Fractional CISO · Chief information security officer, part of the week

Fractional CISO · what one does, what one costs, when you need one

A fractional CISO is a chief information security officer who holds the role for an agreed part of the week, on an ongoing basis, often for more than one company. They own the security strategy, the risk register and the response plan, and report to the CEO and board on cyber risk, without a full-time appointment.

This page explains the role: the week, the cost, how it compares with a virtual, interim or full-time CISO, and when you need one. To hire a fractional CISO or to browse fractional CISO jobs, go to the hub. We recruit fractional, interim, part-time, temporary and permanent security leaders.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

In the press

  • Fast Company 16 leaders on when fractional C-suite hires make sense · 24 Jun 2026

    Senior leaders disagree on when a fractional C-suite hire makes sense: many back one for a defined mandate, others want a full-time owner for work that needs daily attention. Security is where that test bites hardest, so it is worth reading before you scope the days.

3–5
Shortlist · with pay or day rate, availability and IR35 set out
5
Vetting · stages before a candidate reaches you
£1,200–£2,000
Fractional CISO day rate · a day
Optima Europe
£184,000
Full-time CISO salary, London median · 50th percentile
Robert Half, 2026

15 minutes · video or phone

Book 15 minutes to hire a fractional CISO

Tell us the scope and the days a week. We come back with CISO candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

Live CISO and security leadership roles

Fractional recruiting starts with the brief, not the CV pile. Send a CISO brief and we come back with a shortlist of three to five candidates, each through five-stage vetting.

01/ the role

What is a fractional CISO?

A fractional CISO is a chief information security officer engaged for part of the week, on an ongoing basis. The person holds the CISO seat in full: they set the security strategy, decide where to invest, and answer for cyber risk to the board, for an agreed number of days rather than five. “Fractional” describes the days, not the seniority.

The government’s Digital and Data capability framework describes the seat as creating a culture that keeps the organisation’s information and technology secure: a security strategy, an assessment of current maturity, advice to the board on risk, and readiness to detect, respond to and recover from an attack. A fractional CISO does that work in fewer days, so the days go on decisions rather than tickets.

CISO, CIO or security manager?

A CISO owns security risk across the business and reports on it to the board. A CIO owns the systems and suppliers, and security often sits with them until it needs its own seat. A security manager runs the controls day to day. If the gap is the wider technology estate, hire a fractional CIO instead. For the full seat, see what a CISO does.

02/ scope

What a fractional CISO does, week to week

The first month

An assessment of where security stands: what data the business holds, which systems and suppliers matter most, which controls are in place, and what would happen in an incident. The output is a risk register and a short roadmap the leadership team can agree and fund.

A typical week

Reviewing the risk register, working through the roadmap with the IT team or managed service provider, answering security questionnaires from customers, and checking suppliers. Much of it starts with the basics: the NCSC’s Cyber Essentials sets five technical controls (firewalls, secure configuration, security update management, user access control and malware protection) as the government’s recommended minimum.

The board

The Cyber Governance Code of Practice shows boards and directors how to govern cyber risk, and the NCSC’s Cyber Security Toolkit for Boards helps them put it into practice. A fractional CISO usually writes the board report against it and leads the response plan.

Data protection

Under the UK GDPR, personal data must be processed securely by “appropriate technical and organisational measures”, as the ICO’s guide to data security sets out. The CISO owns those measures; a fractional DPO often owns the wider data protection programme beside them.

03/ comparison

Fractional, virtual, interim or a full-time CISO

Four ways to put security leadership in place. Choose by how much of the week the work fills and whether you need one named person in the leadership team.

Fractional CISOVirtual CISO (vCISO)Interim CISOFull-time CISO
WhoOne named person in the leadership teamOften a service from a security firm, delivered remotelyOne named person, full-timeAn employee
Days and lengthPart of the week, ongoingA set number of days or hours a monthFull-time for a fixed termFull-time, permanent
Best forOwning security risk at board level without a full-time weekPolicy, compliance and advice to a defined scopeA breach, a departure or a deadline that needs someone every daySecurity that needs a daily owner
Published pay£1,200–£2,000 a day (Optima Europe)£3,000–£15,000 a month (Cypro)Global or EMEA contract £1,000–£1,500+ a day (Barclay Simpson)£184,000 London median (Robert Half)

04/ vetting

How we vet fractional CISOs

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify CISO tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

05/ what it costs

What a fractional CISO costs day rates, retainers and the full-time comparison

Optima Europe, a recruiter, puts a fractional CISO at £1,200 to £2,000 a day, with two-to-three-day weekly retainers at £8,000 to £18,000 a month. Cypro, which sells virtual CISO services, prices a vCISO at £3,000 to £15,000 a month, on a day rate of £1,200 to £2,500. These are their figures, not ours; we set out each candidate’s day rate on the shortlist.

For a full-time CISO, Robert Half’s 2026 guide gives a London band of £131,000 to £220,000 (25th to 75th percentile), median £184,000 (Robert Half). Cypro puts a full-time UK CISO at £140,000 to £220,000 base. A salary carries employer costs on top, and a day rate does not, so compare like with like.

