Ian Findlay
Fractional CIO | CIO Practice Lead | Chief Information Officer
I spent 20 years running a managed service provider (MSP). I know how the vCIO model was built, what it was designed to do, and how it actually gets used in practice. So when I tell you that a Virtual CIO and a Fractional CIO are not the same thing, I’m not making a competitive argument. I’m describing two fundamentally different roles with two fundamentally different sets of incentives.
The term Virtual CIO was coined by the MSP industry, which matters for understanding what the role is actually designed to do.
MSPs — Managed Service Providers — are outsourced IT companies. Smaller businesses hire them instead of building an internal IT team, and for a fixed monthly fee they get helpdesk support, network management, security monitoring, and a range of other technical services. It’s a solid model, and for the right company it works well.
At some point, MSPs recognized that their clients were also asking bigger questions. Beyond the basic “can you fix my laptop” variety and more towards “what technology should we be investing in,” “are we secure,” and “how should we be thinking about IT as we grow.” Enter the vCIO role. In theory, the vCIO would function as a strategic advisor: helping the client set IT direction, evaluate investments, and navigate the technology landscape.
Here’s the structural reality of the vCIO model: the person filling that role works for the MSP. Their compensation, their performance metrics, and their job security are all tied to the MSP’s business outcomes, not yours (the client’s). That just means their advice comes with a frame around it, whether intentional or not.
In practice, what I saw from the inside is that vCIOs often function as sophisticated account managers. They’re good at maintaining client relationships, identifying opportunities to expand services, and keeping the account healthy from the MSP’s perspective. Those are legitimate business functions, but they’re not independent strategic advice.
You have to look at the recommendations themselves. A truly independent IT advisor will sometimes tell you, for example, that you’re spending too much, that a vendor relationship isn’t working, or that your MSP isn’t fulfilling its job. A vCIO working for that MSP is structurally prevented from giving you that last piece of advice, even if it’s exactly what you need to hear.
I recently conducted an IT Health Assessment (an independent 3rd party review of a company’s IT systems) for a large healthcare organization. On the surface, the MSP appeared to be doing a good job – staff was happy with the helpdesk, security tools were deployed, and the company didn’t seem to have many IT issues. What I discovered, however, was a veneer of competency. The company experienced two cyber security breaches in the span of six months – and, in spite of these incidents, very, very significant security and IT system issues existed. The issue is that these problems existed before the breaches, and they remained after the breaches, directly the result of incompetent vCIO leadership for the company, and placing the organization in serious jeapordy. Unfortunately, this lack of technical diligence and leadership is very common amongst vCIOs that I see.
That isn’t to say that all vCIOs fall into this unfortunate bucket – there are a few that I have worked with who are very impressive, diligent, and focus on what is right for the client first – these are the MSPs that I recommend when conducting an MSP search for a client.
To be sure, quality varies enormously from one MSP to the next, and from one person to the next within the same MSP. There are many talented, experienced people in those roles who genuinely deliver strategic value to their clients.
The difference, when it exists, usually comes down to three things: the depth of the individual’s actual IT experience, the degree to which the MSP genuinely empowers them to give objective advice even when it’s uncomfortable, and whether the vCIO has performance targets for selling goods and services to their clients. Some MSPs do build a culture that values honest, direct feedback. But – for those MSPs where the vCIO’s compensation is tied to the revenue growth of their clients, the conflict of interest can be stark.
The honest answer is that most companies don’t know which kind of vCIO they have until they bring in someone who can assess it independently.
When speaking with an MSP about their services, it is helpful to understand a few points about how they manage the client relationship.
The goal here is to understand if your primary point of contact is a vCIO and what their primary job is – if their job is to manage your account and sell you services, I would look elsewhere.
A Fractional CIO is a senior technology executive who works as a member of your company on a part-time basis, the amount varying entirely based on the needs of the company. I work with clients between 5 and 300 employees, and the amount of time I spend with each one varies greatly (from 2-4 hours per month to 2-4 hours per day). The engagement is scoped to what the company actually needs, not to what fills a vendor’s revenue target.
In theis context the fractional CIO role functions as the head of Corporate IT for their client, and does what a full-time head of corporate IT would: managing the IT team, setting IT strategy, managing risk, overseeing vendors, evaluating technology investments, and making sure the company’s infrastructure is built for where it’s going, not just where it is at the moment. The difference is that you’re getting that leadership at the size and frequency that makes sense for your business, without the overhead of a full-time executive hire.
The other difference is independence — I don’t sell services or have an MSP relationship to protect. When I tell a client their current IT vendor isn’t performing, it’s because it’s in the best interests of the client. Over the last three years I’ve helped roughly ten companies replace their IT teams or MSPs for exactly that reason. That kind of advice is only possible when there’s no financial conflict behind it.
I also work with MSPs. I recommend them to clients, I help clients select them, and I manage those relationships on the client’s behalf. The MSP handles operations. I handle strategy. Those are complementary functions, and for the most part it works perfectly.
