# 11. vCISO and Managed Security Services

Share
# 11. vCISO and Managed Security Services

Onward. This is a topic where the market has exploded in the last few years, every consultant with a CISSP now offers "vCISO services," and every MSP has rebranded as "MSSP." Quality varies wildly, and buyers often can't tell the difference between strategic security leadership and someone selling 10 hours a month of advice they got from ChatGPT.


Context: Two related but distinct categories that often get bundled:

  • vCISO (Virtual/Fractional CISO), strategic security leadership delivered as a service. Typically a senior security professional (or firm) acting as your CISO part-time, building strategy, advising the board, managing programs, leading incident response. Used by companies that need CISO-level thinking but can't justify (or afford, or attract) a full-time hire.
  • Managed Security Services, operational delivery of security functions. Spans MDR (covered in Topic 2), managed SIEM, managed firewall, managed vulnerability management, managed compliance, etc. The "we'll run the tools and do the work" model.

The market reality: vCISO has become the new "security consulting" with all the same quality variability. Anyone who's had a senior security title can hang out a vCISO shingle. Some are exceptional and worth their weight in gold; others are rebranded auditors selling templates and policy documents.

For managed security services, the issue is different: vendors compete on price, scope creep is rampant, accountability is fuzzy, and the gap between "we'll monitor your tools" and "we'll keep you secure" is often the gap where breaches happen.

The right question for vCISO isn't "do you have CISO experience?", it's "will you actually move my security program forward, or just produce reports?"

The right question for MSS/MSSP's isn't "do you offer 24/7 monitoring?", it's "what specifically will you do, what won't you do, and where does your responsibility end and mine begin?"


14 Questions to Ask vCISO and Managed Security Service Providers

1. "Who specifically will be my vCISO / primary point of contact, and what's their actual background, time commitment, and accountability to my account?"
Why: This is the most important question in the category. Many firms sell senior names in the proposal and deliver junior staff in execution. The individual matters more than the firm, security leadership is deeply personal.
Good answer: Named individual, contractually committed, with a real bio and verifiable background; their hours, scope, and replacement policy clearly defined. Red flag: "We have a team that supports you" or "we'll match you with the right person at kickoff."

2. "How much of your vCISO's time am I actually getting per month, and how is that time tracked and reported?"
Why: Many vCISO arrangements quote "fractional CISO services" without specifying hours. The reality might be 4 hours/month of an actual senior person and 20 hours of junior staff filling templates. Get specifics.
Good answer: Defined hours per month for the named vCISO + clear delineation of supporting staff time, transparent time reporting. Red flag: "We don't track hours; we deliver outcomes" (good in theory, exploitable in practice).

3. "What outcomes do you contractually commit to, and how is success measured?"
Why: "Strategic advisory" is unmeasurable. Real vCISO engagements should have outcomes: program maturity gains, audit readiness, board reporting cadence, incident response readiness, specific deliverables. If they can't define success, they can't be held accountable.
Good answer: A defined roadmap with milestones, measurable program improvements, named deliverables. Red flag: "We provide ongoing strategic advisory."

4. "What's your methodology, and is it tailored to my industry, size, and risk profile, or is it a template you apply to everyone?"
Why: Many vCISO firms run the same playbook regardless of customer (NIST CSF assessment + policy refresh + tabletop exercise + quarterly reports). That's not strategic, that's a checklist. Mature providers tailor approach to your business.
Good answer: Clear methodology with explicit tailoring points, industry-specific expertise, references in your sector. Red flag: Generic NIST/ISO framework slides as the entire approach.

5. "Walk me through a real engagement where the program improved measurably under your guidance. What was the starting state, what changed, and what's the evidence?"
Why: This is the credibility test. Real vCISOs have stories, programs they took from chaos to maturity, audits they passed, breaches they prevented or contained. If they can't tell those stories with specifics, they don't have them.
Good answer: Specific (sanitized) before/after stories with measurable outcomes. Red flag: Generic claims about "improving security posture."

