Fractional CISO vs. full-time hire vs. consultant: an honest comparison
Somebody (a customer, an investor, an auditor, or your own engineering lead at 11pm) has made it clear that your company needs someone to own security. You have three realistic options: hire a full-time security leader, engage a fractional CISO, or bring in a consultant or consultancy for a defined project.
I’m a fractional CISO, so I’m not a neutral party here. I’ll try to earn your trust by being straight about what each option is good at, what each is bad at (including mine), and how to choose based on your situation rather than on whoever’s website you landed on. If you finish this and conclude you need a full-time hire or a project consultant, that’s a good outcome; it means you understood the problem.
The three models, in plain terms
A full-time CISO (or Head of Security) is an executive on your payroll. Fully loaded (salary, bonus, equity, benefits, employer costs), an experienced security executive typically runs $300K–$450K+ CAD per year in the Canadian market, and meaningfully more in the US. They’re present every day, accountable in every meeting, and building a function they’ll lead for years.
A fractional CISO is a senior security leader who works with your company part-time on an ongoing basis (typically two to eight days a month) as an embedded member of your leadership team. The accountability model is the same as a full-time CISO’s, scaled down in hours. Depending on days and seniority, most engagements run roughly $4K–$16K CAD per month. (I’ll publish a detailed piece on pricing structures separately; the short version is that most engagements land somewhere between a sixth and a half of a full-time executive’s fully loaded cost.)
A consultant or consultancy delivers a defined project: a gap assessment, a SOC 2 readiness sprint, a penetration test, an incident response. They bill hourly, daily, or at a fixed fee. They arrive, deliver the artifact, and leave. Rates vary enormously, from $200/hour independents to multiples of that at name-brand firms.
Here’s how they compare at a glance:
| Full-time CISO | Fractional CISO | Consultant | |
|---|---|---|---|
| Cost | $300K–$450K+ CAD/yr fully loaded | ~$4K–$16K CAD/mo | Hourly, daily, or fixed-fee |
| Presence | Daily | 2–8 days/month, ongoing | Duration of the project |
| Accountability | Permanent executive owner | Embedded, ongoing owner | For the deliverable only |
| Best for | Daily security operations; ~150+ people or regulated scale | Seed–Series B needing senior ownership, part-time | Bounded work with an internal owner waiting for it |
| Fails when | Hired too early, or too junior for the title | Daily ops load; practitioner overextended across clients | Nobody owns the results after departure |
The models aren’t interchangeable, and the differences aren’t really about cost. They’re about continuity and accountability.
What each model is genuinely bad at
Every vendor will tell you what their model is good at. The failure modes are more useful.
Full-time hires fail through timing and scope. At seed through Series B, there usually isn’t a full-time executive’s worth of security leadership work. There’s two to six days a month of it. A senior person hired too early spends the rest of their time either drifting into IT management, inventing process nobody asked for, or getting bored and leaving; all three are expensive. The other failure mode is hiring junior to make the salary palatable: a security analyst with a big title who can run tools but can’t scope an audit, negotiate with an enterprise customer’s security team, or tell your board something they don’t want to hear. When the hard questions arrive, nobody senior is actually accountable. You’ve spent real money to still have the original problem.
Consultants fail through departure. A good consultant delivers exactly what was scoped, and that’s the problem: security isn’t a deliverable, it’s an operating property of your company. The gap assessment PDF ages the day it’s delivered. The policies get written and go stale. Six months later a customer questionnaire arrives, the consultant is on another engagement, and nobody in the building owns the answers. Consultants are the right tool for genuinely bounded work (a pen test, an audit, specialized expertise you’ll never need in-house) and the wrong tool for ongoing ownership.
