Hire a Fractional CISO · Fractional CISO Jobs UK
Hire a fractional CISO · Fractional CISO jobs UK
Hire a fractional CISO — cyber security leadership 1–3 days a week — for companies facing compliance requirements, security audits, customer security reviews and board-level risk reporting. UK-wide, from a single brief to a shortlist of 3–5, with the IR35 position set out on every brief.
- £1,200–£2,000 a day · Optima Europe 2026
- 1–3 days a week
- 3–5 candidates on every shortlist
- 5 stages of vetting
How a brief runswhat we undertake
- 01Brief30-MINUTE SCOPING CALLDay 0
- 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
- 03InterviewsYOU MEET THE SHORTLISTYour diary
- 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
- 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief
Shortlist3–5
15 minutes · video or phone
Book 15 minutes to hire a fractional CISO
Tell us the scope and the days a week. We come back with fractional CISO candidates, their day rates and availability.
- 0115 minutes, video or phone
- 02We scope the role and the days a week
- 03A shortlist of 3–5 after the call
- 04Fractional, interim and permanent briefs
Pick a day that suits · live availability
Fractional and virtual CISO jobs · last 3 months
Live Fractional CISO jobs
No live Fractional CISO roles in the last three months. Showing live fractional executive roles instead.
- FractionalSyndicated
Head of Medical Compliance, Governance & Diligence (Fractional)
CNX Therapeutics Ltd · Greater London
est £1,000/dayGreater London - FractionalSyndicated
Head of Applied Legal – AI Product (Fractional)
Stealth Startup · London
est £1,600/day2 d/wk - FractionalSyndicated
Fractional Product Practice Leader - 9 Month Contract
Tails.com · London
est £1,000/day2 d/wk - FractionalSyndicated
Fractional CPO
Log my Care · City of London
est £3,250/day3 d/wk - FractionalSyndicated
Fractional Finance Directors
PWF Associates Limited · Manchester
est £750/dayManchester - FractionalSyndicated
Fractional legal counsel
Nifina · London
est £750/dayLondon - FractionalExclusive
Fractional COO
Confidential client (Fractional Quest mandate) · London
Rate n/aLondon - FractionalSyndicated
Fractional Financial Controller
MarcoPolo Learning · City of Westminster
est £750/day2 d/wk - FractionalSyndicated
Chief Financial Officer
Fiberpay · Marlow
Rate n/a2 d/wk
01/ definition
What is a fractional CISO?
A fractional CISO is a part-time Chief Information Security Officer. Not a consultant, not an MSSP: the CISO, 1–3 days a week. Four ideas define the model.
01 · cadence
A chief information security officer, 1–3 days a week.
Senior, certified CISO capability across a defined slice of the week. You get the security leadership you need without a full-time salary or a five-day commitment.
02 · role
Owns security — not just an audit.
Unlike a consultant or pen-tester, a fractional CISO is in the leadership team: owns the security programme, risk register, compliance roadmap and incident response.
03 · terms
Paid by the day, not a salary.
A fractional CISO invoices a day rate for the days worked rather than drawing a full-time package — Optima Europe puts the UK band at £1,200–£2,000 a day (2026).
04 · horizon
A mandate, not a tenure.
Scoped to an outcome — ISO 27001 certification, SOC 2 compliance, post-breach recovery — often ending in a clean handover to a permanent CISO.
02/ scope
CISO responsibilities.
What a fractional CISO owns versus what they delegate — to your IT team, a managed security provider or a specialist supplier.
- Security strategy & roadmap
- Risk register & appetite
- Compliance programmes (ISO 27001, SOC 2)
- Incident response planning
- Board reporting & metrics
- Security team structure
- Vendor selection & management
- Policy & governance framework
- 24/7 SOC monitoring
- Hands-on penetration testing
- Day-to-day ticket resolution
- Firewall configuration
- Vulnerability patching
- Security awareness training delivery
- Log analysis & SIEM tuning
- Identity management operations
03/ alternatives
Fractional CISO vs alternatives.
How a fractional CISO compares with a virtual CISO, a managed security provider, a security consultant and a full-time appointment.
→ The labels overlap. Fractional CISO = embedded, day-rate leadership. Virtual CISO = remote-first, usually a monthly package — see hire a virtual CISO.
→ A fractional CISO leads security. An MSSP operates it.
