Hire a Fractional CISO · Fractional CISO Jobs UK

Hire a fractional CISO · Fractional CISO jobs UK

Hire a fractional CISO — cyber security leadership 1–3 days a week — for companies facing compliance requirements, security audits, customer security reviews and board-level risk reporting. UK-wide, from a single brief to a shortlist of 3–5, with the IR35 position set out on every brief.

  • £1,200–£2,000 a day · Optima Europe 2026
  • 1–3 days a week
  • 3–5 candidates on every shortlist
  • 5 stages of vetting

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

£1.2–2.0k
Fractional CISO day rate band
Optima Europe 2026
£8–18k
Monthly retainer, 2–3 days a week
Optima Europe 2026
3–5
Candidates on every shortlist
Our commitment
5
Vetting stages
Our commitment

15 minutes · video or phone

Book 15 minutes to hire a fractional CISO

Tell us the scope and the days a week. We come back with fractional CISO candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

01/ definition

What is a fractional CISO?

A fractional CISO is a part-time Chief Information Security Officer. Not a consultant, not an MSSP: the CISO, 1–3 days a week. Four ideas define the model.

01 · cadence

A chief information security officer, 1–3 days a week.

Senior, certified CISO capability across a defined slice of the week. You get the security leadership you need without a full-time salary or a five-day commitment.

1–3 daysa week

02/ scope

CISO responsibilities.

What a fractional CISO owns versus what they delegate — to your IT team, a managed security provider or a specialist supplier.

  • Security strategy & roadmap
  • Risk register & appetite
  • Compliance programmes (ISO 27001, SOC 2)
  • Incident response planning
  • Board reporting & metrics
  • Security team structure
  • Vendor selection & management
  • Policy & governance framework
  • 24/7 SOC monitoring
  • Hands-on penetration testing
  • Day-to-day ticket resolution
  • Firewall configuration
  • Vulnerability patching
  • Security awareness training delivery
  • Log analysis & SIEM tuning
  • Identity management operations
ISO 27001SOC 2GDPRRisk ManagementIncident ResponseCloud SecurityZero TrustBoard Reporting

03/ alternatives

Fractional CISO vs alternatives.

How a fractional CISO compares with a virtual CISO, a managed security provider, a security consultant and a full-time appointment.

Fractional CISOVirtual CISO
ModelOn-site + remote hybridRemote-first, usually
PresenceIn the room for the boardMostly video; on site by arrangement
PricingDay rate, days usedMonthly package, more often
AccountabilityNamed risk ownerVaries — named lead or a pooled service
Best forRegulated industries, active programmesSMEs & startups needing a steady governance rhythm

→ The labels overlap. Fractional CISO = embedded, day-rate leadership. Virtual CISO = remote-first, usually a monthly package — see hire a virtual CISO.

04/ vocabulary

Fractional, virtual, interim, contract — what CISO hiring actually means.

Companies searching for CISO hiring or a CISO for hire rarely say “fractional”. They mean one of four engagements, and the right one depends on how many days the work needs and who has to answer for it.

AN OWNER

Fractional CISO

One named person, in your business one to three days a week, ongoing, accountable for the security programme rather than a deliverable. Usually priced by the day.

A PACKAGE

Virtual CISO (vCISO)

Remote-first and usually sold as a monthly package — Cypro publishes £3,000–£15,000 a month. See hire a virtual CISO.

A FIXED TERM

Interim or contract CISO

Full-time for a fixed term — cover for a departure, a remediation, an incident aftermath. Barclay Simpson publishes contract CISO rates of £1,000–£1,500+ a day. See interim CISO jobs.

A DECISION

Security consultant

Engaged for an assessment, a gap analysis or a certification readiness review, and delivers a document. Scope it as a project.

Which you want depends on whether you need an owner or a decision. If the security question will still need someone accountable next quarter, it is a seat, and fractional is the lightest way to fill it at this seniority. This is our reading of how the terms are used in the UK market, not a published definition.

05/ economics

Cost to hire a fractional CISO, UK 2026.

Published figures only, each with its source. Scope rises with regulatory load and estate complexity — a first security hire at a startup, ISO 27001 or SOC 2 at a scale-up, a multi-framework enterprise estate, a regulated financial services or healthcare firm. No source publishes a sector-by-sector band; Cypro puts rates above £2,000 a day on financial services, healthcare and M&A work.

