What is a vCISO, and does your South African company need one?
Christo Goosen3 min read
A plain-English guide to vCISOs for South African companies: what a vCISO does, how it differs from a full-time CISO, and how it fits with POPIA and ISO 27001.
A vCISO, or virtual (sometimes fractional) chief information security officer, is a senior security leader who works for your company part-time, on a retainer, instead of as a permanent hire. This guide covers what the role involves, when it makes sense for a South African company, and when it does not. If you would rather talk it through, see our vCISO services.
What a vCISO does
A CISO is the person accountable for an organisation’s information security. A vCISO does the same job in fewer days per month. In practice that usually covers:
- Owning the security strategy and a risk register, so risks are named, ranked and assigned rather than living in someone’s head.
- Setting policy, such as acceptable use, access control, incident response and supplier security, sized to your team.
- Overseeing vendor and third-party risk, including the security questionnaires your customers send you.
- Translating technical risk into decisions for your leadership team or board.
- Coordinating the hands-on work: audits, penetration testing, cloud hardening and remediation.
vCISO, fractional CISO and CISO as a service: are they different?
No. They are different names for the same model: senior security leadership without a full-time hire. “vCISO” and “virtual CISO” are the most common terms; some firms say “fractional CISO” or “CISO as a service”. The differences that matter are scope and cadence: whether the engagement is advisory only or includes hands-on work, and how many days per month it covers.
When a vCISO makes sense
- Enterprise customers or investors send security questionnaires you struggle to answer credibly.
- You handle personal information and need to show reasonable safeguards under POPIA.
- You are working toward ISO 27001 or another certification and need someone to drive it.
- You have engineers and security tools, but nobody senior who owns security decisions.
- A full-time CISO is not yet justified by the size of the business or the budget.
When it may not be the right fit
If security is already a daily, full-time job in your company, for example a large security team or a regulated environment with continuous audit demands, a permanent CISO is likely a better fit. A vCISO can still help you define that role and hire for it. Likewise, if you only need a single deliverable such as a penetration test, a one-off engagement is simpler; see penetration testing.
How a vCISO relates to POPIA
The Protection of Personal Information Act (POPIA) does not require you to appoint a CISO. It does require a responsible party to secure the integrity and confidentiality of the personal information it holds by taking appropriate, reasonable technical and organisational measures, and to notify the Information Regulator and the affected people when there are reasonable grounds to believe that personal information has been accessed or acquired by an unauthorised person. A vCISO helps you decide what “reasonable” means for your business and keep the evidence that you are doing it. This is general information, not legal advice; speak to a lawyer about your specific obligations.
How a vCISO relates to ISO 27001
ISO/IEC 27001 is the international standard for an information security management system. A vCISO can run the readiness work, including scoping, risk assessment, policies and controls, and preparing for the audit, but certification itself is awarded by an accredited external certification body. Whether you need certification at all usually comes down to what your customers require.
What a vCISO costs
There is no standard price. Cost depends on the size and complexity of your environment, how many days per month you need, whether compliance remediation is in scope, and whether hands-on work sits alongside the retainer. A good scoping conversation should end with a monthly engagement sized to those factors, not a generic package.
Questions to ask before you hire one
- Who exactly will do the work, and how many days per month are included?
- What will I have in hand after 90 days: a roadmap, policies, a risk register?
- How do you report progress, and to whom?
- What is in scope for hands-on work, and what is billed separately?
- How do you handle conflicts of interest if you also sell testing or tooling?
If you would like to talk it through, book a free consultation, or read more about our vCISO services in South Africa and CISO as a service.
Keep reading
2 min read
Fractional CTO in South Africa: when it works and how engagements run
What a fractional CTO does, when a South African startup or scale-up should use one instead of a full-time hire, and how a typical engagement runs.
Read post7 min read
Building multi-agent workflows with Google ADK and Gemini
How we build multi-agent systems on Google’s Agent Development Kit and Gemini: multimodal input, a fusion router, search grounding, custom skills and evals.
Read postNeed a hand with your own project?
Fractional CTO leadership, CISO services and AI security, from Cape Town to anywhere remote.