The detail is on three pages: fractional CISO cost, CISO salary and vCISO cost and the fractional CISO hourly rate.

06/ fractional vs interim

Fractional CISO vs interim CISO ongoing cover, or a full-time stint

Fractional CISO vs interim CISO is a choice between ongoing part-week ownership and a full-time stint with an end date. A fractional CISO holds the seat for part of the week for as long as the business needs it. An interim CISO works full-time for a fixed period: after a breach, during a remediation programme, while a permanent CISO is found, or to meet a regulator’s or customer’s deadline.

Barclay Simpson, a recruiter, benchmarks a global or EMEA CISO on contract at £1,000 to £1,500 or more a day. An interim costs more in total because they work every day of the assignment. For full-time cover, see interim CISO jobs.

07/ fractional vs virtual

Fractional CISO vs virtual CISO how the vCISO relates

The two titles overlap, and some people use them interchangeably. In practice a virtual CISO (vCISO) is usually a service: a security firm provides CISO-level advice remotely, for a set number of days or hours a month, to a defined scope such as policies, certification or supplier questionnaires. A fractional CISO is one named person who joins the leadership team part of the week and owns security risk to the board.

If the need is a defined package of advice, a vCISO may be enough; see virtual CISO jobs and how to hire one. If the board wants a named owner of cyber risk, it is a fractional CISO. For what each engagement covers, see fractional CISO services.

08/ when

When to hire a fractional CISO the usual triggers

Companies usually look at when to hire a fractional CISO once security questions reach the board or the sales team before anyone senior owns them. The common triggers:

Customers asking for proof. Security questionnaires and audits from larger customers that hold up sales.

A certification to reach. Cyber Essentials, or ISO 27001 (see our ISO 27001 consultant page).

A board asking about cyber risk. Directors who want to govern it as the Cyber Governance Code describes, and need someone to report to them.

After an incident or a review. A near miss, or a cyber security assessment that found gaps no one owns.

If an incident is live and needs someone every day, an interim CISO fits better. When security fills the week, most companies move to a full-time CISO; we recruit that permanent hire too.

09/ hiring

How to hire one the short version

Write down what the CISO must deliver in the next twelve months, who they report to, what they can spend and how many days that takes. Ask candidates for a CISO role they held in a business like yours, and check certifications with the issuing body: the ISC2’s CISSP, for example, is aimed at experienced practitioners leading a security programme.

Settle the contract before the start date. Where the CISO works through their own company, the off-payroll working rules (IR35) may apply; status depends on how the engagement runs in practice, and a medium or large client makes the determination (HMRC’s guidance for clients). Our IR35 guide explains the tests.

To hire a fractional CISO through us, send the brief. We send a shortlist of 3–5, each with day rate or pay, availability and IR35 position set out, after our five-stage vetting.

10/ questions

Fractional CISO FAQ

The questions people ask before bringing in a fractional CISO.

A chief information security officer who holds the role for part of the week, on an ongoing basis, often for more than one company. They own the security strategy and the risk register, and report to the CEO and board on cyber risk.
Assesses where security stands, writes the risk register and roadmap, puts the basic controls in place, answers customers’ security questions, oversees suppliers, and reports to the board. The day-to-day controls stay with the IT team or a managed service provider.
A fractional CISO works part of the week on an ongoing basis. An interim CISO works full-time for a fixed period, such as after a breach or while a permanent CISO is found. See interim CISO jobs.
They overlap. A virtual CISO is usually a remote service from a security firm, to a defined scope and a set number of days a month. A fractional CISO is one named person in the leadership team who owns security risk. See virtual CISO.
When security questions reach the board or the sales team before anyone senior owns them: customer audits, a certification, a board asking about cyber risk, or gaps found after an incident or review.
Write the brief (outcomes, reporting line, budget and days), test candidates on a CISO role they held in a similar business, check certifications with the issuing body, and settle IR35 before the start. Or send us the brief: we send a shortlist of 3–5.
The day rate times the days. Optima Europe, a recruiter, puts a fractional CISO at £1,200 to £2,000 a day; Cypro prices a virtual CISO at £3,000 to £15,000 a month. Robert Half’s 2026 London median for a full-time CISO is £184,000. We set out each candidate’s day rate on the shortlist.
It depends on how the engagement runs in practice, not on the title. In most cases a medium or large client decides the status; for a small client outside the public sector, the worker’s own company decides (HMRC). We set out each candidate’s IR35 position and do not promise an outcome.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

For hiring managers

Bring the brief. We bring the shortlist.

Sign up now →Book a call

  1. A shortlist of 3–5, each with day rate, availability and IR35 position
  2. Fractional, interim, part-time, temporary or permanent — and non-executive directors
  3. Every candidate through our five-stage vetting
  4. Your briefs and their candidates, in one room
Fractional Quest logo — how to hire a fractional CISO, fractional CISO