→ Fractional CISOs run the security function. Consultants advise on it.
→ Cypro puts a virtual CISO at 5–10 days a month roughly 40–70% cheaper than a full-time CISO — the saving narrows as days rise.
04/ vocabulary
Fractional, virtual, interim, contract — what CISO hiring actually means.
Companies searching for CISO hiring or a CISO for hire rarely say “fractional”. They mean one of four engagements, and the right one depends on how many days the work needs and who has to answer for it.
AN OWNER
Fractional CISO
One named person, in your business one to three days a week, ongoing, accountable for the security programme rather than a deliverable. Usually priced by the day.
A PACKAGE
Virtual CISO (vCISO)
Remote-first and usually sold as a monthly package — Cypro publishes £3,000–£15,000 a month. See hire a virtual CISO.
A FIXED TERM
Interim or contract CISO
Full-time for a fixed term — cover for a departure, a remediation, an incident aftermath. Barclay Simpson publishes contract CISO rates of £1,000–£1,500+ a day. See interim CISO jobs.
A DECISION
Security consultant
Engaged for an assessment, a gap analysis or a certification readiness review, and delivers a document. Scope it as a project.
Which you want depends on whether you need an owner or a decision. If the security question will still need someone accountable next quarter, it is a seat, and fractional is the lightest way to fill it at this seniority. This is our reading of how the terms are used in the UK market, not a published definition.
05/ economics
Cost to hire a fractional CISO, UK 2026.
Published figures only, each with its source. Scope rises with regulatory load and estate complexity — a first security hire at a startup, ISO 27001 or SOC 2 at a scale-up, a multi-framework enterprise estate, a regulated financial services or healthcare firm. No source publishes a sector-by-sector band; Cypro puts rates above £2,000 a day on financial services, healthcare and M&A work.
- Fractional CISO£1,200–£2,000Optima Europe 2026
- Virtual CISO£1,200–£2,500Cypro 2026
- Contract CISO£1,000–£1,500+Barclay Simpson 2026
Two days a week across a 46-week year at the Optima Europe band is £110,400–£184,000 in day fees — our arithmetic (92 days × £1,200–£2,000).
06/ economics
Part-time CISO cost.
Model the cost against a full-time CISO, or what one fractional mandate earns.
£1,400 a day is within the published band for a UK fractional CISO (£1,200–£2,000, Optima Europe 2026).
Year-one cost
£128,800
2 d/wk · 46 weeks · day fees, before tax
Fractional costs less in year one£51,200
Book a 15-minute call →Our arithmetic, indicative. Full-time CISO = £180,000, the low end of Cypro’s £180,000–£270,000 fully loaded range (a £140,000–£220,000 base plus on-costs), so any saving shown is the conservative one.
07/ decision
When to hire a fractional CISO.
Four scenarios where it pays to hire a fractional CISO — and where fractional CISO jobs deliver the most for UK businesses.
Which sounds like you?
ISO 27001, SOC 2 or a sector-specific certification needed for growth or a contract. Consultants can prepare the documents; someone has to make the decisions the documents describe, and give the board assurance.
- → Credible leadership for a certification with a date
A breach has happened. You need credible leadership to engage the regulator, rebuild the programme and restore board and customer confidence.
- → A named owner after the incident
Regimes such as the FCA’s operational resilience rules in the UK, and NIS2 and DORA for firms operating in the EU, put accountability for security and ICT risk with senior management.
- → Named accountability · formal risk ownership · audit readiness
Due diligence needs credible security leadership and a mature programme: security DD preparation, risk quantification, and answers an investor or acquirer will accept.
- → Board-ready security leadership for the deal
08/ the buyer’s guide
CISO recruitment: how to hire a fractional CISO.
Scope the mandate first: the framework or deadline driving it, the regulator or customers asking, the size of the estate and the team, and the days a week the work needs. Set the budget against the published bands above — £1,200–£2,000 a day for a fractional CISO (Optima Europe), or £3,000–£15,000 a month for a virtual CISO package (Cypro).
Assess on track record leading security at your stage, not certificates alone: ask for the last certification they owned end to end, the last incident they ran, and a board paper they wrote. Take references from recent clients. Then start with a defined first phase — a gap analysis and roadmap, or the first stage of a certification — before settling into a steady weekly cadence.
