You’re paying $2,000–$6,000 a month for a virtual CISO. You get status updates, occasional meetings, and the reassurance that someone is handling your security program. But can you actually say what they delivered last quarter?
If the answer is “not specifically,” you’re in good company - and it’s not necessarily your vCISO’s fault. Most vCISO disappointment traces to the same root cause: the scope was never written down clearly enough to evaluate. The title created an expectation; the contract created an obligation that didn’t match it.
These five questions cut through the ambiguity. Ask them in your next quarterly review. A strong engagement has specific answers to all five. A weak engagement - or one with unclarified scope - will struggle with at least two or three.
1. “What did you deliver last quarter?”
Why it works: This is the most revealing question on the list because it immediately distinguishes between activity and output. Activity is meetings attended, emails responded to, platform alerts reviewed. Output is artifacts that exist and can be shown: a completed gap assessment, a risk register updated with three new findings and owner assignments, a board security briefing presented on a specific date, vendor risk reviews completed for four new vendors.
What a strong answer sounds like: “We completed the ISO 27001 gap assessment we scoped in January - here’s the document. We ran Q1 access reviews and closed the two exceptions that came out of them. We updated the risk register with the findings from the vendor assessment on your data processor in Germany, and we briefed the board on the phishing simulation results.”
What a weak answer sounds like: “We’ve been monitoring the platform, attending team meetings, and keeping an eye on things. The Vanta tests have been mostly green.” This is activity, not delivery. It may represent real work - but it’s not a program deliverable, and it’s not what a CISO function produces.
The softer version of a weak answer sounds like deliverables but stays vague: “We’ve been working on policies and the risk register.” Push for specifics: which policies, what status, what changed in the risk register and when.
2. “What’s on the security roadmap for the next two quarters?”
Why it works: A genuine CISO function includes proactive planning - knowing where the program is going and why, with milestones that can be tracked. If your vCISO can answer this question with a specific roadmap (not just “we’ll keep maintaining the platform”), it’s strong evidence that they’re operating as a security leader rather than a maintenance function.
What a strong answer sounds like: “Q3 is the ISO 27001:2022 transition - we have a 10-week plan with milestone dates. Q4 is focused on maturing the vendor risk program: we’re adding tiered assessment forms and a quarterly review cadence. We’ve also scheduled a tabletop IR exercise for September.”
What a weak answer sounds like: “We’ll keep things running and respond to whatever comes up.” Reactive planning is not a roadmap. Some vCISO engagements are explicitly scoped as reactive - if yours is, that’s fine, but it should be explicit, and the price should reflect it.
If there’s no roadmap, that’s the output of this conversation: agree on one together. Get it in writing. A roadmap is both a planning tool and a deliverables contract for the next quarter.
3. “What would happen if we had an incident tonight?”
Why it works: Incident response readiness is one of the clearest tests of whether a vCISO is operating at the strategic level or the operational level. A strategic vCISO has made sure an IR plan exists, knows what their role in it is, and has tested it at least once. A vCISO who manages your Vanta instance probably isn’t leading your incident response.
What a strong answer sounds like: “Our IR plan is in [location], last updated in March. Your role is notification owner for customer comms; mine is coordination lead for the technical response and breach notification assessment. We did a tabletop in April - the main gap that came out of it was our communication tree for after-hours incidents, and we’ve since updated that.”
What a weak answer sounds like: “We have an IR plan template in the system.” Templates are not plans. “In the system” is not the same as “practiced and ready.” Follow up by asking: what is your specific role if we have a breach at 11pm on a Friday? If the answer is unclear, the incident readiness is unclear.
This isn’t about blame - it’s about scope clarity. A vCISO whose engagement doesn’t include incident response leadership should say so explicitly. If yours does, they should be able to walk through it in 60 seconds.
4. “What’s our biggest unaddressed risk right now?”
Why it works: This tests proactive risk thinking. A vCISO who is genuinely owning your program’s risk management function should always be able to name the top risk they’re watching - and explain why it’s unaddressed and what addressing it would require. If they can’t answer this question without checking the system first, it suggests they’re managing tasks rather than owning risk.
What a strong answer sounds like: “The biggest unaddressed item is our third-party data processor in Southeast Asia - they’re in scope for our GDPR obligations but we don’t have a DPA in place and the vendor assessment hasn’t been completed. We’ve flagged it twice; the blocker is legal needing to review the DPA template. Here’s the risk item in the register with the owner and due date.”
What a weak answer sounds like: “Everything looks pretty good overall. Vanta is mostly green.” Mostly green automated tests are not a risk assessment. A risk register with no open items of concern is either a sign of a very mature program or a sign that the risk register isn’t being maintained seriously. In most mid-market companies, the former is unlikely.
If your vCISO genuinely can’t name a top unaddressed risk, that’s either great news about your program’s maturity - or it’s a signal that risk identification isn’t happening proactively. The conversation itself is valuable either way.
5. “Walk me through our audit readiness.”
Why it works: Audit readiness is the most concrete, measurable dimension of a vCISO’s work. It has a binary outcome - you pass or you don’t - and the path to that outcome should be visible and trackable. A vCISO who can walk through your current readiness state with specifics (which controls are green, which are yellow, what evidence is outstanding, what the timeline to audit looks like) is demonstrably doing their job. One who gives a vague “we’re in good shape” is not.
What a strong answer sounds like: “We’re 11 weeks out. Controls are 94% green in Vanta. The two failing tests are the encryption-at-rest finding on your legacy data warehouse - we have a remediation plan with engineering due in 3 weeks - and the background check control, which is blocked on HR. Evidence coverage is solid across all SOC 2 criteria except CC9.2, where we have two vendors without completed assessments. Here’s the readiness tracker.”
What a weak answer sounds like: “We’re in pretty good shape. Things look mostly green. I’ll do a more detailed review closer to the audit.” If your audit is less than 90 days away, “I’ll do a more detailed review closer” is too late. The 90-day window before an audit is when detailed review should already be happening.
This question also surfaces whether your vCISO is going to lead the audit or just be present for it. Ask explicitly: what is your role during audit fieldwork? Are you managing evidence requests, attending auditor calls, and owning the auditor relationship? Or are you available for questions?
What to do with the answers
If all five questions get specific, documented answers - your engagement is delivering. That’s worth knowing and saying clearly.
If two or three questions get vague answers, that’s a scope conversation, not a crisis. The most common cause is that expectations were set in the pitch and never formalized in the contract. Schedule a scope alignment meeting, use the independent 25-point vCISO checklist as a framework, and agree in writing on what’s in scope and what’s not.
If most questions get vague answers, you’re paying for a title. The vCISO Audit is an independent $750 review designed for exactly this situation - it assesses what your provider has actually delivered against an independent standard and gives you a written scorecard with a clear verdict.
The goal of these questions isn’t to catch your vCISO doing something wrong. Most weak engagements are weak because the scope was never clear - not because the provider is bad. Good vCISOs welcome this kind of structured evaluation. It gives both parties a clear picture of what’s working and what needs to be addressed before the next audit, renewal, or leadership question about security program ROI.
Not sure if switching is the right move?
A free 30-minute consultation maps your exact situation - what data moves, what doesn't, whether your timeline is viable, and what the switch will actually cost in time and disruption.
Independent advice. Not affiliated with any platform vendor.