Has anyone had experience with a vCISO in a small (0-10) company environment? Where every dollar counts, is it worth it to step away from building the product if you have a team to back you up while you take the reigns on info sec and compliance?
I talk to founders on a daily basis who are considering the vCISO versus in-house route. If you can guaranteed commit ~30 hours of time from your team for SOC 2 and 40-60 for ISO27001 - you could do it yourself. But if you can't find that time by your deadline - it might be better just to outsource. You can also engage them for part of the project (e.g get them for an internal audit, scoping advice, pen test, help you resolve some security tasks). This makes the engagement cheaper while still helping you move along.
I definitely support putting someone dedicated to the CISO role as soon as finically feasible. Both because ensuring compliance to regulations is tedious, but also investing in doing it correctly when the company is small pays off when you go to scale. Think of it like renovating a house. You wouldn't hire a contractor to replace a light bulb. But you would pay him to install the light fixture.
