Virtual CISO services in India exist because of a specific gap. You have outgrown "the IT manager also handles security" (enterprise customers are sending questionnaires, an auditor is asking who owns the risk register) but a full-time chief information security officer is a senior salary you cannot yet justify.
A vCISO fills the role rather than advising it. Someone owns the security strategy, chairs the governance, signs off on risk, prepares the audit, answers the customer questionnaire, runs the incident when there is one, and presents to your board, on an agreed number of days per month, at a fraction of the cost of the position.
The engagement works because the role is largely judgement and accountability rather than volume of hours. Where it needs to become a full-time internal role, we say so and help you recruit into it. Where you need the plan before the accountability, start with cybersecurity strategy and governance.