New Zealand organisations are increasingly turning to virtual CISOs (vCISOs) rather than full-time hires. This guide sets out the pricing benchmarks published by NZ and ANZ providers in 2026, what those numbers should cover, and how to evaluate a proposal.
The published NZ / ANZ benchmarks
Two providers have published clear pricing anchors for the ANZ market:
Insicon Cyber (ANZ) publishes an approximate monthly retainer of NZ$8,000-$15,000 for 10-20 hours of executive guidance per month. The scope typically covers governance, risk management, compliance frameworks, and board reporting, with remote delivery and quarterly on-site strategic reviews.
NSP New Zealand publishes the full-time CISO comparison: NZ$180,000-$250,000+ per year in total compensation, before recruitment fees and benefits. NSP positions its vCISO as delivering the same calibre of leadership at a fraction of the cost with a flexible engagement model.
What you should expect a vCISO to include at NZ$8-15k/month
At this price point, the following scope items are standard in the NZ market:
- Named CISO with backup cover — a principal vCISO and a named backup, both currently sitting in NZ vCISO seats. Leadership cover continues if the primary vCISO is unavailable.
- Multi-year security strategy — aligned to NZISM, ISO 27001, APRA CPS 234 (if in financial services), and sector regulations.
- Governance and risk framework — governance model, risk register, policy suite, and risk appetite statement.
- Board and executive reporting — quarterly board papers, risk dashboards, and attendance at risk or audit committee meetings.
- Programme oversight — independent assurance over major security programmes and architecture decisions.
- Team coaching — mentoring for in-house security staff, not replacing them.
- Regulatory engagement — representing the organisation in regulator conversations and audit response.
If a vCISO proposal at this price point excludes any of the above, ask why.
What a vCISO should NOT be doing at this price point
At NZ$8-15k/month for 10-20 hours, the vCISO is executive leadership. They are not:
- Running your SOC or writing your detection rules
- Performing hands-on penetration testing or vulnerability scanning
- Writing incident response playbooks from scratch (they oversee; someone junior drafts)
- Managing day-to-day security operations
- Filling a full-time CISO role's ~40 hours per week
If your need is hands-on delivery, a vCISO is the wrong instrument. You need a security engineering engagement or an in-house senior consultant on retainer.
Full-time CISO vs vCISO — the numbers
| Cost dimension | Full-time NZ CISO | vCISO (10-20 hrs/month) |
|---|---|---|
| Annual cost | NZ$180,000-$250,000+ | NZ$96,000-$180,000 |
| Recruitment cost | 15-25% of salary | None |
| Recruitment time | 6-12 months (per Insicon research) | 48-72 hours |
| Notice period | 3+ months | 30 days typical |
| Time to strategic impact | 3-6 months (onboarding) | First month |
| Suitable for | Enterprises with a mature security function | SMEs, growing organisations, interim cover |
The cost gap narrows when the vCISO is a senior operator whose day rate reflects that seniority. The bigger difference is optionality — you can scale a vCISO engagement up or down; you cannot easily do that with a full-time hire.
When a vCISO is the right choice
A vCISO fits when one or more of the following is true:
- Your organisation is between 50 and 500 staff and does not yet warrant a full-time CISO
- You need CISO-level leadership within 30 days (audit, incident, board pressure)
- Your budget does not yet stretch to NZ$300k+ all-in for a full-time hire
- You want to test the CISO function before committing to a permanent hire
- Your risk profile changes seasonally or by programme
When a vCISO is the wrong choice
Be honest about the following situations:
- You have a critical incident and need 40+ hours per week of hands-on leadership for 6+ months
- Your regulator specifically requires a named, in-house CISO (rare, but check your obligations)
- Your organisation's security maturity is so low that no strategic layer is worth building yet — you need a security manager and technical uplift first
How to evaluate a vCISO proposal
Ask these six questions of any NZ vCISO proposal:
- Who is the named CISO on the engagement, and is that person doing the work? Not a delivery lead with the "CISO" title on the org chart of the delivering firm.
- How many other vCISO seats does this individual currently hold? Two to three simultaneous seats is normal; five or more is dilution.
- What is the backup cover model? Named backup, not "the wider team."
- What is the escalation path if I disagree with the vCISO's advice? You need a peer inside the provider's practice.
- How is the engagement measured? Board-report cadence, risk register maintenance, roadmap milestones. If the answer is "hours logged," that is a time-and-materials contract, not executive leadership.
- What is the termination clause? 30 days notice is standard. Anything longer is a red flag for a growing organisation.
What CyberTeam offers
CyberTeam's vCISO service sits in the middle of the market. Our vCISOs are senior practitioners who currently hold or have held the CISO seat at NZ technology, financial-services, and government clients. When deeper delivery is needed we draw on the wider CyberTeam bench so the engagement scales without losing its CISO.
We publish our rate card structure — the more days committed, the lower the day rate — because we think buyers should not have to negotiate blind.
If you are scoping a vCISO engagement, book a 30-minute call with Tom. We will tell you honestly whether CyberTeam is the right choice, and if not, we will point you to who is.