Published UK day-rate bands · £ a day
  • Fractional CISO£1,200–£2,000Optima Europe 2026
  • Virtual CISO£1,200–£2,500Cypro 2026
  • Contract CISO£1,000–£1,500+Barclay Simpson 2026
Fractional CISO bandComparator band
EngagementPublished figureSource
Fractional CISO£1,200–£2,000 a dayOptima Europe 2026
Fractional CISO retainer, 2–3 days a week£8,000–£18,000 a monthOptima Europe 2026
Virtual CISO (vCISO)£1,200–£2,500 a day · £3,000–£15,000 a monthCypro 2026
Contract CISO (Global / EMEA)£1,000–£1,500+ a dayBarclay Simpson 2026
Full-time CISO, UK advertised median£137,650ITJobsWatch, mid-2026 ↗
Full-time CISO, London£184,000 median (£131,000–£220,000)Robert Half 2026 ↗
Full-time CISO, fully loaded£180,000–£270,000 a yearCypro 2026

Two days a week across a 46-week year at the Optima Europe band is £110,400–£184,000 in day fees — our arithmetic (92 days × £1,200–£2,000).

06/ economics

Part-time CISO cost.

Model the cost against a full-time CISO, or what one fractional mandate earns.

Days a week needed2 days

£1,400 a day is within the published band for a UK fractional CISO (£1,200–£2,000, Optima Europe 2026).

Year-one cost

£128,800

2 d/wk · 46 weeks · day fees, before tax

Fractional CISO£128,800
Full-time CISO, loaded£180,000

Fractional costs less in year one£51,200

Book a 15-minute call →

Our arithmetic, indicative. Full-time CISO = £180,000, the low end of Cypro’s £180,000–£270,000 fully loaded range (a £140,000–£220,000 base plus on-costs), so any saving shown is the conservative one.

07/ decision

When to hire a fractional CISO.

Four scenarios where it pays to hire a fractional CISO — and where fractional CISO jobs deliver the most for UK businesses.

Which sounds like you?

ISO 27001, SOC 2 or a sector-specific certification needed for growth or a contract. Consultants can prepare the documents; someone has to make the decisions the documents describe, and give the board assurance.

  • → Credible leadership for a certification with a date

A breach has happened. You need credible leadership to engage the regulator, rebuild the programme and restore board and customer confidence.

  • → A named owner after the incident

Regimes such as the FCA’s operational resilience rules in the UK, and NIS2 and DORA for firms operating in the EU, put accountability for security and ICT risk with senior management.

  • → Named accountability · formal risk ownership · audit readiness

Due diligence needs credible security leadership and a mature programme: security DD preparation, risk quantification, and answers an investor or acquirer will accept.

  • → Board-ready security leadership for the deal

08/ the buyer’s guide

CISO recruitment: how to hire a fractional CISO.

Scope the mandate first: the framework or deadline driving it, the regulator or customers asking, the size of the estate and the team, and the days a week the work needs. Set the budget against the published bands above — £1,200–£2,000 a day for a fractional CISO (Optima Europe), or £3,000–£15,000 a month for a virtual CISO package (Cypro).

Assess on track record leading security at your stage, not certificates alone: ask for the last certification they owned end to end, the last incident they ran, and a board paper they wrote. Take references from recent clients. Then start with a defined first phase — a gap analysis and roadmap, or the first stage of a certification — before settling into a steady weekly cadence.

If you are looking at chief information security officer recruitment agencies for a permanent hire, that is usually a retained search: UK retained search fees run 25–35% of first-year total compensation, with £30,000–£40,000 minimum fees common at established firms (Headhunters.co.uk, March 2026). We recruit fractional, interim and permanent CISOs: a shortlist of 3–5, each with day rate or pay, availability and IR35 position set out. See how we run fractional searches.

09/ structure

Fractional CISO services: scope, contract and terms.

A fractional CISO engagement sets out the scope, the days a week, the day rate and the notice period. IR35 status depends on how the engagement runs in practice, and a medium or large client makes the status determination. HMRC looks at the three points below. Reference: HMRC off-payroll working (IR35) guidance and the CEST tool. See the IR35 guide.

TEST 1 / SUBSTITUTION

Right of substitution

Whether the CISO could send a suitably qualified substitute, and whether that right is real in practice.

✓ In the contract

TEST 2 / CONTROL

Control

Whether the company directs how, when and where the CISO works, or defines the outcomes and leaves the method to them.

✓ In the contract

TEST 3 / MUTUALITY

Mutuality

Whether the company must offer work beyond the agreed mandate, and whether the CISO must accept it.

✓ In the contract

10/ for security leaders

CISO jobs: fractional, interim and contract roles.

Most CISO jobs advertised in the UK are permanent, and this page does not list those. What it carries are the other routes into the seat: fractional roles of one to three days a week, interim and contract CISO roles for a fixed term, and part-time security leadership. The board above shows each posting as it is advertised, with the day rate where the posting states one.

What the roles ask for is consistent. The UK government’s chief information security officer role description sets out the remit most employers work to: a security strategy that supports the organisation’s own, a view of risk across the organisation reported to the board, readiness to detect, respond to and recover from an attack, and a security-aware culture. Postings commonly ask for a recognised certification — ISC2’s CISSP or ISACA’s CISM — alongside a record of leading certification, incident and board work.

For fractional work, the portfolio matters as much as the CV: a CISO with several clients needs clear terms on incident cover and on conflicts between clients. See interim CISO jobs for full-time fixed-term roles and remote fractional jobs for remote security leadership.