Fractional CISOs fail through absence and overextension. I’m not in your standup. If your business has daily security operations (a SOC to run, an on-call rotation, constant incident load), a few days a month of leadership doesn’t cover it, and a fractional CISO pretending otherwise is doing you harm. The model also breaks when the practitioner takes on too many clients and becomes a distant advisor rather than an embedded leader: you get slideware instead of decisions. And there’s a ceiling: at some point your company genuinely needs a full-time executive, and a fractional arrangement that lingers past that point is holding you back. A good fractional CISO names that moment before you do.
Choosing by situation, not by pitch
Choose a consultant when the work is genuinely bounded and someone in your company can own the results afterward: a penetration test, a one-time assessment, deep expertise for a specific technical problem, or hands-on-keyboard execution against a plan someone else owns. If nobody internal can own the results afterward, you don’t have a project problem. You have a leadership gap, and a project won’t fill it.
Choose a fractional CISO when you need ongoing, senior ownership of security but not forty hours a week of it. The classic profile is seed to Series B, 10–150 people, selling into enterprises or regulated markets, facing SOC 2/ISO/privacy obligations and customer security reviews, with engineers who can implement but nobody who can lead. You need someone accountable in the board deck, credible on the customer call, and present enough to know your actual systems, at your stage’s scale.
Choose a full-time hire when security is operationally daily. Reliable signals: security questions or incidents consume leadership attention most days, not most months; compliance obligations span several concurrent frameworks with continuous audit activity; you’re past ~150–200 employees or post-Series B/C in a regulated vertical; customer security engagement is constant; or you’re building security products where it’s core to the roadmap. At that point the fractional math inverts: you need presence, and presence is the one thing the fractional model structurally can’t offer.
One pattern works well in practice: these models sequence rather than compete. Use a consultant for the bounded technical work, a fractional CISO for the leadership layer through your growth stage, then convert to a full-time hire the fractional leader helps you recruit and onboard, handing over a working program instead of a blank page. That’s the arc I aim for with clients, and being explicit about the ending is, in my view, the difference between an advisor and a squatter.
Four questions that decide which model you need
Strip away the titles and ask:
- Is the work ongoing or bounded? Bounded > consultant. Ongoing > one of the other two.
- How many days a month of senior security leadership does your company actually generate? Be honest. Under ~8 > fractional. Consistently above ~12 > start planning the full-time hire.
- Who answers for security to your board, your customers, and your auditors? If the answer is “our compliance platform” or “our engineers, collectively,” you have no answer. Tools and teams execute; someone senior has to own.
- What happens after the engagement? If a consultant’s deliverable has no internal owner waiting for it, you’re buying a report that goes straight to a shelf. If a fractional engagement has no eventual graduation plan, you’re renting what you should eventually own.
FAQ
Can’t our CTO just own security?
A CTO can, for a while, and many do it admirably. The model breaks on time and on specialization: enterprise security reviews, audit scoping, and regulatory interpretation are their own craft, and every hour your CTO spends becoming mediocre at it is an hour off the product. The CTO should stay accountable for engineering security; the question is who leads the program.
Is a vCISO the same thing as a fractional CISO?
The terms are used interchangeably, but read the engagement model, not the label. Some “vCISO” offerings are productized subscriptions: templated policies, a dashboard, quarterly calls. That’s closer to a compliance service than to leadership. The question to ask any provider: how many clients does the actual named individual carry, and will they be in the room (virtual or otherwise) when our biggest customer’s security team calls?
We just need SOC 2. Isn’t that a consultant project?
Getting the report can be a project. Staying certified, answering the questionnaires that follow, and running the program the auditors examined is permanent. Companies that treat SOC 2 as a one-time project tend to relive the whole scramble every renewal, usually with the audit window already open.
How do we know when we’ve outgrown a fractional CISO?
You’ve outgrown the model when the days-per-month keep climbing quarter over quarter, when response latency starts costing you (decisions waiting on the next scheduled day), or when security work becomes daily rather than periodic. A fractional CISO worth hiring will surface this trend before you do and help run the search for their replacement.