This type of situation comes up not infrequently: a company has an MSP with a vCIO relationship in place and things seem to be running fine. Then something prompts them to bring in outside perspective, like a growth event, merger, security incident, or it could simply be a sense that IT isn’t functioning properly.
What I typically find in those situations is one of three things.
MSPs do important work and most of them do it well. But the VCIO role exists inside a business model, and that business model has its own set of interests. That’s not a good or bad thing, just important to understand.
The question every company should be asking is simple: is the strategic IT advice I’m getting coming from someone whose only interest is my company’s technology health? If the answer is yes, you’re in good shape. If you’re not sure, it’s worth finding out.
A Fractional CIO isn’t the right answer for every company at every stage. But independence and objectivity are, and whatever form your IT leadership takes, those two things should be non-negotiable. If you’re not sure what you’re actually getting from your IT advisor, you’re not alone. An IT health assessment from one of our experienced Fractional CIOs is a straightforward way to find out where you actually stand across your infrastructure, your security posture, your vendor relationships, and your IT strategy. No agenda, just clarity.
FAQ
It depends on what the company actually needs. If the primary requirement is operational IT support with some account-level guidance, a VCIO relationship through a solid MSP can work well. Where it falls short is when the company needs genuinely independent strategic advice — especially around vendor performance, IT investment decisions, or technology direction tied to business growth. Those are situations where the MSP’s conflict of interest becomes a real limitation.
Yes, and it’s not unusual. The Fractional CIO provides independent strategic leadership and vendor oversight, while the MSP’s VCIO manages the day-to-day operational relationship. The key is clarity about who owns what — and making sure the Fractional CIO has the standing to evaluate the MSP relationship objectively.
It varies entirely by the needs of the client, and likely will fluctuate for that same client throughout a year depending on what the company is experiencing. So, a Fractional CIO may be averaging 4 hours a week with a client, but then the client begins a major project (like a migration to cloud services), or begins a significant expansion, in which case the amount of time needed for the Fractional CIO may need to double (or more) for a period of time. Typically a Fractional CIO is embedded with the company, attending leadership meetings, managing vendor relationships, overseeing IT operations, actively managing the company’s technical systems, and driving whatever strategic initiatives are on the roadmap. The engagement scales with the company’s needs and evolves as the business grows.
A good MSP relationship is a solid foundation — not a substitute for IT leadership. The MSP handles operations. A Fractional CIO handles strategy: making sure your technology decisions are aligned with your business goals, your vendor relationships are performing, and your IT foundation is built for where the company is going. Those are different jobs, and a good MSP will tell you the same thing.
Get the latest insights from TechCXO’s fractional executives—strategies, trends, and advice to drive smarter growth.
I spent 20 years running a managed service provider (MSP). I know how the vCIO model was built, what it was designed to do, and how it actually gets used in practice. So when I tell you that a Virtual CIO and a Fractional CIO are not the same thing, I’m not making a competitive argument. I’m describing two fundamentally different roles with two fundamentally different sets of incentives.
The term Virtual CIO was coined by the MSP industry, which matters for understanding what the role is actually designed to do.
MSPs — Managed Service Providers — are outsourced IT companies. Smaller businesses hire them instead of building an internal IT team, and for a fixed monthly fee they get helpdesk support, network management, security monitoring, and a range of other technical services. It’s a solid model, and for the right company it works well.
At some point, MSPs recognized that their clients were also asking bigger questions. Beyond the basic “can you fix my laptop” variety and more towards “what technology should we be investing in,” “are we secure,” and “how should we be thinking about IT as we grow.” Enter the vCIO role. In theory, the vCIO would function as a strategic advisor: helping the client set IT direction, evaluate investments, and navigate the technology landscape.
Here’s the structural reality of the vCIO model: the person filling that role works for the MSP. Their compensation, their performance metrics, and their job security are all tied to the MSP’s business outcomes, not yours (the client’s). That just means their advice comes with a frame around it, whether intentional or not.
In practice, what I saw from the inside is that vCIOs often function as sophisticated account managers. They’re good at maintaining client relationships, identifying opportunities to expand services, and keeping the account healthy from the MSP’s perspective. Those are legitimate business functions, but they’re not independent strategic advice.
You have to look at the recommendations themselves. A truly independent IT advisor will sometimes tell you, for example, that you’re spending too much, that a vendor relationship isn’t working, or that your MSP isn’t fulfilling its job. A vCIO working for that MSP is structurally prevented from giving you that last piece of advice, even if it’s exactly what you need to hear.
I recently conducted an IT Health Assessment (an independent 3rd party review of a company’s IT systems) for a large healthcare organization. On the surface, the MSP appeared to be doing a good job – staff was happy with the helpdesk, security tools were deployed, and the company didn’t seem to have many IT issues. What I discovered, however, was a veneer of competency. The company experienced two cyber security breaches in the span of six months – and, in spite of these incidents, very, very significant security and IT system issues existed. The issue is that these problems existed before the breaches, and they remained after the breaches, directly the result of incompetent vCIO leadership for the company, and placing the organization in serious jeapordy. Unfortunately, this lack of technical diligence and leadership is very common amongst vCIOs that I see.
