Most businesses that reach 30 to 200 employees hit the same wall. IT is managed by whoever is most technical on the team. Security consists of an antivirus subscription and a hope that nothing goes wrong. Leadership knows this is not enough, but a full-time Chief Information Security Officer costs £120,000 to £180,000 a year in the UK before benefits and recruitment fees. A Head of IT adds another £70,000 to £110,000. A virtual CISO and virtual IT Manager are what fills that gap in practice.

These are not just outsourcing arrangements. They are strategic leadership roles delivered on a part-time basis by an experienced practitioner who works across multiple organisations. This article explains what each role actually covers, who gets the most value from it, and what an engagement looks like on a practical level.

What a vCISO does

A virtual CISO is a security executive, not a technical operator. The distinction matters. A vCISO does not monitor your firewall or respond to alerts. They set the direction for how your organisation manages security risk, then help you execute against it.

Security strategy and risk management

The starting point for any vCISO engagement is an honest assessment of where the organisation stands. What are the main risks? Where are the controls weakest? What regulatory obligations apply? From that baseline, the vCISO builds a prioritised security roadmap, one that reflects the actual risk profile of the business rather than a generic framework checklist.

Compliance and regulatory oversight

Regulatory requirements are increasingly unavoidable for businesses of any size that operate in Europe. NIS2 applies across 18 critical sectors. GDPR carries enforcement risk that is actively materialising. ISO 27001 is now a requirement in many procurement processes and supply chains. A vCISO takes ownership of understanding what applies to your business, what it requires, and how to build compliance into operations without creating bureaucratic overhead that slows the business down. See our NIS2 guide and ISO 27001 guide for SMEs for detail on both frameworks.

Incident response leadership

When a serious security incident occurs, most organisations without a CISO improvise. Decisions get made by whoever is most senior and available, often with incomplete information and no prior planning. A vCISO ensures an incident response plan exists before it is needed, that the right people know their roles, and that there is an experienced decision-maker available when the situation escalates.

Board and executive reporting

Security risk belongs on the board agenda, but most technical teams struggle to translate their work into language that drives informed decisions at that level. A vCISO bridges that gap. They report on security posture, risk exposure, and investment priorities in terms that resonate with executives and non-technical stakeholders, without watering down the substance.

Vendor and third-party security

Most organisations rely on a long list of external software, cloud platforms, and service providers. Each one is a potential entry point. A vCISO reviews the security of your vendor relationships, sets minimum security standards for suppliers, and flags where third-party risk is being underestimated. This is increasingly relevant as supply chain attacks become more common and regulators begin holding organisations accountable for the security posture of their supply chains.

What a vIT Manager does

A virtual IT Manager operates at the intersection of technology and business strategy. They are not a helpdesk. They are responsible for ensuring that IT decisions serve the business, that infrastructure is fit for purpose, and that the organisation is not accumulating technical debt or exposure through poor governance.

IT strategy aligned to business goals

Many businesses make IT decisions reactively: a system fails, a contract expires, a vendor pitches something new. A vIT Manager brings a forward-looking view. What does the business need from its technology in the next two years? What should be replaced, consolidated, or migrated? What investment is genuinely necessary versus what a vendor is trying to sell? These are strategic questions that require someone thinking about IT at an organisational level, not just fixing problems as they arise.

Vendor and contract management

Most SMEs have accumulated a collection of IT vendors over time without a clear view of what they are paying for, whether they are getting value, or what the contractual terms actually say. A vIT Manager reviews these relationships, negotiates renewals, and ensures the organisation is not locked into unsuitable agreements. They also manage the performance of managed service providers if the day-to-day IT support function is outsourced.

IT governance and policy

Without governance, IT grows in unpredictable directions. Staff bring their own devices. Data ends up stored in personal cloud accounts. Software gets procured without IT visibility. Shadow IT creates risk that nobody has formally assessed. A vIT Manager puts the policies and processes in place that bring order to this without creating bureaucracy that makes the business slower to move.

Infrastructure oversight and planning

Servers reach end of life. Networks become congested. Security architecture starts to show gaps as the business grows. A vIT Manager tracks the health of the infrastructure, plans upgrades before they become crises, and oversees projects to completion. They do not do the technical work themselves, but they specify what needs to happen and hold the people doing it accountable for delivering it.

Who benefits most from these roles

The vCISO and vIT Manager model works best for organisations in a specific range. Too small and there is not enough complexity to justify the engagement. Too large and the business needs full-time leadership in-house. The sweet spot is broadly 30 to 300 employees, though the driver is complexity more than headcount.

Specific situations where these roles have the clearest return:

  • Regulated sectors. Healthcare, financial services, and hospitality businesses face sector-specific compliance obligations that require someone with the right expertise to interpret and implement them correctly.
  • Pre-audit or certification. Businesses working toward ISO 27001, Cyber Essentials Plus, or NIS2 compliance need someone to own the programme. A vCISO can lead that work without the business needing to hire a full-time CISO for what is often a 6 to 12 month project.
  • Post-incident recovery. Organisations that have experienced a breach often need to rebuild their security posture from a more structured starting point. A vCISO can lead that process and help the business avoid repeating the conditions that made the incident possible.
  • Pre-investment or acquisition. Investors and acquirers run IT and security due diligence. Businesses preparing for investment benefit from having someone who can assess their posture honestly, close gaps before they become deal issues, and present their IT and security story credibly.
  • IT managed by non-specialists. Many SMEs have IT managed by an office manager, operations director, or finance team member. Those individuals are good at their jobs and not trying to do IT. A vIT Manager takes the function off their desk and runs it properly.

What an engagement actually looks like

A typical vCISO or vIT Manager engagement runs at between two and eight days per month, delivered as a mix of on-site and remote work depending on what the business needs at any given time.

The engagement is not a retainer for ad hoc advice. It is a structured arrangement with defined deliverables: a quarterly security review, a board-ready risk report, a maintained security roadmap, vendor evaluations as needed, and availability for escalation when something requires urgent attention. During specific projects, such as an ISO 27001 audit preparation or a significant infrastructure migration, the engagement can scale up temporarily without the organisation needing to hire additional resource.

The cost is significantly lower than a full-time hire. More importantly, it gives the business access to someone who has worked through the same challenges across many different organisations, which means fewer mistakes and faster progress than a first-time in-house appointment would typically deliver.

Common questions

Is this the same as managed IT support?

No. Managed IT support covers day-to-day operations: helpdesk, device management, patching, monitoring. A vIT Manager sits above that layer. They set direction, manage vendors including the managed services provider, and make strategic decisions. Both can coexist and often work best together.

What happens during a security incident?

A vCISO is available for escalation and can lead the initial response. They are not a 24/7 security operations centre, so for businesses that need round-the-clock monitoring and response capability, that function is handled through a separate managed detection and response arrangement. The vCISO oversees it and takes responsibility for the overall response strategy when something serious happens.

Do they need to understand our industry?

Sector knowledge matters. A vCISO working with a healthcare organisation needs to understand clinical workflows, data sensitivity, and NHS supplier requirements. A vIT Manager in financial services needs to know what FCA rules mean for IT governance. At Cyvra, we focus on healthcare, financial services, and hospitality specifically because sector depth makes the advice materially better than a generalist approach.