Hire a fractional CISO
A fractional CISO owns security posture without the cost of a full-time hire most companies cannot yet justify. In practice they are often hired because an enterprise customer sent a security questionnaire nobody could answer.
What a fractional CISO owns
- Security strategy proportionate to your actual risk, not a generic checklist
- ISO 27001, SOC 2 and Cyber Essentials: the certification companies keep asking for
- Security questionnaires and enterprise procurement reviews
- Incident response planning, before you need it rather than during
- Vendor and supply chain risk, which is where a lot of exposure hides
Signs you need one
- An enterprise deal is blocked on a security review you cannot pass
- You handle sensitive data and nobody senior owns the risk
- You need ISO 27001 or SOC 2 and have no idea where to begin
- You had an incident, or a near miss, and it exposed how little was in place
What it costs in the UK
Among the highest fractional rates, driven by certification work and regulated sectors.
Rates are set by the operator and paid to them directly. We are not in the payment path, and the operator never pays us a fee.
How this compares
A penetration test finds vulnerabilities at a point in time. A managed security provider watches your systems. A CISO decides what risk you accept, owns the certification programme, and is the person an enterprise buyer or regulator wants to speak to.
What to look for
- Certification experience specifically, if that is what is blocking you
- Sector matters: fintech, health and public sector each carry different obligations
- Someone who talks about business risk rather than only tooling
- Ask whether they will do the certification work or just advise on it, and get that clear
Common questions
- What does a fractional CISO cost in the UK?
- Typically £900 to £1,500 a day, among the highest fractional rates. Many engagements are one to two days a week during a certification push, then reduce to a day or two a month for maintenance.
- Can a fractional CISO get us ISO 27001 or SOC 2?
- Yes, and it is one of the most common reasons companies hire one. Expect three to six months for ISO 27001 depending on your starting point. Confirm up front whether they are doing the work or advising on it, because both models exist at very different prices.
- We are small. Do we really need a CISO?
- Often not until something forces it, and then it is urgent. The usual trigger is an enterprise customer whose procurement process requires answers you cannot give. At that point a fractional CISO is the fastest route to an unblocked deal.
- What is the difference between a CISO and a penetration test?
- A pen test finds technical vulnerabilities on a given day. A CISO owns the whole security posture: policy, process, certification, vendor risk and incident readiness. You will likely want both, and the CISO will tell you when to book the test.
- Do you take a commission?
- No. You contract and pay the operator directly, and we take nothing from it.
Operator Search: £999 to run, £2,500 if you hire
Can't find the right CISO, or haven't got the time to look? We run the search and put three vetted operators in front of you in five business days. Both numbers agreed before anything starts, and the operator pays nothing either way.
Send a brief →