6. "How do you handle incident response leadership, are you on-call 24/7, or do I need a separate IR retainer when something happens?"
Why: The dirtiest secret in vCISO services: when something actually happens at 2am on a Saturday, many vCISOs aren't reachable, aren't insured for incident leadership, or aren't experienced in actual incident command. Verify this before you need it.
Good answer: Defined on-call coverage, named incident commander, IR retainer or partner, insurance coverage. Red flag: "We'll be available when you need us" with no contractual specifics.

7. "What's your actual technical depth, and where are you out of your depth? Be honest."
Why: The best vCISOs know their limits. Strategic CISOs may not be deeply technical in cloud architecture, AppSec, OT, or specific compliance regimes, and that's fine, if they say so and bring in specialists. Generalists pretending to deep expertise are dangerous.
Good answer: Honest mapping of strengths and gaps, named specialist partners, willingness to bring in deeper expertise when needed. Red flag: "We cover everything in security."

8. "How do you work with my existing IT, engineering, finance, and legal teams, and how do you handle disagreements with leadership?"
Why: CISOs succeed or fail based on organizational politics as much as technical expertise. A vCISO who can't navigate executive relationships, push back on bad decisions, or build coalitions across departments will be ineffective, no matter how technically sound.
Good answer: Stories of organizational influence, board engagement, conflict navigation, executive presence. Red flag: "We work with your IT team to implement security."

9. (For MSS specifically) "Show me the RACI matrix, for every service you offer, what do you do, what do I do, and what falls between us?"
Why: This is the question that prevents future disappointment. Most managed services disputes happen in the gaps, "I thought you were monitoring that" / "I thought you were patching that." Clear RACI in writing, before signing, prevents 90% of these conversations.
Good answer: Written, detailed RACI for every service, with named responsible parties on both sides. Red flag: "We work as an extension of your team" with no specifics.

10. (For MSS) "What are your SLAs, for response, for resolution, for reporting, and what happens when you miss them?"
Why: SLAs without consequences are aspirations. Mature MSPs have credit structures, escalation paths, and root-cause accountability when they fail. Immature ones have SLAs they don't even measure.
Good answer: Tiered SLAs by severity, measured response and resolution times, financial credits for misses, transparent reporting. Red flag: SLAs without consequences or measurement methodology.

11. (For MSS) "What's your staffing model, locations, shifts, certifications, tenure, and customer-to-analyst ratio?"
Why: Same logic as MDR (Topic 2). MSS economics push providers toward junior, offshore, high-ratio models. You're paying for human expertise, verify it exists.
Good answer: Named locations, named tier structure, low analyst:customer ratios, tenure data. Red flag: "We have a global 24/7 team" with no specifics.

12. "What tools do you use, your own, customer-provided, or hybrid? Who owns the tooling, and what happens to my data when I leave?"
Why: MSS providers often run their own tools (their SIEM, their EDR, their ticketing). When you leave, you may lose the historical data, custom rules, and tuning you paid for. Or, worse, you've been paying twice, once for their tools embedded in service fees, once for your own licenses.
Good answer: Clear ownership model, defined data export rights, no double-licensing, transition support. Red flag: "We use our proprietary platform" with no exit story.

13. "How do you scale with me, and how do you handle the moment when I'm ready to bring this capability in-house?"
Why: Every healthy vCISO and MSS engagement should have an end state. Either growing with you, or transitioning to internal capability. Vendors who don't acknowledge this are optimizing for retention, not your maturity.
Good answer: Honest discussion of scaling, in-house transition support, knowledge transfer plans. Red flag: "Our customers stay with us long-term" (true, but is that because they want to or have to?).

14. "What does your own security program look like? Show me your SOC 2 / ISO 27001 / equivalent, and your last security incident."
Why: You're handing them visibility into your security program, your weaknesses, and often your data. Their security maturity matters. A managed security provider with poor internal security is a brand of irony you don't want.
Good answer: Current attestations, transparent incident history, named security leader, customer-accessible audit reports. Red flag: "We're working on SOC 2" or evasion.