11/ what the board expects

CISO hiring: what boards and regulators expect.

CISO hiring is increasingly led by the board. The NCSC’s Cyber Security Toolkit for Boards, built around the government’s Cyber Governance Code of Practice, sets out how directors should oversee cyber risk — and a board that has to oversee it needs someone to report to it. That is often the first reason to hire a CISO, fractional or full-time.

Decide what the hire must deliver first. For many smaller companies it is a baseline: the government-backed Cyber Essentials scheme covers the most common internet-based threats, and a growing number of organisations ask suppliers to hold it. For companies handling personal data at scale, it is showing that security is appropriate to the risk, as the ICO’s guide to data security requires under UK GDPR. For regulated firms, it is the accountability their regulator expects.

Then hire to that outcome. A baseline, or a certification with a date, suits a fractional CISO on one to three days a week; running a large security team day to day needs a full-time seat. The recruitment guide above covers how to scope and assess candidates; to compare costs, see fractional CISO cost.

12/ process

How we vet CISOs.

The CISO-specific checks inside our five-stage vetting process, undertaken on every brief before a candidate reaches your shortlist.

  1. 01

    Security credibility

    Verify a real track record leading security at your stage — not just an audit or pen-testing background.

    SOURCING
  2. 02

    Certification check

    Validate certifications (CISSP, CISM, sector-specific) and that they are current.

    VERIFICATION
  3. 03

    Reference validation

    We speak to recent clients and boards ourselves: real outcomes, not just tenure.

    DUE DILIGENCE
  4. 04

    Shortlist delivery

    3–5 candidates, each with day rate, availability, fit and IR35 position set out.

    SHORTLIST OF 3–5

13/ questions

Fractional CISO FAQ.

Common questions about hiring and working as a fractional CISO.

A part-time chief information security officer who owns your security programme within a defined scope — risk management, compliance, governance and incident response. Not a consultant, not an MSSP: the CISO, 1–3 days a week.

The published UK band is £1,200–£2,000 a day (Optima Europe, 2026); at two days a week that is £2,400–£4,000 a week (our arithmetic). Optima Europe puts two-to-three-day weekly retainers at £8,000–£18,000 a month.

For comparison, the advertised UK median salary for a permanent CISO is £137,650 (ITJobsWatch, mid-2026), before employer on-costs; Cypro puts a full-time CISO at £180,000–£270,000 fully loaded. Use the calculator above for your numbers.

Yes — that’s exactly what a fractional CISO is: a Chief Information Security Officer working 1–3 days a week, embedded in your leadership team and owning the security programme, risk register and compliance roadmap.

The terms overlap, and many providers use them interchangeably. In practice a fractional CISO is usually embedded — in the room for board meetings, owning risk formally, leading the team — and priced by the day. A virtual CISO is usually remote-first and sold as a monthly package: Cypro publishes £3,000–£15,000 a month, and £3,000–£6,000 for a smaller business taking 4–6 days a month.

The question worth asking either way is whether you get a named individual or a pooled service. We run searches for both through the same brief — see hire a virtual CISO.

Usually, yes. “CISO for hire” is how many buyers search for a senior security leader engaged through their own company rather than employed. The distinction that matters is cadence: one to three days a week, ongoing, is fractional; five days for a fixed term is interim.

Look for CISSP, CISM or CCSP as a baseline. For regulated sectors, specific qualifications such as QSA (PCI DSS) or CISA (audit) matter. Experience trumps certificates, though: ask for the last certification programme they owned end to end.

Submit your brief and we shortlist 3–5 fractional CISOs, each with day rate, availability, fit and IR35 position set out. You interview and choose.

Yes. We recruit fractional, interim and permanent CISOs: a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out. If you use a retained search firm instead, UK retained search fees run 25–35% of first-year total compensation (Headhunters.co.uk). Many companies bring in a fractional CISO first, and use them to write the permanent brief.

It depends on how the engagement runs in practice — control, substitution and mutuality of obligation — not on the title. A medium or large client makes the status determination; HMRC’s CEST tool is the reference.

Both, in that order. Set the baseline first — Cyber Essentials for the most common threats, and security appropriate to the risk under UK GDPR — then make sure the board can oversee cyber risk, which the NCSC’s Toolkit for Boards sets out. A baseline or a certification with a date suits a fractional CISO; running a large security team needs a full-time one.

Book 15 minutes · shortlist of 3–5

Bring the brief.
We architect the team.

A shortlist of 3–5. Five-stage vetting. IR35 position on every brief.

For hiring companies

Book a call or submit your fractional CISO brief; we come back with a shortlist of 3–5 candidates.

For fractional CISOs

Browse live fractional and interim CISO roles from our jobs feed, or get in touch about the searches we run.

Fractional Quest logo — how to hire a fractional CISO, fractional CISO jobs UK