Most companies that approach us do not open with "we need a vCISO." They open differently. A customer sent a security questionnaire nobody can answer. We have discovered we fall under the cybersecurity act. Our insurer wants evidence of our security posture. We have audit findings and no idea where to start. The colleague who somehow held all this together has left.

The common denominator is always the same. Nobody in the company owns security, decides on it, or can defend those decisions to the board and to a regulator.

The textbook answer is to hire a CISO. But a capable full-time security manager costs roughly what two senior developers cost, and in a company of a hundred people they will not have eight hours of work a day. That is the gap a vCISO fills.


What a vCISO means

vCISO stands for virtual Chief Information Security Officer — an external security manager who performs the CISO role part-time. This is not a consultant who visits, writes a report, and disappears. It is someone who owns the direction of your security programme and takes part in the decisions.

The difference from ordinary consulting is where the engagement ends. A consultant answers the question you asked. A vCISO is also accountable for whether you asked the right question.

In the Czech context you will also encounter the term external cybersecurity manager. This is a role explicitly anticipated by the Czech Cybersecurity Act, and for many companies it is the specific reason they start looking for a vCISO in the first place. More on that below.


What a vCISO actually does

The specific scope depends on where a company stands. In practice, six areas recur.

Where we are and where we are going. Assessing the current state, identifying the largest risks, and building a plan with sequencing and deadlines. Not a hundred-page document, but a list you can actually work from.

Decisions about money. Which security investments make sense now and which can wait. This is where a vCISO saves the most, because it prevents buying tools the company cannot operate.

Supplier governance. Selecting and overseeing IT service providers, assessing their security, and setting contractual requirements. For companies with outsourced IT, this is often the most important part of the job.

Compliance. NIS2, the Czech Cybersecurity Act, DORA, ISO 27001, customer requirements. Translating regulation into concrete controls and evidencing that they are in place.

Incident response. Preparing procedures in advance and leading the company through the moment something happens, including external communication and regulatory notification where required.

Communicating with leadership. A regular, plain-language view of what risks the business is carrying and what is being done about them, tied to business impact rather than technical detail.


How much time it takes

The common assumption is that a vCISO means a couple of hours a month. Reality differs, and it depends on the phase.

Ramp-up typically means two to four days a month for three to six months. The environment has to be mapped, the people understood, a plan built, and the first measures started.

Steady state then settles somewhere between one and three days a month: regular reviews, handling what comes up, audit preparation, and reporting to leadership.

Spikes such as an incident, an audit, or certification preparation need more, and it pays to plan for that in advance.

A fifty-person company with a simple environment manages on one day a month. A three-hundred-person company with in-house development and regulatory exposure needs closer to three or four.


When a vCISO makes sense

Several situations give an unambiguous answer.

You fall under cybersecurity regulation. The Czech Cybersecurity Act (Act No. 264/2025 Coll.), which transposes NIS2, requires a designated cybersecurity manager. The role can be filled externally, and for most companies that is the only realistic route, because qualified people are not available on the market and cannot be developed internally in a month.

You have IT but no security function. An IT administrator keeps things running. A security manager decides which risks the business accepts. These are different roles with different incentives, and merging them into one person creates a conflict — you cannot reasonably ask someone to audit their own work.

You are growing faster than you can secure. Customers, systems, and people are being added. Decisions made now will either pay off in two years or be expensive to unwind.

Customers have started asking. Security questionnaires, certification requirements, customer audits. When these arrive and nobody can handle them, they start blocking deals.

You have audit or pentest results and no starting point. Producing findings is easy. Driving remediation is hard. A vCISO turns fifty recommendations into a sequenced plan.

The person who held it together has left. Someone was handling security informally on top of their real job, and the knowledge walked out with them.


When you do not need one

This deserves an honest answer, because not every company does.

You do not have the basics. If you lack backups, multi-factor authentication, or any picture of who has access to what, you do not need a strategy. You need to implement fundamentals. A good IT partner will do that, and more cheaply. Come back to a vCISO once the basics are in place.

You want a one-off deliverable. If you need a specific system assessed, an application tested, or a report produced for a customer, that is a job for an assessment or a pentest, not an ongoing role.

You already have a functioning internal CISO. Then consulting on topics they lack capacity for may help, but the role itself is redundant.

You want a rubber stamp. If the goal is a name on paper for an audit and nobody intends to act on the recommendations, this will not work. You will get an expensive document and the same risk you started with.


What goes wrong most often

Three patterns recur.

A vCISO without authority. An external manager with no access to leadership and no ability to get anything approved is just a more expensive consultant. The role needs a mandate and a direct line to someone who decides.

Unrealistic expectations of scope. One day a month cannot cover strategy, hands-on technical work, and tool administration simultaneously. If technical implementation is also needed, that means either more time or another person.

No internal owner. A vCISO designs and directs, but implementation is usually carried out by internal staff or a supplier. Without someone inside moving things forward between meetings, the plan stalls.


How to recognise a good one

A few questions worth asking during selection.

Do they ask about your business, or go straight to technology? A good vCISO wants to know how the company makes money and what would sink it.

Can they tell you what not to do? Anyone who recommends everything is not helping you prioritise.

What does their output look like? Ask for a sample board report. If you cannot follow it, it will not work for you either.

Who will actually do the work? At larger firms, a senior sells and a junior delivers.

What happens during an incident? A response time measured in days is not adequate for this role.


What it costs

Czech market rates sit roughly between CZK 15,000 and 30,000 per day depending on seniority and scope. At a steady state of one to three days a month, the annual cost lands somewhere around CZK 200,000 to 900,000.

For comparison, a senior in-house CISO costs roughly CZK 1.8 to 3 million a year including employer contributions. On top of that, you have to find one, which on the Czech market takes months.

The deciding factor is not the price, though. It is whether the company can make use of the role. The most expensive vCISO is the one whose recommendations nobody implements.


Where to start

Before you start looking, answer three questions.

Who decides on security here today? If the answer is nobody, or the IT administrator in passing, you have your first reason.

Are we in scope of regulation? If you are not sure, find out. The answer determines whether a vCISO is a choice or an obligation.

Do we have someone to implement? If not, solve that first. Strategy without execution is just a document.


If you are unsure whether a vCISO is what you need, we are happy to talk it through — including reaching the conclusion that something else would serve you better.

Start a Consultation →

External Cybersecurity Manager and vCISO →

The initial consultation is free and comes with no obligation. We respond within 24 hours.