vCISO & Fractional CISO

The vCISO that
answers for the outcome.

A virtual CISO (vCISO), sometimes called a fractional CISO, gives you senior security leadership without a full-time hire. Core3 goes further. We do not just advise the program, we run it and answer for it, up to serving as your named CISO of record.

Most vCISOs advise. The question is who is accountable.

Virtual CISO and fractional CISO are two names for the same role: senior security leadership on a part-time, retained basis. The label is branding. What actually differs between providers is what the engagement is accountable for. Many are structured to advise, assess, recommend, and hand you a report. Fewer are structured to own the outcome and still be there when the board asks whether it worked.

That is the line Core3 draws. We quantify risk in financial terms, run the program, and report against our own commitments quarter over quarter. At the deepest tier, we serve as your security leader of record: the name on the attestation, and the person auditors, regulators, customers, and the board get answers from.

Three tiers,
by depth of ownership.

The tiers escalate by what Core3 absorbs, not by hours. Advisor: Core3 sets the plan and reports against it. Your team runs it. Operator runs the program for you. Partner becomes your CISO of record. The step you pay for is a transfer of accountability, not more time.

What's included AdvisorYou run it RecommendedOperatorCore3 runs it PartnerCISO of record
Quarterly Cyber Risk Briefing
Financial Exposure ModelSnapshotTolerance trackingFull trend analysis
Risk tolerance & appetite framework
Who runs the programYou doCore3Core3
Monthly Executive Intelligence Brief—
Executive reporting cadenceQuarterlyMonthlyMonthly
Board briefingQuarterlyWith exec prepCore3 presents
Compliance oversightAdvisoryGovernedGoverned
Vendor risk oversightQuarterlyGovernedGoverned
Annual tabletop exercise—
CISO of record, name on the SOC 2, faces auditor, regulator, customer & board——
Incident response coordination——
AI Governance Program track——
M&A due diligence support——As situations arise
Specialist programs & technical deliveryScoped to needScoped to needScoped to need

The jump from Operator to Partner is risk transfer, not more hours. At Operator, you are still the accountable executive. At Partner, Core3 becomes the named security leader of record: the answer to the enterprise customer who demands one, and the name a board can point to. Pricing is fixed for each tier and shared on request.

When a vCISO
makes sense.

A full-time CISO makes sense once security is large and constant enough to justify a senior salary and a team. Before that point, a vCISO gives you the same seniority for the fraction of time you actually need it. It usually comes up at a moment like one of these.

A deal is blocked

An enterprise customer's security review is holding up a contract, and you need someone who can answer for the program.

An investor or board is asking

Due diligence, a new board, or a sponsor wants cyber risk explained in terms they can govern.

A framework is now required

SOC 2, ISO 27001, HIPAA, or PCI has become a condition of doing business, and someone has to own it.

You have outgrown informal ownership

Security has been handled off the side of someone's desk, and the risk has outgrown that arrangement.

You are between CISOs

A departure left a gap, and the program needs senior leadership to hold steady and keep moving.

Something just happened

After an incident, you need experienced leadership to steady the program and close the gaps that were exposed.

Deciding between
advice and ownership?

If you are weighing a vCISO, the distinction that actually matters is not virtual versus fractional. It is advice versus accountability. Our guide walks through the difference and the questions to ask before you hire one.

Read: vCISO vs. Fractional CISO

Need senior security
leadership now?

Start with the program you have. The dollar view is there when it becomes useful. From there, you choose the tier that fits.