Virtual CISO Consultant — Senior Security Leadership Without the ₹60 Lakh Hire
Most mid-sized companies have security tools. Almost none have a security owner.
I get a version of the same phone call every month. A company of 150, maybe 300 people — a manufacturer in Faridabad, a NBFC in Connaught Place, a hospital chain in Noida — has just been told by an auditor, a customer, or an insurer that it needs a CISO. Someone who owns information security. The founder looks at the market, sees CISO salaries quoted at ₹60 lakh and climbing, and the hire quietly dies. Another year passes with the IT manager carrying security as a third job.
A virtual CISO consultant exists for exactly this gap. You get senior security leadership — the person who owns risk, faces the board, defends the audit, runs the incident — for a few days a month, at a fraction of the full-time cost. Not a report that lands in a drawer — a named individual who stays accountable.

I’ve sat on both sides of the audit table for three decades. Here is what a fractional CISO engagement looks like when it’s done properly, what it costs, and when it’s the wrong answer entirely.
What a virtual CISO actually does
The difference first: a consultant writes a document. A CISO carries a responsibility. The document can be excellent — I’ve written many — but nobody’s job is at stake if the recommendations aren’t implemented. A virtual CISO’s job is.
The work breaks down into six recurring duties:
- Risk ownership. Maintaining the risk register, deciding what gets treated, transferred, or accepted, and putting their name against those decisions. When leadership asks “are we secure?”, there is one person who answers.
- Board reporting. Translating technical exposure into language directors act on — money, liability, continuity. A quarterly board pack that a CFO can read in ten minutes, not a 90-slide deck nobody opens.
- Budget and roadmap. A rolling three-year security roadmap broken into quarters, with a budget that justifies each line. The difference between “we need a SIEM” and “here is why ₹18 lakh on monitoring beats ₹18 lakh on another appliance this year.”
- Vendor management. Evaluating security vendors, negotiating contracts, and — this matters more than people realise — challenging the vendors you already have. An independent vCISO has no quota to hit.
- Audit defence. Preparing for and sitting through ISO 27001, RBI, SEBI, customer, and insurance audits. Knowing which findings to fix, which to remediate on a schedule, and how to answer an auditor without volunteering new problems.
- Incident command. When something goes wrong at 2 a.m., someone has to decide: isolate the segment, call CERT-In, preserve evidence, brief the board. A vCISO is on call for that decision, and has rehearsed it beforehand.
If the person you’re evaluating doesn’t do all six, you’re buying a consulting retainer, not a CISO function. Price it accordingly.
Who actually needs one
The sweet spot is a company of roughly 50 to 500 people with real compliance obligations and no security leadership. You’ll recognise yourself here: you have a small IT team that keeps the lights on; security decisions get made by whoever is loudest in the meeting; you handle personal data, financial data, or regulated workloads; and at least one of CERT-In, DPDP, RBI, SEBI, or a demanding enterprise customer now expects a named security head.
Below that size, you probably need an audit and a hardening project, not an ongoing CISO. Above it — or if you’re a bank, a large regulated entity, or running critical infrastructure — you need a full-time hire, and a fractional CISO is at best a bridge while you recruit. If you’re unsure which side of that line you’re on, read how I work with companies at different stages.
What it costs — honestly
A full-time CISO in India costs ₹50–80 lakh a year in salary for someone genuinely senior, before benefits, bonuses, and the team they’ll want to build. For a 200-person company that’s an uncomfortable number, which is why the role stays vacant.
A virtual CISO engagement in India typically runs ₹1.5–4 lakh a month depending on scope, sector, and how regulated you are. A straightforward SME with ISO 27001 aspirations sits at the lower end; a SEBI-regulated entity or a company mid-incident-recovery sits higher. Annualised, that’s roughly a quarter to a third of the full-time cost — and you’re buying 30 years of scar tissue, not someone’s first leadership role.
The honest caveat: at ₹1.5 lakh a month you are not getting a daily presence. You are getting a senior brain on a cadence, plus on-call availability for the days that matter. If someone promises daily involvement at that price, ask which clients they’re dropping.
Why this has become urgent in India
Four regulatory shifts have turned “we should probably have a CISO” into “we need a name on paper and a programme behind it”:
- DPDP Act 2023. Personal data now carries explicit accountability. A data fiduciary needs someone who can demonstrate reasonable security safeguards — and defend them after a breach.
- CERT-In reporting. Incidents must be reported within six hours. Without a named incident commander and a rehearsed plan, that clock runs out while people are still figuring out whose job it is.