🎯 The Meta-Test

For vCISO:

  • Q1, Q2, Q3, and Q5 are the credibility filter. A vCISO who can't give specifics on individual, time, outcomes, and prior wins is selling a brand, not a service.
  • Q6 is the panic-test. When the breach happens, will they actually be there?

For MSS:

  • Q9 and Q10 are the contractual filter. RACI + meaningful SLAs in writing, or walk away.
  • Q11 and Q14 are the trust filter. Who's actually doing the work, and is their own house in order?

💡 Honest Observations

For "regular" companies, this is one of the most leverage-rich categories of security spend, if you pick well. The wrong vCISO or MSSP is worse than nothing (false sense of security + cost). The right one can transform a program in 12 months. Here's what I see:

On vCISO specifically:

  1. Right-size the engagement to your maturity. A startup with 50 employees needs different vCISO support than a 1,000-person regulated company. Don't pay enterprise vCISO rates for startup needs, and don't expect a startup vCISO to navigate enterprise complexity.
  2. The best vCISOs are picky about clients. Top-tier vCISOs decline clients where success is unlikely, bad culture, no executive support, unrealistic expectations. If your prospective vCISO says yes to everything, that itself is a signal.
  3. Independent vCISOs vs. firms, there's no universal right answer. Independent vCISOs offer continuity, deep relationships, and senior expertise, but bus-factor risk and limited bench. Firms offer scale, specialization, and continuity, but often less personal investment. Your size and complexity should drive the choice.
  4. The vCISO trap is "endless advisory." A good vCISO has a finish line, bringing in a full-time CISO, transitioning to internal leadership, completing a defined maturity uplift. A vCISO who's been with you for 5+ years with no transition plan is comfortable, not ambitious for your program.
  5. vCISO ≠ pen tester ≠ compliance auditor. These are different skills. A great auditor often makes a mediocre vCISO and vice versa. Hire for the function you need.

On Managed Security Services specifically:

  1. Most MSSP relationships fail because of unclear ownership, not bad work. The provider monitors; you respond. The provider alerts; you patch. Three months in, both sides are frustrated about what didn't get done. The fix is brutally explicit RACI from day one, and revisiting it quarterly.
  2. Beware the "single throat to choke" pitch. It sounds good ("one vendor for everything") but creates massive lock-in, hides individual service quality, and concentrates risk. Better to have best-of-breed in critical functions and accept some integration overhead.
  3. MSP ≠ MSSP. A traditional MSP (managing your IT) selling "security services" is often just running the same toolset with the same staff and a security label. Real MSSPs have dedicated security operations, security expertise, and security accountability separate from IT operations. If your MSSP is also managing your printers, ask hard questions.
  4. The economics force certain trade-offs. MSSPs need to make money. The only ways to do that are: high analyst-to-customer ratios (you're not getting much attention), automated/junior tier-1 (limited expertise), upsell-driven engagements (scope creep), or premium pricing (transparent and often worth it). Be honest about which trade-off you're accepting.
  5. The exit story matters more than the entry. MSSP transitions are painful, losing tooling, losing tuning, losing institutional knowledge. Plan for it before you sign. Document everything. Maintain ownership of data and configurations. Avoid proprietary platforms unless the value is overwhelming.

The combined view (for "regular" mid-market companies):

The smartest play I see for companies in the 200–2,000 employee range is often:

  • vCISO for strategy and program ownership (8–20 hours/month from a senior practitioner)
  • MDR for detection and response (24/7 coverage, narrow scope, strong RACI)
  • Specialized partners for periodic deep work (pen testing, IR retainer, GRC, awareness training)
  • In-house ownership for IT operations, identity, and patch management (don't outsource what you should control)

What this avoids: the "MSSP does everything" trap that creates dependency and obscures accountability. What this enables: clear ownership, senior expertise where it matters most, and a path to internal capability over time.


Read more