Back to Blog
Security Leadership5 min read

What Does a vCISO Actually Do Day-to-Day?

A virtual CISO isn't a consultant who shows up with a report. Here's what the work actually looks like: onboarding, monthly cadence, deliverables, and what you should have at 30/60/90 days.

There's a version of "vCISO" that's a retainer with no defined deliverables, a monthly call with no agenda, and a relationship that drifts until someone decides it isn't working. That's not a vCISO engagement — that's an expensive advisory subscription.

A well-structured vCISO engagement looks different. There are defined outputs at predictable intervals, a running agenda, and accountability for the security program's direction. Here's what that actually looks like in practice.

The First 30 Days: Getting the Picture

Before a vCISO can advise anything, they need to understand what they're working with. The first month is mostly discovery:

  • Stakeholder interviews: Who owns IT? Who owns risk decisions? What does the board care about? What are the active compliance obligations?
  • Environment assessment: What systems exist, what data do they hold, who has access, what's the current patch posture?
  • Policy and documentation review: What's already written down? Is it current? Is it actually followed?
  • Vendor inventory: Who are the critical vendors? What security requirements exist in contracts?
  • Incident history: What's happened in the past 12-24 months? What was the response?

This isn't theoretical. A vCISO who skips the discovery phase and starts recommending tools in week one is operating on assumptions. The output of month one is a current-state picture and a gap list.

30-day deliverable: Current state summary, prioritized gap list, draft security roadmap.

The Monthly Cadence

After onboarding, a vCISO engagement settles into a rhythm. Typical structure for an 8-16 hours/month engagement:

Monthly advisory meeting (2-3 hours):

A standing meeting with consistent attendees — usually the CEO or COO, the IT lead, and anyone running active compliance projects. A good agenda covers:

  1. Open incidents or security events since last meeting
  2. Status update on active projects (SOC 2 readiness, policy development, vendor reviews)
  3. Upcoming compliance deadlines or audit milestones
  4. New technology or business changes that affect security posture (new SaaS tool, new customer contract with security requirements, hiring)
  5. Any board or investor communication needed
  6. Prioritization decisions for the next 30 days

Between meetings (remaining hours):

The work doesn't stop between calls. Between meetings, a vCISO might be:

  • Reviewing vendor security questionnaires or new customer contracts
  • Drafting or revising policies
  • Providing input on a new tool selection
  • Attending a compliance-related call with an auditor or assessor
  • Reviewing security awareness training completion metrics
  • On an ad hoc call after an incident or near-miss

Quarterly:

A board or executive summary — the kind of security update that leadership can actually use. Not a 40-slide technical deck. Something that communicates current risk posture, active projects, what's changed, and what decisions need to come from leadership.

60 and 90 Days

By day 60, the initial gaps from the discovery phase should have treatment plans. Not all gaps are solved — that's not realistic — but each one has an owner, a timeline, and a defined approach.

By day 90, the security roadmap is operational. There are ongoing projects, not just a list of recommendations. Training has been rolled out or scheduled. The most critical policy gaps have been addressed. A risk register exists and is being maintained.

What you should NOT have at 90 days: A binder of recommendations with no action on any of them. If that's where you are, the engagement structure needs to change.

Deliverables Over the Life of an Engagement

A vCISO engagement that's working produces real deliverables:

  • Security roadmap — 12-18 month plan with projects, owners, and timelines
  • Risk register — documented, rated, with treatment status tracked
  • Policy library — written, approved, and communicated to staff
  • Compliance project plans — SOC 2 readiness timelines, ISO 27001 implementation tracking, HIPAA gap remediation
  • Board reporting — quarterly summaries in executive language
  • Vendor risk assessments — documentation of security reviews for critical vendors
  • Incident response tabletop results — if tabletops were run, findings and action items
  • Security awareness metrics — training completion, phishing simulation results

These aren't extras. They're what the engagement is supposed to produce. If you end a 12-month vCISO engagement and can't point to most of these, something went wrong.

What a vCISO Doesn't Do

A vCISO is not your IT department. They don't configure firewalls, manage your endpoint platform, or staff a 24/7 SOC. That's a different service category.

They also don't run the day-to-day security operations — patching schedules, alert triage, vulnerability scanning remediation. Those activities need owners inside the organization or through a managed service provider.

What a vCISO does is make sure all of those functions have a direction, a governance structure, and a person accountable for outcomes. They're the function that decides what matters, sets the standard, and keeps your security program tied to the business.


SOURCES

  • CISA, "Virtual CISO: Benefits, Limitations, and Hiring Tips": cisa.gov
  • SANS Institute, security leadership resources: sans.org/security-leadership
  • (ISC)², "The 2024 Cybersecurity Workforce Study": isc2.org/research

Evaluating whether a vCISO engagement is right for your organization? Schedule a free consultation to talk through what the engagement would look like for your specific situation.

Jonathan Carpenter
Jonathan Carpenter
Founder, Anchor Cyber Security
Share:

Want to discuss this topic?

Let's talk about how these insights apply to your organization.

Get in Touch