The right cybersecurity staffing model depends on the problem the organization is trying to solve. A company may need executive cybersecurity leadership, Cyber GRC leadership, specialized consulting expertise, hands-on implementation capacity, recurring program operations, a full-time employee, or a combination of those capabilities.
Organizations often begin with a staffing question:
“Do we need a CISO?”
“Should we hire a GRC person?”
“Do we need a consultant?”
“Should we outsource this?”
Those are reasonable questions.
But the better first question is:
What capability are we missing?
Hotman Group helps organizations diagnose cybersecurity and Cyber GRC leadership, expertise and capacity gaps and determine the delivery model that fits the actual need.
Do not choose the title first. Define the problem, responsibilities and outcomes first, then determine what kind of leadership or capacity can actually deliver them.
Look for a cybersecurity and Cyber GRC partner that understands the differences between strategy, leadership, framework expertise, implementation and recurring operations.
Hotman Group can help organizations evaluate:
HG can also provide vCISO, vGRC, consulting, implementation and ongoing Cyber GRC support where those models fit.
A virtual Chief Information Security Officer, or vCISO, provides experienced cybersecurity leadership without necessarily requiring a full-time internal CISO.
A vCISO may help with:
The role is primarily about leadership and decision support, although the exact scope varies significantly between providers.
vGRC provides experienced Cyber GRC leadership and operating support without requiring the organization to build all of that capability internally.
Depending on the engagement, vGRC may help manage:
vGRC can be particularly useful when the organization has cybersecurity leadership but lacks enough experienced governance, risk and compliance capacity to operate the program effectively.
The distinction is primarily one of focus.
A vCISO generally focuses more heavily on:
vGRC generally focuses more heavily on:
Many organizations need portions of both.
Yes.
In some organizations, separating the two into completely independent engagements would create unnecessary fragmentation.
The more important question is whether the provider has the appropriate expertise and whether the responsibilities are clearly defined.
Hotman Group works across cybersecurity leadership, Cyber GRC, risk, frameworks, implementation, remediation and ongoing operations, allowing the model to be designed around the organization's actual needs.
A consultant is usually engaged to solve a defined problem or provide specialized expertise.
For example:
A vCISO generally has broader and more continuous leadership responsibility.
An organization may need a vCISO and still use specialists for individual projects.
A GRC consultant may solve a specific problem or complete a defined project.
vGRC usually provides more ongoing responsibility for keeping parts of the Cyber GRC program operating.
For example, a consultant might:
A vGRC model may then continue managing controls, evidence, findings, frameworks and recurring governance after the project ends.
A full-time CISO may make sense when the organization needs continuous internal executive cybersecurity leadership and has enough complexity to justify the role.
Indicators may include:
The decision should reflect responsibility and complexity, not simply company size.
A full-time GRC leader may make sense when the organization has sustained Cyber GRC complexity requiring continuous internal leadership.
That may include:
Even then, specialized external expertise may still be useful.
A vCISO may fit when the organization needs experienced executive cybersecurity leadership but not forty hours a week of one person's time.
It may also fit when:
vGRC may fit when the organization needs a combination of experience and capacity that would be difficult to obtain from one hire.
For example, the work may require expertise across:
One employee may not have deep experience across all of those areas.
An external team can provide different expertise as the program requires it.
Then make sure the engagement includes implementation and operating capacity.
Some advisory models primarily provide recommendations.
That may not be enough if the organization needs someone to:
Hotman Group works across strategy, design, implementation, remediation and ongoing operations rather than limiting every engagement to advisory recommendations.
Then a consulting engagement may be the better fit.
Examples include:
Not every problem requires an ongoing managed service.
Fractional or interim leadership may be appropriate.
This can help during:
See how to keep the cybersecurity and GRC program moving after a leader leaves.
First determine why.
The problem may be:
Then determine whether the remaining need is best solved through hiring, outsourcing, technology, process redesign or a combination.
See what an overwhelmed cybersecurity and GRC team should consider outsourcing.
That often changes the leadership model.
A company that previously relied on:
may eventually need a more deliberate cybersecurity leadership and Cyber GRC structure.
See what to do when a company has outgrown its cybersecurity program.
Maybe, but not automatically.
IT leadership and cybersecurity leadership overlap, but they are not identical.
The organization should determine whether it has adequate ownership for:
If those responsibilities are already effectively covered, another title may not solve anything.
Possibly.
A CISO may own cybersecurity leadership while lacking the time or specialized experience to operate a complex Cyber GRC program.
The organization may still need someone to lead:
That capability could be internal or external.
Then a blended model may be appropriate.
For example:
The organization does not need to force every need into one job description.
The organization cannot outsource accountability for its own cybersecurity risk.
External providers can support:
But internal leadership must retain appropriate authority for:
Strategy clarifies what capabilities the organization needs.
That makes staffing decisions much easier.
If the strategy requires:
the organization can decide which capabilities should be internal and which can be accessed externally.