That isn’t to say that all vCIOs fall into this unfortunate bucket – there are a few that I have worked with who are very impressive, diligent, and focus on what is right for the client first – these are the MSPs that I recommend when conducting an MSP search for a client.
To be sure, quality varies enormously from one MSP to the next, and from one person to the next within the same MSP. There are many talented, experienced people in those roles who genuinely deliver strategic value to their clients.
The difference, when it exists, usually comes down to three things: the depth of the individual’s actual IT experience, the degree to which the MSP genuinely empowers them to give objective advice even when it’s uncomfortable, and whether the vCIO has performance targets for selling goods and services to their clients. Some MSPs do build a culture that values honest, direct feedback. But – for those MSPs where the vCIO’s compensation is tied to the revenue growth of their clients, the conflict of interest can be stark.
The honest answer is that most companies don’t know which kind of vCIO they have until they bring in someone who can assess it independently.
When speaking with an MSP about their services, it is helpful to understand a few points about how they manage the client relationship.
The goal here is to understand if your primary point of contact is a vCIO and what their primary job is – if their job is to manage your account and sell you services, I would look elsewhere.
A Fractional CIO is a senior technology executive who works as a member of your company on a part-time basis, the amount varying entirely based on the needs of the company. I work with clients between 5 and 300 employees, and the amount of time I spend with each one varies greatly (from 2-4 hours per month to 2-4 hours per day). The engagement is scoped to what the company actually needs, not to what fills a vendor’s revenue target.
In theis context the fractional CIO role functions as the head of Corporate IT for their client, and does what a full-time head of corporate IT would: managing the IT team, setting IT strategy, managing risk, overseeing vendors, evaluating technology investments, and making sure the company’s infrastructure is built for where it’s going, not just where it is at the moment. The difference is that you’re getting that leadership at the size and frequency that makes sense for your business, without the overhead of a full-time executive hire.
The other difference is independence — I don’t sell services or have an MSP relationship to protect. When I tell a client their current IT vendor isn’t performing, it’s because it’s in the best interests of the client. Over the last three years I’ve helped roughly ten companies replace their IT teams or MSPs for exactly that reason. That kind of advice is only possible when there’s no financial conflict behind it.
I also work with MSPs. I recommend them to clients, I help clients select them, and I manage those relationships on the client’s behalf. The MSP handles operations. I handle strategy. Those are complementary functions, and for the most part it works perfectly.
This type of situation comes up not infrequently: a company has an MSP with a vCIO relationship in place and things seem to be running fine. Then something prompts them to bring in outside perspective, like a growth event, merger, security incident, or it could simply be a sense that IT isn’t functioning properly.
What I typically find in those situations is one of three things.
MSPs do important work and most of them do it well. But the VCIO role exists inside a business model, and that business model has its own set of interests. That’s not a good or bad thing, just important to understand.
The question every company should be asking is simple: is the strategic IT advice I’m getting coming from someone whose only interest is my company’s technology health? If the answer is yes, you’re in good shape. If you’re not sure, it’s worth finding out.
A Fractional CIO isn’t the right answer for every company at every stage. But independence and objectivity are, and whatever form your IT leadership takes, those two things should be non-negotiable. If you’re not sure what you’re actually getting from your IT advisor, you’re not alone. An IT health assessment from one of our experienced Fractional CIOs is a straightforward way to find out where you actually stand across your infrastructure, your security posture, your vendor relationships, and your IT strategy. No agenda, just clarity.
FAQ
It depends on what the company actually needs. If the primary requirement is operational IT support with some account-level guidance, a VCIO relationship through a solid MSP can work well. Where it falls short is when the company needs genuinely independent strategic advice — especially around vendor performance, IT investment decisions, or technology direction tied to business growth. Those are situations where the MSP’s conflict of interest becomes a real limitation.
Yes, and it’s not unusual. The Fractional CIO provides independent strategic leadership and vendor oversight, while the MSP’s VCIO manages the day-to-day operational relationship. The key is clarity about who owns what — and making sure the Fractional CIO has the standing to evaluate the MSP relationship objectively.
It varies entirely by the needs of the client, and likely will fluctuate for that same client throughout a year depending on what the company is experiencing. So, a Fractional CIO may be averaging 4 hours a week with a client, but then the client begins a major project (like a migration to cloud services), or begins a significant expansion, in which case the amount of time needed for the Fractional CIO may need to double (or more) for a period of time. Typically a Fractional CIO is embedded with the company, attending leadership meetings, managing vendor relationships, overseeing IT operations, actively managing the company’s technical systems, and driving whatever strategic initiatives are on the roadmap. The engagement scales with the company’s needs and evolves as the business grows.
A good MSP relationship is a solid foundation — not a substitute for IT leadership. The MSP handles operations. A Fractional CIO handles strategy: making sure your technology decisions are aligned with your business goals, your vendor relationships are performing, and your IT foundation is built for where the company is going. Those are different jobs, and a good MSP will tell you the same thing.
Get the latest insights from TechCXO’s fractional executives—strategies, trends, and advice to drive smarter growth.