone knows who owns the call. This is where ownership gets real. Ultimately, the CISO-versus-vCISO decision comes down to authority. Incident notifications require an accountable named individual with the authority to make the call under time pressure. Some vCISO engagements stop at advice, which creates a critical distinction when a regulator expects a decision within hours. Establish these parameters in the contract long before an incident occurs.

Define incident authority in writing early on. The advisor providing incident guidance may not be the person authorized to formally notify a regulator, so explicit contractual rights are necessary before the first incident tests them.

This line between advisory scope and formal decision-making authority is a key benchmark when evaluating a vCISO engagement. While titles may appear similar, operational authority often differs significantly.

To evaluate whether a fractional model meets your strategic needs, look closely at the scope and limits of what a vCISO delivers.

What a vCISO Actually Gives You—and Where the Authority Can Stop

A vCISO can cover much of the same ground, but the authority may stop at advice. Who makes the call? I want the answer in the contract. That is the part the engagement has to answer.

What they do:

  • Security Strategy: Set the Direction Without Adding a Full-Time Executive. They set the security direction and turn it into an operating plan.
  • Risk Management: Find What Needs Attention First. A vCISO finds where risk is piling up and prioritizes what to fix first.
  • Compliance and Governance: Clarify Ownership Before the Clock Starts. A vCISO keeps the organization ahead of industry-specific requirements and prepared for new ones.
  • Incident Response: Advice Is Not the Same as Authority. A vCISO develops, tests, and refines incident response protocols that help teams contain an incident without bringing the business to its knees.
  • Security Training: Build Better Judgment Across the Team. A vCISO designs and delivers security awareness programs that give teams enough security judgment to spot trouble before it snowballs.

The good news is that a strong vCISO engagement can change shape as the risk picture matures. From there, the engagement moves from finding risk to assigning ownership and then into ongoing governance.

That makes the comparison less about title and more about how much of the job needs to be embedded.

vCISO vs. CISO: Which Model Fits the Decisions Your Business Is Making?

Cost

Cost is usually the first comparison, but I wouldn’t decide on salary alone.

  • In-house CISO: Six-figure salary, benefits, support staff, and training add up fast. I’d pay for full-time presence when the decisions are full-time.
  • vCISO: A vCISO gives you senior security leadership without putting another full-time executive on the books, and the level of support can scale up or down as the need changes.

Adaptability

In-house CISO: A CISO lives and breathes your organization — they are fully embedded and deeply familiar with internal workflows and always involved in day-to-day security operations. An internal CISO still operates through the organization’s engineering priorities.

I separate discovery speed from fix speed. A vCISO engagement also scales with the business: entering a new market, absorbing a new regulatory requirement, or expanding the digital footprint changes the contract scope instead of sending the company back to square one on hiring.

That’s one option. A full-time CISO makes sense when security decisions are frequent and deeply tied to internal operations. However, if you need an agile approach, a vCISO may offer greater flexibility.

Flexibility is only half of it. The other half comes from useful context.

Breadth vs. Depth

In-house CISO: You never quite know which undocumented dependency will matter until an incident exposes it. That is where an embedded CISO has an edge. The trade-off is field of view: someone working inside one organization sees one threat surface, and new attack patterns reach them through conferences and vendor briefings rather than through direct experience.

Same story with emerging threats. A vCISO may see the pattern across clients before it reaches your organization. Most vCISO engagements also provide access to a broader team: penetration testers, compliance specialists, incident responders, available without separate hiring.

How to choose: If your biggest risks live inside company-specific systems and processes, depth wins. If it concentrates in a fast-moving external threat and regulatory landscape, breadth wins.

That distinction gets a lot less theoretical during an incident.

Crisis Response

Internal CISO: They coordinate teams in real time to contain the blast radius and keep the damage from spreading.

I use the 2:00 a.m. test. At 2:00 a.m., an identity provider shows signs of compromise. Who has access to the SIEM? Who can turn off credentials? Who can isolate production workloads? Who calls legal? Who decides whether the incident is material? Who starts the regulatory clock? If those answers are fuzzy, the model is fuzzy. So much for executive security leadership if every critical decision still waits on an internal manager.

And even when the authority is clear, response speed still depends on how fast the leader can get inside the environment.

Speed

Internal CISO: Hiring a CISO doesn’t happen overnight; recruiting, interviewing, security vetting, onboarding, and building a full understanding of the environment can take months.

That sounds fine until the first finding depends on six weeks of engineering capacity. I budget the fix, not just the finding. The first week may surface missing incident logging, yet resolving it still depends on engineering capacity. Finding the problem fast and fixing it fast are two different things.

The same is true of judgment. Seeing the issue clearly is not the same as being able to move the organization around it.

Objectivity and Independence

vCISO: A vCISO is less tied to internal politics and “the way we’ve always done it,” which lets them assess risk independently and make recommendations based on the evidence, including the ones nobody wants to pay for.

Fresh eyes help when the same internal answer has stopped moving the problem forward.

How to choose: If your organization needs fresh eyes to unstick changes that have gone nowhere internally, a vCISO provides independent security leadership. If you need someone who understands and can navigate internal dynamics, a full-time CISO may be a better fit.

Internal influence matters even more once the job moves from decisions into behavior. Build a culture focused on security:

  • In-house CISO: A full-time CISO has the advantage of being deeply integrated into your organization’s culture, which makes it easier to lead training, promote security awareness, and make security part of how people work every day.
  • vCISO: While they develop policies, provide high-level guidance, and establish security frameworks, an external vCISO has a harder time making security part of the company’s muscle memory.

At some point, that stops being a limitation you can solve with more contract hours.

When the Fractional Model Stops Being Fractional

I would start reconsidering the fractional model when security decisions become continuous rather than periodic. If the leader spends most days negotiating priorities with engineering, the company may already be paying full-time money for a fractional model. Daily security trade-offs are my signal.

The remit is widening on its own. Gartner expects half of CISOs to be asked to own disaster recovery on top of incident response by 2028, as security programs get rebranded around resilience. Scope creep of that kind is a decision-volume signal before it is a headcount one.

Frequent decisions pull me toward an embedded CISO. Company-specific decisions pull me there even faster.

The irony is, hiring a full-time CISO too early can leave the company paying for executive capacity it rarely uses. A company with only a handful of material security decisions each quarter may need far less than 40 hours of CISO-level decision-making every week, meaning it pays for executive capacity it doesn’t actually use. Executive capacity should match decision volume.

Final Verdict

I’d match the role to the decisions.

If the calls are frequent, company-specific, and need authority inside the business, I lean toward a full-time CISO. If the need is strategic, periodic, and can be scoped cleanly, a vCISO usually makes more sense. Give me the regulations and the current signer. I can usually tell which model fits from there. Give me the regulations that already apply to you — SEC 8-K, NIS2, CRA Article 14 from today — and the current signer. The model follows the clock.