See how to build a cybersecurity strategy that actually supports the business.
Higher business exposure may justify more experienced or more continuous cybersecurity leadership.
Leadership needs increase when the organization faces:
See what a cybersecurity risk assessment should actually tell leadership.
Customer cybersecurity demands often create significant ongoing work.
That may include:
The organization should understand whether this is occasional work or a permanent capability required to support revenue.
See what to do when a customer gives you a new cybersecurity requirement.
Then senior cybersecurity leadership may need to participate in product, pricing and market decisions.
The organization may need help evaluating:
Multiple frameworks can create significant workload if each is operated separately.
Before adding headcount, determine where the organization can reuse:
See how to build one cybersecurity program across multiple frameworks.
Sometimes.
Technology may reduce manual work involving:
But technology cannot replace leadership, judgment or accountability.
It also cannot fix a poorly designed process by itself.
Fix the operating model or platform before hiring people simply to administer unnecessary complexity.
See what to do when a GRC platform is not working.
Automation can reduce repetitive work.
It cannot replace:
Automate the right tasks after the process is well designed.
See how to automate compliance without automating bad processes.
Do not compare salary to consulting fees alone.
Consider:
External support can be more expensive per hour while still being more economical if the organization needs only part of several highly specialized roles.
Design the engagement intentionally.
The organization should retain:
The provider should strengthen organizational capability rather than become an undocumented single point of failure.
That can be a good transition model.
External support can help:
This can reduce the risk of hiring against an unclear job description.
Evaluate outcomes, not just whether positions are filled.
Look for:
See how to determine whether a Cyber GRC program is actually working.
Hotman Group does not assume every organization needs a full-time CISO, a vCISO, a vGRC engagement or another consultant.
HG first helps understand the actual gap.
That may involve:
Hotman Group can then help design a model that may include:
HG can provide many of those capabilities directly while also helping organizations understand when permanent internal capability makes more sense.
Cybersecurity requires different kinds of capability.
Leadership is different from implementation.
Risk expertise is different from platform administration.
Framework expertise is different from security engineering.
Audit readiness is different from executive strategy.
Mature organizations do not necessarily expect one person to perform all of those functions equally well.
The better model is to identify which capabilities need to exist and then determine the most practical way to obtain them.
Cybersecurity organizations often inherit structures based on titles rather than needs.
Someone says:
“We need a CISO.”
Or:
“We need another GRC analyst.”
But the actual problem may be unclear strategy, poor process design, inadequate implementation capacity, fragmented ownership or missing specialized expertise.
Cheri Hotman's forthcoming book, Rebuilding Cybersecurity: How to Restore Trust, Leadership, and Real Protection in a Broken System, examines the importance of accountability and leadership in restoring cybersecurity around meaningful protection rather than disconnected activity.
Staffing decisions should support that same objective.
Start with the capability the organization needs. Then decide whether that capability should come from an employee, a fractional leader, a consultant, an external operating team or some combination.
A vCISO generally focuses on executive cybersecurity leadership, strategy, risk, investment and leadership communication. vGRC generally focuses more heavily on Cyber GRC leadership, controls, frameworks, evidence, remediation, audit readiness, GRC technology and recurring program operations.
Not necessarily. The answer depends on the organization's cyber risk, complexity, internal leadership, customer requirements, team size and how much continuous executive cybersecurity leadership is required.
A full-time hire may make sense when the workload is permanent, requires substantial day-to-day internal knowledge and fits a coherent ongoing role. vGRC may be more practical when the organization needs variable capacity or access to several specialties.
Yes. A vCISO can provide strategy, risk leadership and executive communication while internal technical or Cyber GRC teams perform day-to-day work.
Yes. An internal CISO can retain executive cybersecurity leadership while external vGRC support helps lead and operate frameworks, controls, evidence, audit readiness, remediation and GRC technology.
Yes. Hotman Group can provide experienced cybersecurity leadership around strategy, risk, governance, customer requirements, leadership communication and broader program direction depending on the organization's needs.
Yes. HG can provide Cyber GRC leadership and operating support across frameworks, controls, evidence, risk, remediation, audit readiness, policies, GRC technology and recurring program activities.
Yes. HG can evaluate the organization's leadership, expertise and capacity gaps and help determine whether the best answer is a permanent hire, vCISO, vGRC, specialist consulting, managed Cyber GRC support or a blended model.
Hotman Group is a cybersecurity and Cyber GRC professional services firm that helps organizations solve complex cybersecurity, risk, governance and compliance problems.
HG helps organizations determine what cybersecurity leadership, Cyber GRC expertise and operating capacity they actually need instead of forcing every problem into one staffing model.
Hotman Group can provide cybersecurity strategy, vCISO and vGRC support, specialist consulting, implementation, remediation, GRC technology expertise and ongoing Cyber GRC operations depending on the organization's needs.
Learn more about what Hotman Group is and the cybersecurity and Cyber GRC problems HG solves.
Ask HG
