Virtual CISO or in-house CISO

Two ways to put a senior person in charge of security: an external service by the day or an executive on the payroll. What changes, and when each makes more sense.

In short

The two often meet: a Virtual CISO supports the IT manager, or sets up policies and documentation before an in-house CISO arrives.

Virtual CISO

Makes sense when:

  • You are an SME and a full-time senior hire is not in the budget.
  • You need to start on NIS 2 compliance or ISO 27001 and need someone in charge now.
  • You have an IT manager who runs the systems and needs support on policies, risk and priorities.

In-house CISO

Makes sense when:

  • The organisation is large, with many sites, and security needs decisions on site every day.
  • Security is part of the product you sell and the team needs a dedicated person.
  • You want to build an in-house security team and lead it over time.

Point by point

Comparison checked on 1 October 2026.
Cost Virtual CISOThe fee of the chosen plan, with no hire In-house CISOAn executive salary, benefits, training and recruitment
Presence in the company Virtual CISOThe days agreed in the plan, usually remotely by video call In-house CISOEvery day, on site
Knowledge of the company Virtual CISOBuilt through the initial assessment and periodic reviews In-house CISODeep and continuous, from the inside
Skills Virtual CISOA professional backed by our team In-house CISOThose of the person hired
Tools Virtual CISOCyber Console: controls, activities and documentation In-house CISOTo be chosen and bought separately
NIS 2 and ISO 27001 compliance Virtual CISOControls and audit-ready documents in Cyber Console In-house CISODepends on the person's experience
Continuity Virtual CISOThe work does not depend on one person and is documented In-house CISOA resignation or long absence leaves a gap
Getting started Virtual CISOFrom the Cyber Check-up and an initial assessment In-house CISOAfter recruitment and onboarding
Flexibility Virtual CISODays are sized to needs and budget In-house CISOA fixed cost

Getting started with Virtual CISO

  1. 1

    Cyber Check-up

    A self-assessment that returns the company's cyber profile and its first priorities.

  2. 2

    Assess

    Questionnaires and internal analysis to understand the current state of security.

  3. 3

    Plan

    Corrective actions for the risks found, in order of priority, within the days of the chosen plan.

  4. 4

    Periodic reviews

    Risks, policies and open actions are updated at every review, in Cyber Console.

Frequently asked questions

No. The IT manager runs systems and operations; the Virtual CISO sets policies, risks and priorities and checks that the agreed measures are applied.

It depends on the plan: days are sized to the company's needs and budget, and can be revised over time.

Yes. The Virtual CISO's work is documented in Cyber Console: whoever arrives starts from policies, a risk register and actions already written.

With the Cyber Check-up: it returns the company's cyber profile and helps work out how many days are needed and on what.

Not sure yet which fits you?

The Cyber Check-up returns your company's cyber profile and the priorities to start from.