A problem that will not solve itself
The cybersecurity labour market in Poland has a fundamental structural problem. According to (ISC)² data from the Cybersecurity Workforce Study 2024, the global shortage of cybersecurity professionals stands at 4 million people, and Europe is short of more than 300,000 qualified staff. The situation in Poland is proportionally similar — organisations compete for a limited pool of specialists, driving salaries up to levels that are out of reach for most mid-sized companies and for practically every public institution.
At the same time, regulatory requirements keep growing. NIS-2 requires management bodies to take direct responsibility for cybersecurity. KRI obliges every public sector entity to run an information security management system (ISMS). DORA introduces stringent requirements for the financial sector. ISO 27001 increasingly appears as a condition in tenders and in contracts with business partners. Organisations need someone to manage this area — but not all of them can afford a full-time information security director.
This is where the vCISO model comes in — the Virtual Chief Information Security Officer.
What a vCISO is
A vCISO is an external specialist, or a team of specialists, who performs the role of information security director on an outsourcing basis — with the same responsibility, competence and commitment, but without the fixed cost of a C-suite post.
In the Polish legal context, a vCISO most often combines three roles that in large organisations are held by separate people. First, the information security officer (required de facto by KRI in public sector entities and recommended by ISO 27001 in every organisation) — responsible for coordinating the ISMS, overseeing security policies and reporting to management. Second, a regulatory compliance coordinator for cybersecurity, who monitors legal developments — NIS-2, the Polish NIS-2 implementing act (the KSC Act), KRI, DORA — assesses their impact on the organisation and coordinates the work needed to adapt. Third, a strategic IT risk adviser, who helps management make informed decisions on security investment, risk prioritisation and resource allocation.
It is worth stressing the difference between a vCISO and an ordinary consultant. A consultant arrives, delivers a project and leaves. A vCISO is a permanent presence in the organisation — attends board meetings, knows the people, the systems and the processes, responds to incidents and builds a security culture. It is a continuous relationship, not a one-off engagement.
How a vCISO differs from an information security officer
The information security officer is an operational function. KRI, ISO 27001, NIS-2 — each of these regulatory regimes requires the organisation to appoint a person responsible for the Information Security Management System. The officer runs reviews, documents risk, coordinates training and handles incidents. This is day-to-day, concrete work.
The vCISO is a strategic function. It works at board level, not at IT department level. Its task is to turn information security from a set of regulatory obligations into a competitive and managerial asset. The vCISO asks the questions nobody else in the organisation asks — and gives answers that shape business decisions.
In practice the two models complement each other. The officer runs the system operationally. The vCISO provides the strategic direction the officer then works to. In smaller organisations one person or one external partner may hold both roles — but it needs to be understood that these are different roles, requiring different competencies and a different way of working.
The line can be thin on the data protection side as well — we discuss the point at which combining roles ceases to be acceptable in our article on DPO independence.
When a vCISO makes sense
The vCISO model is not a universal answer — it works in specific organisational situations. It is worth considering in several scenarios.
Mid-sized companies (50–500 employees) that process sensitive data, are subject to regulation (NIS-2, GDPR, sector-specific rules) or have clients requiring ISO 27001 certification — but whose scale does not justify hiring a full-time CISO.
Local government units that have to meet KRI requirements and potentially NIS-2, but have limited budgets for specialist posts. Full-time pay for a cybersecurity specialist in the public sector is simply not competitive with the private market.
Companies that have suffered a security incident and have realised they need professional IT risk management, but do not want to wait six months to find and onboard a full-time CISO.
Organisations going through ISO 27001 certification that need an experienced person to coordinate the implementation and maintenance of the information security management system.
Municipal companies and entities owned by local authorities — water utilities, district heating plants, waste management operators — that are subject to regulation but whose scale of operations does not justify a dedicated post.
The vCISO model usually does not work in large corporations with extensive IT teams (above a thousand employees), in organisations from sectors facing the highest regulatory requirements (large banks, class A critical infrastructure operators) where the regulator expects a full-time CISO, or in companies that treat security as a core competence and want to build an in-house team from the ground up.
What a vCISO does day to day
The scope of a vCISO's work covers both strategic and operational activity. The balance depends on the organisation's maturity — in a company starting to build its ISMS, project work dominates; in an organisation with a system already in place, the emphasis shifts to monitoring, improvement and response.
The strategic layer covers drafting and updating information security policies, carrying out and overseeing risk analysis, reporting to the management board or to the head of the entity (in the case of local authorities), preparing IT security budgets, monitoring regulatory change and assessing its impact, coordinating ISO 27001 certification and taking part in management reviews.
The operational layer means overseeing the implementation of technical controls, coordinating the response to security incidents, managing relationships with IT suppliers from a security perspective, reviewing privileges and access controls, organising and supervising staff training, coordinating internal and external audits, and managing ISMS documentation.
The communication layer — often the most important of the three — is the ability to translate technical threats into language the board understands, to build security awareness across the whole organisation, and to act as the point of contact for regulators, auditors and business partners.
The advantage of the vCISO model
The key advantage of the vCISO model over a full-time CISO is not purely economic — although economics matter. The organisation gains access to a team with complementary competencies (auditor, lawyer, IT specialist, risk management specialist) instead of relying on a single individual. A vCISO team sees threat patterns and good practice across many organisations at once — an in-house CISO knows only their own company. Staff turnover in the cybersecurity industry is high, and the vCISO model removes the risk of losing capability when a key employee leaves.