- SEBI CSCRF. The Cybersecurity and Cyber Resilience Framework puts governance duties on regulated entities and their senior management. Auditors now ask who owns cyber risk, and “the IT vendor” is no longer an acceptable answer.
- RBI expectations. Across its IT and outsourcing frameworks, RBI expects a designated, competent senior officer accountable for information security — in banks, NBFCs, and increasingly their service providers.
Each of these can be satisfied by a properly structured vCISO arrangement, provided the role is documented, the person is demonstrably senior, and the programme has real artefacts — risk register, board minutes, incident plan — behind it. A paper appointment fools nobody who’s audited for a living.
How I structure a vCISO engagement
My version of this follows the same arc as everything else I do: assess, architect, then operate on a steady cadence.
Month one: assess
I spend the first weeks inside your environment — talking to IT, finance, HR, and leadership, reviewing what you actually have deployed, and reading your last audit findings. The output is a baseline risk register and a brutally honest gap list, ordered by what would hurt you most.
Months two to three: architect
We build the roadmap: quick wins first, then the quarter-by-quarter plan with budgets. Policies get written to match how you actually work — a policy nobody follows is worse than none. The incident response plan gets drafted, assigned, and tabletop-tested.
Ongoing: operate
The steady state is a monthly cadence. A working session with your IT team, a vendor and change review, and a metrics update. Quarterly, I present the board pack in person. Annually, audit preparation and a full plan refresh. And through it all, I’m on call when an incident breaks — a CISO who isn’t reachable during a breach isn’t a CISO.
If you’d rather have the whole function run for you as a managed service — vCISO leadership plus the monitoring and response muscle underneath it — my team at PJ Networks delivers exactly that through our virtual CISO services for Indian enterprises, backed by the same 24/7 operations I describe on the PJ Networks site.
When a vCISO is the wrong answer
I’ll save you the discovery call in three situations.
First, if you need hands on keyboards daily — firewall changes, alert triage, user provisioning — you need in-house engineers or a managed SOC, not a part-time strategist. A vCISO directs that work; they don’t replace it.
Second, if your regulator expects a full-time, dedicated officer — some RBI-supervised entities fall here — a fractional arrangement won’t satisfy it.
Third, if leadership wants a CISO purely to absorb blame after a breach, walk away. The role works when the board genuinely wants the truth about its risk; I’ve declined engagements where the appointment was theatre.
Frequently asked questions
What’s the difference between a virtual CISO, a security consultant, and an MSSP?
A consultant delivers advice and documents, usually project by project. An MSSP delivers managed technology — monitoring, firewalls, response — as an ongoing service. A virtual CISO is neither: it’s ongoing leadership and accountability. The vCISO sets direction, owns risk, and often oversees both the consultants and the MSSP on your behalf. Many companies need all three; the mistake is expecting one to do the others’ jobs.
How many days a month does a virtual CISO actually give?
Typically two to six days a month, structured as scheduled working sessions, board and audit commitments, and document review — plus on-call availability for incidents. The cadence matters more than the raw day count: a fixed monthly rhythm with a quarterly board presence accomplishes more than ten unstructured days.
Will a vCISO pass an RBI or SEBI audit as our security head?
Yes, if the arrangement is genuine. Auditors look for a named, demonstrably competent officer, documented responsibilities, and evidence the function operates — risk registers, board minutes, incident plans, review records. A paper appointment with no artefacts behind it fails. A properly run vCISO engagement produces those artefacts as a matter of course, which is precisely what the audit tests.
What does a virtual CISO cost in India?
Most engagements run ₹1.5–4 lakh per month depending on company size, sector, and regulatory load. Compare that with ₹50–80 lakh a year for a full-time senior CISO before benefits and team costs. Be suspicious of anything dramatically cheaper — it usually means a junior consultant with a rebranded title.
Can you work with our existing IT team?
That’s the only way it works. I don’t replace your IT team; I give them direction, priority, and air cover with leadership. Most internal teams are relieved to have someone senior who understands the technical detail arguing for their budget. Where gaps exist — monitoring, for instance — I’ll say so plainly and help you fill them, in-house or outsourced.
How does the engagement start?
With a working session, not a sales pitch. We spend an hour on your current state, your compliance obligations, and what’s actually keeping you up at night. If a vCISO fits, I propose a scoped first quarter — baseline assessment, risk register, quick wins — so you can judge the relationship on delivered work before committing to a year.
Let’s talk about your situation
If you’re a 50–500 person company carrying compliance obligations without security leadership, the gap only gets more expensive. Start with a conversation — book a working session and I’ll tell you honestly whether you need a vCISO, a full-time hire, or just a hardening project. Based in Delhi, working with enterprises across India.