Cybercrime impact on business is real. No business leader should think that their business is immune. But with many providers jumping on the “vCISO” (virtual CISO, Interim CISO, fractional CISO, etc.) bandwagon, it’s hard to discern quality from smoke & mirrors.
But what is a vCISO, and do you need it? Let’s start with basics: WHY it’s needed, WHEN it’s helpful, WHO is the right one, and HOW will they deliver:
Why: Not everyone needs a vCISO. In fact, we hope for a day when every company has a dedicated cybersecurity leader. But that world is far from reality, especially for small and mid-size businesses (SMBs).
All enterprises need help retaining CISOs due to the nature of the role and the job market. In fact, the average CISO tenure is just 18-26 months—much shorter than other C-suite roles. When a CISO leaves, it’s a rush to find a replacement or external support.
When: vCISO leadership is helpful in organizations that can’t justify a full-time leader or experience a leadership transition. vCISO’s also help mature developing programs.
Who: Hiring a vCISO is not like finding a dentist: there aren’t definitive standards for CISOs like in dentistry. Clearly define your needs so you find the right fit. Depth in cyber, proven results, and experience in your industry are all important. Just because a company offers vCISO doesn’t mean they have these attributes.
How: A CISO should be fluent in security, business, and tech. They:
What is NOT a CISO? Fractional leadership is not unique to cyber. It’s used in accounting, finance, and operations (with options for external CXO’s). For cybersecurity, a credible candidate IS NOT:
A good vCISO should be:
At Reveal Risk, we evaluate, design, and deliver strong processes and results in cyber, privacy, and risk that work efficiently, are fit-for-purpose, and are sustained. If you want assistance building your company’s cyber security strategy, governance, and plan towards desired state maturity, please don’t hesitate to contact us at info@revealrisk.com.