In the public sector there is an additional argument: pay scale constraints make it formally impossible to hire a cybersecurity specialist at market rates. The outsourcing model allows that barrier to be worked around.
How to implement the vCISO model
Implementing the vCISO model runs through several stages, and the whole process usually takes two to four weeks before the new vCISO is fully operational.
Phase 1: Discovery (week 1). The vCISO carries out an initial review of the organisation — getting to know its structure, IT systems, existing documentation, key people, identified risks and current challenges. This is the equivalent of due diligence, and it results in a report recommending priorities for the first three months.
Phase 2: Setting the rules of engagement (weeks 1–2). Defining the scope of responsibility, communication channels, reporting frequency, incident escalation rules and the expected level of involvement. Clear rules from the outset eliminate misunderstandings.
Phase 3: Quick wins (weeks 2–4). The first weeks are the time for fast, visible action: tidying up documentation, closing the most obvious security gaps, switching on monitoring. Quick wins build the confidence of the board and of employees in the new model.
Phase 4: Building the system (months 2–6). Systematic work on the full implementation or improvement of the ISMS — risk analysis, policies, procedures, training, audit. This is the phase in which the vCISO creates lasting value.
Phase 5: Ongoing operation (from month 6). The system is running and the vCISO moves into maintenance mode — monitoring, reviews, incident response, updating documentation, refresher training, reporting to the board.
What to look for when choosing a vCISO
Not every security consultant can perform the vCISO role. When choosing a partner, several aspects deserve attention.
Sector experience. A vCISO should understand the specifics of your industry — a manufacturer faces different challenges from a local authority, and both differ from an e-commerce business. Familiarity with sector-specific systems (in the case of local authorities) or with industry regulation (DORA for finance, TISAX for automotive) is not an optional extra — it is a prerequisite.
A team, not an individual. A good vCISO model is not a freelancer with a CISSP certificate — it is a team with complementary competencies: auditor, lawyer, IT specialist, risk management specialist. One person cannot cover every area to an adequate standard.
Availability and response time. A vCISO has to be available in a crisis — a security incident does not wait for the next scheduled consultancy day. Agree availability rules, emergency channels and a maximum response time up front.
Transparency and reporting. A professional vCISO delivers regular reports (monthly or quarterly) covering the security posture, work completed, risks identified, recommendations and the plan for the next period. The board has to see the value of the investment.
A partnership approach. A vCISO is not there to carry out instructions — this is a strategic partner who should have the courage to tell the board uncomfortable things, recommend investment and push back against decisions that put security at risk.
The vCISO and NIS-2 requirements
The NIS-2 Directive makes management bodies directly responsible for cybersecurity (Article 20 of the directive). The board has to approve risk management measures, oversee their implementation and take part in training. It cannot delegate that responsibility — but it can (and should) delegate operational delivery.
This is where the vCISO becomes the natural solution. The vCISO is the person who operationally coordinates everything NIS-2 requires: risk analysis, implementation of security measures, incident management, supply chain security and training for the management body. The board retains responsibility, but has a partner who supplies the knowledge, the tools and the execution.
In the NIS-2 context, incident reporting is a particularly important function. An essential or important entity has to submit an early warning within 24 hours of detecting an incident, a full notification within 72 hours and a final report within one month. A vCISO who knows the organisation, its systems and its procedures can run that process efficiently — unlike an external consultant called in ad hoc at the moment of crisis.
Local government units are simultaneously bound by the National Interoperability Framework (KRI) — a vCISO should keep both regimes in view at once.
Frequently asked questions about the vCISO
Can a vCISO also act as the data protection officer (DPO)? In theory, yes — provided the two roles do not create a conflict of interest. In practice, combining the vCISO and DPO roles is common in smaller organisations where the budget does not allow for two separate posts. What matters is that the person holding both functions has both the technical competence (cybersecurity) and the legal competence (GDPR). In larger organisations we recommend separating the roles.
Does a vCISO have to be physically present in the office? No — most of a vCISO's work is done remotely. Physical presence is advisable at key moments: kick-off, management reviews, training, audits and the response to serious incidents. The typical model is one or two days of physical presence per month plus continuous remote availability.
How do you measure a vCISO's effectiveness? The key performance indicators (KPIs) are: the state of compliance with regulation (KRI, NIS-2, ISO 27001), the number of incidents and the response times, internal audit results, the percentage of employees trained, progress against the risk treatment plan, and the time from detecting an incident to reporting it. The vCISO should propose a set of measures and report on them regularly.
Is the vCISO model consistent with regulators' requirements? Yes — no Polish regulation (KRI, the KSC Act, GDPR) requires the person responsible for information security to be employed on a contract of employment. The requirement concerns the function, not the form of employment. Likewise, ISO 27001 requires the organisation to appoint a person responsible for the ISMS — it does not specify whether that person should be internal or external.
How Fib.Code delivers the vCISO model
At Fib.Code we offer a vCISO model built on a multidisciplinary team — combining the competencies of ISO 27001 auditors, cybersecurity specialists, lawyers specialising in GDPR and NIS-2, and IT practitioners with experience in both the public and private sectors. Every client is assigned a lead consultant who knows the organisation inside out, supported by a team of domain specialists.
We work with private companies (IT, manufacturing, services, e-commerce) as well as with local government units and their subordinate entities. We know the sector-specific systems used by local authorities, we understand the realities of public procurement, and we can adapt ongoing information security oversight to the budgetary realities of the public sector.
Let's talk about security in your organisation: l.grabowski@fibcode.com | fibcode.com/pl/wycena


