All articles

Virtual CISO

The Brain, the Hands, and the Specialist: A Buyer's Guide to vCISO vs. MSSP vs. Consultant

SMBs under €50M are really choosing between three things: a leader, an operator, and a specialist. How to tell a vCISO, an MSSP and a consultant apart.

Sylvio Sorel··6 min read
Three professionals in an office comparing documents held in separate folders — the three-way choice this guide is about.

Three sales calls, three confident pitches, three quotes that don’t compare on a single line. One firm offers a “virtual CISO.” Another sells “managed detection and response.” A third proposes a fixed-scope “security assessment.” They sound like competitors bidding for the same job. They are not. They are answers to three different questions, and the most expensive mistake an SMB makes is buying one while believing it has bought another.

You are not choosing a vendor. You are choosing who owns the problem — the strategy, the daily operations, or a single hard task. In our engagements the recurring pattern is a company that has bought an operator, feels protected, and only discovers at audit or after an incident that nobody was actually accountable for security. This guide separates the three, prices them honestly, and gives you a test you can run before you sign anything.

Three roles, three different jobs

A Virtual CISO (vCISO) is a leader. A senior security executive engaged part-time, they set the strategy, build the programme, own compliance, and report to your board — the same remit as a full-time Chief Information Security Officer, without the full-time salary. Our Virtual CISO service exists precisely for organisations that need that seniority but can’t justify a permanent hire.

A Managed Security Service Provider (MSSP) is an operator. It runs the day-to-day controls: 24/7 monitoring, threat detection, alerting, and often incident response, delivered remotely as a subscription. An MSSP watches your systems. It does not decide your priorities.

A security consultant is a specialist. You bring one in for a defined, time-boxed problem — a penetration test, an ISO 27001 gap assessment, a data-protection impact assessment — and when the report lands, the engagement ends.

The cleanest way to hold the distinction: the vCISO is the brain, the MSSP is the hands, and the consultant is the specialist you call for one procedure. You can have all three. You cannot substitute one for another.

vCISO, MSSP and consultant compared vCISO, MSSP and consultant compared across the six things that actually decide the choice.

What each one actually costs

Price is where the three finally become comparable — as long as you compare what you’re paying for, not just the monthly figure.

Model Typical EU cost What you’re paying for
Full-time CISO €150,000–300,000 / year, all-in A permanent executive — if you can find and keep one
Virtual CISO €2,500–8,500 / month Fractional senior leadership: strategy, compliance, board reporting
MSSP €2,000–5,000 / month 24/7 monitoring, detection and response for a 10–50-person firm
Security consultant €1,000–2,000 / day, per project One bounded problem solved, then handed back

A permanent CISO is the benchmark SMBs under €50M in our engagements quietly rule out: on our own engagement benchmarks the all-in cost lands between €150,000 and €300,000 a year once bonus, pension and benefits are counted on top of salary. A vCISO delivers the same seniority for a fraction of that. An MSSP is priced by users or endpoints, so its cost scales with your size. A consultant is a capital expense, not a running one. One caution on MSSP quotes: confirm whether incident response is included or billed hourly — paying by the hour during a live breach is the worst possible moment to discover a gap in the contract.

Only one of them can answer to your board

Here is the distinction that cost tables miss. Where NIS2 is in force, cybersecurity is no longer something a company can fully outsource and forget. Article 20 makes the management body responsible for approving the organisation’s cybersecurity risk-management measures, overseeing their implementation, and answering for the entity’s failures to meet Article 21. Article 21 sets out the measures themselves. The sharpest end sits elsewhere: under Article 32, and for essential entities only, a regulator that has set a remediation deadline and watched it pass can ask the competent body or court to temporarily bar a chief executive or legal representative from managerial functions in that entity. Transposition is uneven: Belgium has been live since October 2024, Germany’s law entered into force on 6 December 2025 and Luxembourg transposed by the law of 5 May 2026 — while France, as of 20 September 2026, still has not — which is why the Commission referred it to the Court of Justice on 8 July 2026. Where the national law has landed, the obligations are already being tested: since 18 April 2026 Belgian essential entities have had to be able to demonstrate that they are implementing risk-management measures, by one of three routes — CyberFundamentals verification, ISO 27001 with full certification due by April 2027, or a self-assessment plus a request for inspection. Where the law hasn’t landed, the reprieve is on the calendar, not on the obligation.

An MSSP contract does not transfer that accountability. A consultant who has delivered a report and left cannot carry it. Monitoring is not leadership, and a subscription is not a named owner. The only model that gives your board an accountable security leader — someone who can stand in front of directors and account for the programme — is a CISO, whether full-time or virtual. If your organisation is in scope for NIS2 compliance, this is the single most important line in this article.

What an MSSP contract will not do

It will not make anyone accountable to your board, approve your risk treatment, or own your compliance posture. Those are governance duties that stay with your management body — and, in practice, with the security leader who advises them.

When each is the right call — and when it isn’t

A vCISO is right when you have no senior security owner, face a compliance deadline, or need credible board reporting. It is the wrong spend if you already have a capable security leader and simply need more eyes on the network overnight — that is an MSSP’s job.

An MSSP is right when you have direction but lack the capacity to watch and respond around the clock. It is the wrong buy when you purchase it expecting strategy, prioritisation, or accountability. Those are not in the box, however good the dashboard looks.

A consultant is right when the problem is single, bounded, and finite: a test, an audit, a one-off assessment. It is the wrong choice when the real need is ongoing ownership dressed up as a project — you will simply be back in six months.

The combination most SMBs under €50M actually need

For most companies this size, the answer is not one of the three but a sequence. The pattern we see most often across the EU mid-market is a vCISO who sets priorities, measures and board reporting, paired with an MSSP that runs the daily controls the vCISO specifies — with a specialist called in for point problems as they arise.

The order matters: the brain first, the hands second, the specialist occasionally. Buy monitoring before you have anyone deciding what to monitor and why, and you have bought an expensive stream of alerts nobody owns. This is the same trap we described in 10 Questions to Ask Before You Hire a vCISO — the wrong first hire is worse than a slow one.

Which capability to bring in first A five-minute test: which capability to bring in first.

A five-minute test before you sign anything

Ask three questions in order. Is there one named person accountable to your board for security? If no, you need the brain — a vCISO or CISO — before anything else. Is someone watching your systems and able to respond around the clock? If no, you need the hands — an MSSP. Do you have a single, time-boxed problem such as an audit or a penetration test? If yes, you need a specialist — a consultant — for that, and only that.

In our engagements the usual answers are no, no, and occasionally. That is exactly why the vCISO-plus-MSSP pairing is the one we recommend most often, and why buying an MSSP alone so often leaves the most important question — who is accountable — unanswered. In the next 30 days, before you renew or sign, write down which of the three questions you can currently answer with a name. The gaps are your shopping list.

Sylvio Sorel

CISSP, PECB ISO/IEC 27001 and ISO/IEC 42001 Lead Auditor — founder, Cyber-Management.

Take the next step

Talk to a security practitioner, not a salesperson.

Twenty-five minutes, no slide deck, no follow-up sequence. We'll talk through where you are, what's coming up next on your regulatory horizon, and whether we can help.