Skip to main content

← All posts

Do you need a vCISO at 25 employees?

At 25 employees, security decisions are nobody's job. Here is when a fractional security leader earns their fee and when you can wait.

· Jake Schaaf, Founder of Atticus Rowan

A 25-person company gets a 240-question security questionnaire from its biggest customer. It lands in the inbox of the operations manager, who forwards it to the IT provider, who answers the technical rows and sends back 60 blanks with a note: “These are policy questions. Who owns your security program?” The email sits for a week because the honest answer is nobody.

That moment, or one like it, is how most small companies discover the difference between operating security controls and owning security decisions. Somebody patches the laptops. Somebody manages the firewall. But nobody decides what the company’s risk appetite is, which controls are worth funding this year, what the policy actually says or how to answer a customer asking hard questions. At 25 employees there is no CISO, no security committee and no line item for either.

A virtual CISO (vCISO) exists to fill exactly that gap, part-time, at a fraction of the cost of a hire. Whether you need one at 25 employees depends less on headcount than on what is pulling at the company.

The triggers that create the need

In our experience 4 events push a small company from “we should think about security” to “we need someone accountable for it”:

  • Customer security questionnaires. Once enterprise customers start sending them, they keep coming, and the answers become contractual promises. Somebody has to own what the company claims. Our questionnaire walkthrough shows what these actually ask, and most of it is program and policy, not firewall settings.
  • Cyber insurance applications. Underwriters now ask about governance: who is responsible for security, is there a written program, when was the last risk assessment. “Our IT guy handles it” is a weak answer that shows up in the premium.
  • A board, investor or acquirer asking about posture. The question “what is our security posture” cannot be answered with a list of products. It needs a program, and programs need owners.
  • An incident. After a fraud loss or a close call, companies want someone steering. The expensive version of this trigger is hiring the steering after the crash.

If none of these are on your horizon, you may genuinely not need a vCISO yet. We will get to that.

What a vCISO actually does

The title confuses people because it sounds like a person who does security work. A good vCISO mostly makes and documents decisions:

  • Risk decisions. What are the realistic threats to this business, which ones do we accept, which do we spend against. Written down, revisited yearly.
  • The roadmap. A prioritized 12-24 month plan: what gets fixed this quarter, what waits, what it costs. Not a wish list, a sequence.
  • Policy ownership. The acceptable use policy, access control policy, incident response plan and vendor standards. Not template PDFs, documents that match what the company actually does. This is the backbone of the written security program customers and insurers keep asking about.
  • Questionnaire and audit support. When the 240-question spreadsheet lands, the vCISO owns the answers, keeps them consistent across customers and knows which “no” answers need remediation plans attached.
  • Vendor and tooling judgment. An independent voice on whether the proposed tool is necessary or just well marketed.
  • Translation. Reporting security posture to owners and boards in business terms: what we spent, what it bought, what is still exposed.

What a vCISO is not

A vCISO does not replace your IT provider, and a good one will say so in the first meeting. The MSP operates controls: helpdesk, patching, EDR, backup, identity administration. The vCISO decides which controls should exist and verifies they are working. One is hands, the other is head.

The relationship is complementary, and the separation is healthy. When the same party sells the tools, operates the tools and grades the tools, the grades trend generous. An independent decision layer keeps everyone honest, including us.

Be equally skeptical in the other direction. A vCISO who cannot point to the operational reality behind their policies, or who produces 80 pages of documentation no 25-person company will ever follow, is selling paper. Policies that do not match practice are worse than no policies, because customers and courts treat them as promises.

What it costs

Fractional security leadership for a small company commonly runs $2,000 to $8,000 per month depending on scope and cadence. The low end looks like quarterly strategy, an annual risk assessment and policy maintenance. The high end looks like monthly governance, active questionnaire response, insurance renewal support and incident tabletop leadership.

For comparison, a full-time experienced CISO is a $200,000-plus salary before benefits, and at 25 employees there is not 40 hours a week of CISO work to do. That mismatch is the entire logic of the fractional model: you need the judgment, not the headcount.

Against the cost of the problems it prevents (a lost enterprise deal, a declined insurance renewal, a fraud loss that a basic control review would have caught), the fee is small. But it is only worth paying when the triggers are real.

When you do not need one yet

An honest vendor tells you when to keep your money. You can likely wait on a vCISO if:

  • No customer has asked about your security posture and none of your target customers are enterprises
  • Your cyber insurance application was straightforward and the premium was unremarkable
  • No board, investor or lender is asking questions
  • The fundamentals are not in place yet: MFA everywhere, EDR, tested backups, offboarding discipline

That last point matters most. If the basics are missing, fix the basics first. A strategy layer on top of an empty stack produces impressive documents about controls that do not exist. Get the foundation from a competent managed provider, then add governance when the outside world starts asking for it.

The combined model

Some managed security providers, Atticus Rowan included, offer the operational stack and the governance layer as separate engagements that fit together: the MSP contract runs the controls, a security leadership engagement owns the risk register, the roadmap, the policies and the customer-facing answers. The advantage is coherence, one party cannot blame the other. The requirement is discipline, the governance side has to be willing to grade the operational side honestly.

However you source it, the goal at 25 employees is simple: when a customer, insurer or investor asks “who owns security here,” there is a name, a program and a straight answer.

If your company just hit one of the triggers, the security questionnaire arrived or the renewal got hard, we can help you decide whether you need the full governance layer or just the fundamentals done well. See what a security-first managed engagement includes at /solutions or start the conversation.