All articles

Virtual CISO

10 Questions to Ask Before You Hire a vCISO — And the Answers That Should End the Meeting

Ten questions that separate a real vCISO from a templated invoice — and the red-flag answers to listen for. A vendor-neutral buyer's guide for SMB and mid-market boards.

Sylvio Sorel··7 min read·Updated 20 September 2026
Two executives reviewing a document together at a meeting table — the considered evaluation a vCISO hire deserves.

A virtual CISO — a fractional, senior security leader you retain instead of hiring full-time — is one of the better deals available to a mid-market company in 2026. Done well, it puts CISO-grade judgement in your board pack for a fraction of the €150,000–300,000 a full-time hire costs once you count salary, benefits and recruiting. Done badly, it puts a templated policy library and a recurring invoice between you and a real security programme. The trouble is that both look identical in the proposal: the same logos, the same frameworks, the same confident language.

The difference shows up in conversation. The market has filled, fast, with providers calling themselves vCISOs — some are former CISOs of regulated companies, some are analysts who relabelled a consulting offer. The ten questions below are designed to tell them apart. We provide this service, so treat that as a disclosure, not a pitch: point every one of these questions at us too, and walk away from anyone — us included — who answers them the way we flag below.

What good looks like, in three groups

The questions sort into the only three things you actually need to establish: whether the person has truly done the job, whether they fit your company rather than a generic one, and whether the engagement is built around your outcomes or their recurring revenue.

Ten questions, sorted into the three things they reveal Ten questions, sorted into the three things they actually reveal: track record, fit, and how the engagement ends.

Group 1 — Track record and accountability

1. Have you actually owned a security programme — with budget and regulator exposure — or only advised on one? There is a wide gap between someone who has carried the accountability for a programme and someone who has consulted around the edges of one. Owning a programme means having signed off a risk acceptance you were nervous about, defended a budget to a sceptical CFO, and been the name on the line when something went wrong. Red flag: an answer that slides immediately into frameworks and certifications without a single first-person decision.

2. Walk me through the worst incident you personally managed. You are listening for the texture of a real night: what they knew at hour one versus hour six, what they decided with incomplete information, who they called, what they got wrong. Red flag: a tidy, sanitised story with no mistakes in it. Anyone who has run a serious incident has a scar; the polished version means they watched, they didn’t lead.

3. Show me a board report you have written. A vCISO’s core deliverable to you is translation — turning “unpatched edge device” into “this is the risk to revenue and to the directors personally.” Ask for a redacted sample before you sign. A good one will have it ready. Red flag: no sample, or a report that is a wall of CVEs and tool dashboards with no business framing. If you would be uncomfortable putting this person in front of your board, the conversation is already over.

Group 2 — Fit for your size, sector and stack

4. Name three clients your size, in or near our sector — and tell me what month one looked like. A vCISO who has only operated inside large enterprises often struggles with the resource reality of a 120-person company, where there is no security team to delegate to and the “IT department” is two people. Conversely, someone steeped in your sector already knows its threat model and its regulators. Red flag: every reference is a household-name enterprise, or they cannot describe a concrete first month.

5. What in our regulatory landscape would worry you most? For most of our clients across France, Belgium, Luxembourg and Switzerland, the honest answer touches NIS2, DORA or GDPR — and increasingly all three at once. A capable vCISO will name the specific obligation that bites first for a company like yours, not recite an acronym list. This is also the reason the role now sits on the board’s agenda rather than IT’s: NIS2 puts cybersecurity accountability at management-body level, which is exactly the territory our NIS2 readiness work is built around. Red flag: generic “we’ll do a gap assessment” with no view on what actually applies to you.

6. What is your position on AI governance? In 2026 this is the fastest tell in the conversation. Your staff are already pasting company data into AI tools, your vendors are quietly adding AI features, and the EU AI Act and ISO 42001 are now part of the governance map. The tell is whether they know which parts already bite. The Article 4 AI literacy duty has applied since February 2025 — softened by the Digital Omnibus into a duty to take measures rather than to guarantee a result, but not removed. The Article 50 transparency duties — disclosing that a chatbot is a bot — applied from 2 August 2026 and were not deferred. The machine-readable marking of synthetic content was, but only for systems already on the market before that date, and only until 2 December 2026 — the nearest deadline in the Act, shared with two new Article 5 prohibitions that sit in the maximum penalty band. The Omnibus itself — Regulation (EU) 2026/1744, in force since 27 July 2026 — moved the high-risk regime to December 2027 for standalone Annex III systems and August 2028 for AI embedded in regulated products. A current vCISO can tell you which of those touches you and which does not, which is the work our AI Governance & Security service is built around. Red flag: “we don’t really cover AI yet.” That is not a gap in their offer; it is a statement about how current they are.

7. Which tools would you have us buy — and do you resell, or earn commission on, any of them? This is the single most important independence test. A genuine vCISO gives vendor-neutral advice and is comfortable telling you to buy nothing this quarter. Red flag: every problem resolves to a product they happen to sell or partner on. At that point you are not buying a strategic leader, you are buying a salesperson with a better title.

Group 3 — How the engagement actually runs, and ends

8. Who, by name, is my actual operator — and what happens if they leave? Proposals are written by the most senior person in the room. Delivery is sometimes handed to someone far more junior. Get the named individual, their availability for the 4 p.m. emergency that won’t wait for your scheduled hours, and the continuity plan if they move on. Red flag: a vague “our team” with no name attached.

9. What is the review cadence — and how do I leave? A healthy engagement has a quarterly check-in where both sides explicitly ask whether it is still working, and a clean exit clause. Red flag: an auto-renewing contract with no scheduled review. That structure optimises for their revenue continuity, not your security outcomes.

10. When will we outgrow you, and how does the handoff to a full-time hire work? This is the question almost no buyer asks, and the one that reveals the most. A vCISO genuinely working for you can describe the day you no longer need them — usually when your maturity, headcount or risk profile justifies a full-time CISO — and how they would hand over cleanly. Red flag: discomfort, deflection, or the implication that you will need them forever. The same instinct shows up in healthy boundaries elsewhere: a good provider will also tell you when a one-off internal audit or a short project is all you actually need, rather than a retainer.

The one answer that should end the meeting

If you remember nothing else: the disqualifiers are not about credentials, they are about incentives. A provider who cannot show you a board report, whose every recommendation is a product they sell, or who cannot describe how the engagement ends, has told you who they are optimising for — and it is not you. Those three answers should end the meeting regardless of how impressive the logos on the first slide were.

Everything else is recoverable. A slightly thin sector record can be offset by a strong operator and the right references. A modest tool stack is fine. But independence, accountability and a clean exit are not negotiable, because they are the difference between security leadership and a recurring invoice.

If you are weighing up the decision and want a frank, vendor-neutral conversation — including an honest read on whether you need a vCISO at all yet — that is exactly what our Virtual CISO service is built to provide. Ask us all ten questions. We would rather you did. And if the answers hold up, the next thing to ask any provider for is the delivery timeline itself — what should land on your desk at month 1, month 3 and month 12, and the question to ask at each one.

The red-flag scorecard Take this into the meeting: the green-flag answer and the red-flag answer for each disqualifier.

Sylvio Sorel

CISSP, PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor — founder, Cyber-Management.

Take the next step

Talk to a security practitioner, not a salesperson.

Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.