How to hire a fractional CISO in the UK
What the seat covers and costs is on the fractional CISO page. This is the part that usually goes unwritten: how to interview for it, what should be true by day ninety, and when this hire is the wrong answer entirely.
UK day rates for the seat run £900–£1,500. All eleven seats compared →
Six questions to ask, and what a strong answer sounds like
Every question here asks for something that happened, not something they believe. An operator who has genuinely held the seat answers from memory; one who has advised from the sidelines answers in the abstract, and the difference is audible within a minute.
1. Walk me through the last ISO 27001 or SOC 2 programme you ran end to end. What was the starting point, and how long did it really take?
Listen for: Strong answers describe the specific company's starting posture, the gap analysis, the stage one and stage two audits, and something that went wrong on the way. Weak answers describe the standard itself, which anyone can read, rather than a run they actually led.
2. An enterprise prospect sends a 300-question security questionnaire due Friday. What do you actually do first?
Listen for: You want triage: which answers are deal-killers, which honest no answers can carry a remediation date, and a call to the buyer's security team where useful. Anyone who suggests answering everything yes should end the interview; a false questionnaire answer is worse than a lost deal.
3. Tell me about a real incident you handled. What did the first hour look like, and who did you call?
Listen for: A specific incident with containment steps, a decision about the ICO's 72-hour reporting window, and what changed afterwards. If every example is a tabletop exercise, they have the theory but have never run one live, which matters at 2am.
4. What would you refuse to spend money on at a company our size?
Listen for: Strong answers name things: a 24/7 SOC, an enterprise SIEM, a full red team before the basics exist. A CISO who cannot name controls that are disproportionate for you will happily build a FTSE-100 programme on your seed-stage budget.
5. One of our critical vendors is a two-person startup. How do you handle their security review?
Listen for: Risk-based thinking: what data they touch, contractual controls, an exit plan, and an explicit written acceptance of the residual risk. A weak answer runs the same pass-or-fail checklist used for AWS, which either blocks the vendor pointlessly or waves them through blind.
6. In your last fractional engagement, who did you report to, and how did the board hear about security risk?
Listen for: The strong answer is CEO or board, with a short risk register in business terms and specific decisions asked of them. Reporting into IT and presenting tool dashboards is a sign they run projects, not risk.
Red flags
- Arrives with a product shopping list before asking what data you hold and what a breach would actually cost you. Tooling first, risk second is the wrong way round and it gets expensive.
- Promises a certification timeline before asking a single question about your current posture. Anyone offering ISO 27001 in six weeks unseen is selling a template pack, not a security programme.
- Cannot explain a risk without acronyms. Half this job is talking to an enterprise buyer's procurement team and your board; if you cannot follow them in the interview, neither will the people who matter.
- Every control they propose assumes a security team exists to run it. If they have never operated where engineering is four people and there is no one to delegate to, the programme will be designed for staff you do not have.
What day ninety should look like
Agree these before they start, in writing, in the brief. A fractional engagement without a ninety-day marker drifts into a retainer nobody remembers the point of.
- A risk register exists in business language, with named owners, and the top five risks are each either mitigated or formally accepted by you in writing. Explicit acceptance is the test that the register is real.
- The questionnaire that triggered the hire is answered and the deal unblocked, and a reusable answer library exists so the next one takes days rather than weeks.
- An incident response plan is written and has been walked through once, even as a one-hour tabletop, and the certification path is scoped with dates, audit cost and a named auditor.
When a fractional CISO is the wrong answer
- You are mid-breach right now. You need an incident response firm today, this week, on retainer terms, and a fractional CISO afterwards to make sure there is no second time.
- You want hands on keyboards: endpoints configured, firewalls tuned, alerts watched. That is a security engineer or a managed provider, at well under £900 a day, and a CISO will subcontract it anyway.
- Nothing external is forcing it: no sensitive data, no enterprise pipeline, no regulator. Cyber Essentials through your IT provider and sensible defaults cover you for now, and the £900 to £1,500 a day is better spent elsewhere.
If one of those is you, say so in a brief anyway and we will tell you straight. Sometimes the honest answer is interim or full-time, and pointing that out costs us nothing because the operator never pays us either way.
What to put in the brief
- Name the forcing event: which deal, which certification, which regulator, and the real deadline. Fractional CISOs plan and price around the trigger, and a brief without one reads as a seat with no mandate.
- State the stack and who can implement: cloud provider, engineering headcount, whether anyone can action controls. A CISO with no hands to direct will either decline or quote separately for the doing, and it is better to know which before they start.
- The thing founders forget: decide who can accept risk. If every accepted risk needs founder sign-off, say so in the brief, and commit to giving the operator direct access to whoever the enterprise buyer's security team wants to interrogate.
Two ways in, one of them free
Browse verified fractional fractional CISOs on the bench and book direct at no cost, or brief Operator Search and we run the interviews above for you.