Virtual CISO or in-house CISO
Two ways to put a senior person in charge of security: an external service by the day or an executive on the payroll. What changes, and when each makes more sense.
In short
The two often meet: a Virtual CISO supports the IT manager, or sets up policies and documentation before an in-house CISO arrives.
Virtual CISO
- You are an SME and a full-time senior hire is not in the budget.
- You need to start on NIS 2 compliance or ISO 27001 and need someone in charge now.
- You have an IT manager who runs the systems and needs support on policies, risk and priorities.
In-house CISO
- The organisation is large, with many sites, and security needs decisions on site every day.
- Security is part of the product you sell and the team needs a dedicated person.
- You want to build an in-house security team and lead it over time.
Point by point
| Criterion | Virtual CISO | In-house CISO |
|---|---|---|
| Cost | Virtual CISOThe fee of the chosen plan, with no hire | In-house CISOAn executive salary, benefits, training and recruitment |
| Presence in the company | Virtual CISOThe days agreed in the plan, usually remotely by video call | In-house CISOEvery day, on site |
| Knowledge of the company | Virtual CISOBuilt through the initial assessment and periodic reviews | In-house CISODeep and continuous, from the inside |
| Skills | Virtual CISOA professional backed by our team | In-house CISOThose of the person hired |
| Tools | Virtual CISOCyber Console: controls, activities and documentation | In-house CISOTo be chosen and bought separately |
| NIS 2 and ISO 27001 compliance | Virtual CISOControls and audit-ready documents in Cyber Console | In-house CISODepends on the person's experience |
| Continuity | Virtual CISOThe work does not depend on one person and is documented | In-house CISOA resignation or long absence leaves a gap |
| Getting started | Virtual CISOFrom the Cyber Check-up and an initial assessment | In-house CISOAfter recruitment and onboarding |
| Flexibility | Virtual CISODays are sized to needs and budget | In-house CISOA fixed cost |
Getting started with Virtual CISO
-
1
Cyber Check-up
A self-assessment that returns the company's cyber profile and its first priorities.
-
2
Assess
Questionnaires and internal analysis to understand the current state of security.
-
3
Plan
Corrective actions for the risks found, in order of priority, within the days of the chosen plan.
-
4
Periodic reviews
Risks, policies and open actions are updated at every review, in Cyber Console.
Frequently asked questions
No. The IT manager runs systems and operations; the Virtual CISO sets policies, risks and priorities and checks that the agreed measures are applied.
It depends on the plan: days are sized to the company's needs and budget, and can be revised over time.
Yes. The Virtual CISO's work is documented in Cyber Console: whoever arrives starts from policies, a risk register and actions already written.
With the Cyber Check-up: it returns the company's cyber profile and helps work out how many days are needed and on what.
Other comparisons
NIS 2 in house or with Cyber Console
Running NIS 2 on spreadsheets, folders and email or with Cyber Console: answers, history, evidence, activities, documents and audits compared.
Full comparisonThreat Blocker or the firewall's threat intelligence
Threat Blocker and the threat intelligence built into the firewall compared: what they block, compatibility, multiple sites, visibility and when you need both.
Full comparisonNot sure yet which fits you?
The Cyber Check-up returns your company's cyber profile and the priorities to start from.