What a CISO is responsible for
A chief information security officer (CISO) leads an organization's cybersecurity program: setting direction, making sure risks are understood and managed, and reporting to executives and the board. Titles and reporting lines vary, so it helps to describe the job by outcomes rather than by title.
NIST's Cybersecurity Framework (CSF) 2.0, published February 26, 2024, added a Govern function that describes those outcomes. Govern covers how an organization's cybersecurity risk management strategy, expectations and policy are established, communicated and monitored. Its six categories map closely to CISO work:
| Category | What it covers | Typical CISO work |
|---|---|---|
| Organizational Context (GV.OC) | Mission, stakeholder expectations, dependencies, and legal, regulatory and contractual requirements | Mapping which laws, contracts and customers shape security decisions |
| Risk Management Strategy (GV.RM) | Priorities, constraints, risk tolerance and appetite, and assumptions | Agreeing risk appetite with leadership and a consistent way to rank risks |
| Roles, Responsibilities, and Authorities (GV.RR) | Cybersecurity roles, responsibilities and authorities that support accountability | Defining who owns which controls and decisions |
| Policy (GV.PO) | Cybersecurity policy that is established, communicated and enforced | Writing, approving and updating policies people follow |
| Oversight (GV.OV) | Using the results of risk management to inform and adjust strategy | Reporting metrics and progress, and adjusting the roadmap |
| Cybersecurity Supply Chain Risk Management (GV.SC) | Managing cyber supply chain risk with stakeholders | Setting security expectations for vendors and reviewing them |
Beyond Govern
The other five Functions (Identify, Protect, Detect, Respond and Recover) describe the outcomes a security program produces. A CISO, full-time or virtual, makes sure those outcomes are prioritized, resourced and reported on, even when other teams do the hands-on work.
What a virtual or fractional CISO does
A virtual CISO (vCISO) is an outside security leader who does the strategic part of the CISO job part-time. You'll also see the role called a fractional CISO or CISO as a service. The idea is the same: security leadership for part of the week, instead of a full-time executive hire.
A typical engagement runs on a monthly rhythm that covers:
- Roadmap: a prioritized plan tied to your risks and commitments, revisited as they change
- Governance: roles, decision rights and a regular security review with leadership
- Policy: a policy set your team can follow, reviewed and updated as requirements change
- Metrics: a small set of measures that show whether risk is going down
- Reporting: plain-language updates for executives and the board
- Third parties: helping answer customer security questionnaires and setting expectations for vendors
What a vCISO leaves to others
A vCISO usually doesn't run daily operations. Monitoring alerts, patching systems and administering security tools stay with your IT team, a managed service provider or a security operations provider. The vCISO sets priorities for that work and checks the results.
vCISO vs full-time CISO: what stays with your leadership
Hiring an advisor doesn't hand over accountability. CSF 2.0 places that accountability with leadership: “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving” (GV.RR-01). That holds whether the security leader is a full-time employee or an outside advisor.
In practice, these decisions stay inside your organization, whoever advises on them:
- Risk appetite, and any decision to accept a risk rather than fix it
- Budget and headcount for security
- Corporate officer roles and the authority that comes with them
- Signing management assertions, attestations and security questionnaires on the organization's behalf
- Approving policies and the exceptions to them
Leaders drive the culture
CISA's Cyber Essentials, written for leaders of small businesses and small and local government agencies, makes the same point from another angle. It treats the leader as an essential element of a culture of cyber readiness, whose job is to drive cybersecurity strategy, investment and culture. A vCISO can shape that agenda, but leadership has to own it.
Signs a vCISO fits
A vCISO tends to fit startups and growing companies that need security leadership but not a full-time executive. Common signals:
- Customers are sending security questionnaires or asking for a SOC 2 report, and no one owns the answers
- You're preparing for a first compliance milestone, such as SOC 2 readiness or a HIPAA risk analysis, and need a plan
- Your IT lead or managed service provider runs operations well but isn't positioned to set strategy or brief the board
- Security work happens in bursts around deals and customer reviews, then stalls
- You need a policy set, a risk register and a roadmap before you can justify a full-time hire
Starting points for smaller organizations
NIST's CSF 2.0 Small Business Quick-Start Guide (SP 1300) is written for small and medium-sized businesses with modest or no cybersecurity plans. Reading it is a quick way to see how much governance work a vCISO would take on, and which parts your team could handle with guidance.
Signs it's time for a full-time CISO
The case for a full-time CISO grows as security decisions become daily rather than monthly. Signals worth taking seriously:
- Security questions come up every day in product, engineering and sales, and waiting for the next advisory session slows decisions down
- You now have a security team that needs a dedicated leader to hire, develop and manage people
- Several frameworks, regulators or large customers expect an accountable security executive who is available whenever needed
- The board wants a security executive present for every meeting and every significant incident
- Your risk profile has changed: more sensitive data, more critical services or a larger attack surface
Making the transition
Moving to a full-time CISO doesn't have to be abrupt. A vCISO can cover the search period, help define the role, and hand over the roadmap, policies, risk register and metrics as the new hire's starting point.
Working with IT, MSPs and auditors
A vCISO sits between leadership and the people doing the work. With internal IT and a managed service provider, the vCISO sets priorities and checks results while they run the systems. With a managed security provider, the vCISO helps define what should be monitored and how incidents are escalated.
Auditors and assessors are a different relationship. An advisor who helps design and run your controls shouldn't be the party that independently examines or certifies them. Choose the examiner or certification body yourself, and keep the roles separate. A vCISO can prepare you, coordinate evidence and help answer the assessor's questions, but the opinion or certificate has to come from someone independent of the work.
Measuring the engagement
Judge a vCISO engagement by outcomes, not hours. CSF 2.0 helps here: a Current Profile describes the outcomes you achieve today, and a Target Profile describes the outcomes you've chosen to reach. Progress between the two is the clearest measure of the engagement. Useful measures include:
- The roadmap: which items are done, in progress or blocked, and why
- Top risks: whether each is trending down, with owners and dates
- Policy coverage: which policies are approved, reviewed on schedule and followed
- Customer assurance: how quickly and consistently security questionnaires get answered
- Readiness: progress against the framework milestones you committed to
Continuous improvement
CSF 2.0's Improvement category (ID.IM) is a useful lens for the long run: improvements are identified from evaluations, from security tests and exercises, and from running day-to-day processes. A vCISO should turn each of those into roadmap items with owners.
Questions to ask before hiring a vCISO
Before you sign an engagement, ask each candidate:
- What will the monthly rhythm look like, and who on our side needs to attend?
- Which decisions will you make, and which will you only recommend?
- How will you measure progress, and what will we see after the first quarter?
- How will you work with our IT team or managed service provider?
- Will you help us answer customer questionnaires and prepare for SOC 2 or other frameworks?
- If we later need an independent assessment, how will you keep advisory work separate from it?
- How will you hand over if we hire a full-time CISO?