$ cat blog/how-to-evaluate-a-vciso
Back to Blog
Security Leadership7 min read

How to Evaluate a vCISO: Red Flags and Green Flags

Not all vCISO engagements are equal. Here's what to look for in the first conversation, the questions that separate good candidates from expensive ones, and the warning signs to walk away from.

The vCISO market ranges from seasoned security executives who've built programs at multiple organizations to consultants with a certification and a Calendly link. The price range doesn't always track the quality. Here's how to tell the difference before you sign a contract.

What You're Actually Evaluating

A vCISO engagement is a leadership relationship, not a vendor transaction. You're evaluating whether this person can:

  1. Understand your business quickly enough to give relevant advice
  2. Build and maintain a security program that reflects your actual risk, not a generic template
  3. Communicate security to executives and boards in terms they can act on
  4. Be accountable for outcomes, not just recommendations

That last point separates a vCISO from a consultant. A consultant delivers a report. A vCISO owns the program's direction. The evaluation should test for ownership, not just knowledge.

Green Flags

They ask about your business before your tech stack.

The first conversation should cover what you do, who your customers are, what your regulatory obligations are, and what security outcomes matter most to your leadership. A vCISO who leads with "what's your EDR solution?" before they understand your business model is operating on a template, not on your situation.

They describe specific deliverables at 30, 60, and 90 days.

Ask directly: what will we have at the end of the first month that we don't have today? A good vCISO can answer this specifically — current state assessment, gap list, draft risk register, initial roadmap. "We'll figure that out together" is not an answer.

Their experience matches your needs.

HIPAA compliance for a medical practice requires different knowledge than SOC 2 readiness for a SaaS company. Ask whether they've done your specific framework before and what that engagement produced. Relevant experience accelerates everything — irrelevant experience produces generic work.

They're honest about capacity.

Ask how many clients they currently serve. Ask what the typical hours per month per client looks like. A vCISO juggling 20 clients at 2 hours per month each isn't leading anyone's security program — they're providing a subscription with a quarterly check-in.

They've built programs, not just audited them.

There's a meaningful difference between a practitioner who has built a security program from scratch and an auditor who evaluates them. Both have valuable skills, but they're different skills. If you're building a program, you want someone who's done that before — who knows what "done" looks like from the inside, not just against a checklist.

They can describe their communication cadence without prompting.

How often do you meet? Who attends? What does a typical agenda look like? How do you handle urgent issues between meetings? A vCISO who can't describe their working model in concrete terms is going to produce an unstructured engagement.

Red Flags

Vague deliverables.

"Ongoing advisory support" with no defined outputs is a retainer with no accountability structure. Any legitimate engagement scope defines what you'll receive, when, and what success looks like. If a vCISO resists defining deliverables, that's the entire engagement described in one sentence.

The answer to every question is their platform.

Some vCISO offerings are GRC software with a human attached. If the proposal centers on a tool — "our platform tracks your compliance posture, generates reports, and assigns tasks" — you should ask whether the value is the person or the software subscription. Know which one you're actually buying.

Credentials without practitioner experience.

CISSP and CISM are meaningful credentials that require experience and ongoing education. They're not sufficient on their own. An auditor who spent 15 years reviewing other people's security programs has different skills than someone who built them. Ask specifically: describe a security program you built from scratch. If they can't tell that story, they're better positioned as an assessor than a vCISO.

No conflict check.

Does the vCISO receive referral fees or commissions from vendors they recommend? Do they have relationships with specific MSSPs, tool vendors, or training providers? This isn't automatically disqualifying, but it should be disclosed and considered. A vCISO who profits from recommending specific tools has a structural incentive you should be aware of.

Lowball pricing.

A vCISO engagement priced at $500-$1,500/month is almost never what the name implies. At that price point, you're receiving a compliance checklist tool, a periodic template review, or a very junior consultant. Fractional security leadership — real strategic guidance — takes real hours from someone with real experience. The math doesn't work below a certain price.

Resistance to a defined engagement scope.

Any working relationship should have a document that defines: what's in scope, what deliverables are expected, what the communication cadence looks like, what hours are included, how the engagement ends, and what the termination process is. A vCISO who resists this structure — preferring to "keep it flexible" — is describing an engagement with no accountability.

Questions to Ask in the First Meeting

You need straight answers to all of these before you sign anything:

1. What will we have at 30, 60, and 90 days that we don't have today?

Listen for specifics. "A current state assessment and a prioritized gap list" is a real answer. "A better security posture" is not.

2. How many clients do you currently serve, and what's your average monthly time commitment per client?

There's no universally right number, but you're evaluating whether they have capacity to actually do the work. A solo practitioner with 15 clients at 10 hours each is at 150 hours/month before your engagement starts.

3. Have you completed [your specific framework] before? Can you walk me through that engagement?

For SOC 2: what was the scope, what was the timeline, what was their role in the readiness vs. the audit itself? For HIPAA: have they done risk analyses, built BAA programs, supported breach notification?

4. What happens during an incident?

Are they available for incident response support, or does that require a separate engagement? What's their actual availability (not just "I'm always reachable")? Have they managed a real incident before?

5. Can I speak with a current or former client at a similar stage or in a similar industry?

References should exist. If a vCISO can't provide any, or can only provide references with non-disclosure agreements, that's worth understanding before you proceed.

6. How do you handle it when you and leadership disagree on a security decision?

The answer tells you whether they're a partner or a yes-man. Good security leaders push back, document the disagreement and the decision, and stay engaged regardless of the outcome. A vCISO who either folds immediately or describes scorched-earth confrontation is telling you something important.

The Scope Document

Before any engagement starts, there should be a written scope document. Not a statement of work written entirely in contractor-favorable language — a document that describes, specifically:

  • What services are included (advisory, policy development, board reporting, compliance oversight — or some subset)
  • How many hours per month are included
  • What deliverables are expected and when
  • Communication expectations (response time, meeting cadence)
  • What's out of scope
  • How the engagement ends

If a prospective vCISO resists this conversation, you've learned something useful before you've paid anything.


Evaluating vCISO candidates or want to understand what a well-structured engagement looks like? Schedule a consultation to talk through what you should be looking for based on your organization's specific situation.

Jonathan Carpenter
Jonathan Carpenter
Founder, Anchor Cyber Security
Share:

Want to discuss this topic?

Let's talk about how these insights apply to your organization.

Get in Touch