If you are looking at chief information security officer recruitment agencies for a permanent hire, that is usually a retained search: UK retained search fees run 25–35% of first-year total compensation, with £30,000–£40,000 minimum fees common at established firms (Headhunters.co.uk, March 2026). We recruit fractional, interim and permanent CISOs: a shortlist of 3–5, each with day rate or pay, availability and IR35 position set out. See how we run fractional searches.
09/ structure
Fractional CISO services: scope, contract and terms.
A fractional CISO engagement sets out the scope, the days a week, the day rate and the notice period. IR35 status depends on how the engagement runs in practice, and a medium or large client makes the status determination. HMRC looks at the three points below. Reference: HMRC off-payroll working (IR35) guidance and the CEST tool. See the IR35 guide.
TEST 1 / SUBSTITUTION
Right of substitution
Whether the CISO could send a suitably qualified substitute, and whether that right is real in practice.
✓ In the contractTEST 2 / CONTROL
Control
Whether the company directs how, when and where the CISO works, or defines the outcomes and leaves the method to them.
✓ In the contractTEST 3 / MUTUALITY
Mutuality
Whether the company must offer work beyond the agreed mandate, and whether the CISO must accept it.
✓ In the contract10/ for security leaders
CISO jobs: fractional, interim and contract roles.
Most CISO jobs advertised in the UK are permanent, and this page does not list those. What it carries are the other routes into the seat: fractional roles of one to three days a week, interim and contract CISO roles for a fixed term, and part-time security leadership. The board above shows each posting as it is advertised, with the day rate where the posting states one.
What the roles ask for is consistent. The UK government’s chief information security officer role description sets out the remit most employers work to: a security strategy that supports the organisation’s own, a view of risk across the organisation reported to the board, readiness to detect, respond to and recover from an attack, and a security-aware culture. Postings commonly ask for a recognised certification — ISC2’s CISSP or ISACA’s CISM — alongside a record of leading certification, incident and board work.
For fractional work, the portfolio matters as much as the CV: a CISO with several clients needs clear terms on incident cover and on conflicts between clients. See interim CISO jobs for full-time fixed-term roles and remote fractional jobs for remote security leadership.
11/ what the board expects
CISO hiring: what boards and regulators expect.
CISO hiring is increasingly led by the board. The NCSC’s Cyber Security Toolkit for Boards, built around the government’s Cyber Governance Code of Practice, sets out how directors should oversee cyber risk — and a board that has to oversee it needs someone to report to it. That is often the first reason to hire a CISO, fractional or full-time.
Decide what the hire must deliver first. For many smaller companies it is a baseline: the government-backed Cyber Essentials scheme covers the most common internet-based threats, and a growing number of organisations ask suppliers to hold it. For companies handling personal data at scale, it is showing that security is appropriate to the risk, as the ICO’s guide to data security requires under UK GDPR. For regulated firms, it is the accountability their regulator expects.
Then hire to that outcome. A baseline, or a certification with a date, suits a fractional CISO on one to three days a week; running a large security team day to day needs a full-time seat. The recruitment guide above covers how to scope and assess candidates; to compare costs, see fractional CISO cost.
12/ process
How we vet CISOs.
The CISO-specific checks inside our five-stage vetting process, undertaken on every brief before a candidate reaches your shortlist.
- 01
Security credibility
Verify a real track record leading security at your stage — not just an audit or pen-testing background.
SOURCING - 02
Certification check
Validate certifications (CISSP, CISM, sector-specific) and that they are current.
VERIFICATION - 03
Reference validation
We speak to recent clients and boards ourselves: real outcomes, not just tenure.
DUE DILIGENCE - 04
Shortlist delivery
3–5 candidates, each with day rate, availability, fit and IR35 position set out.
SHORTLIST OF 3–5
13/ questions
Fractional CISO FAQ.
Common questions about hiring and working as a fractional CISO.
For comparison, the advertised UK median salary for a permanent CISO is £137,650 (ITJobsWatch, mid-2026), before employer on-costs; Cypro puts a full-time CISO at £180,000–£270,000 fully loaded. Use the calculator above for your numbers.
The question worth asking either way is whether you get a named individual or a pooled service. We run searches for both through the same brief — see hire a virtual CISO.

Book 15 minutes · shortlist of 3–5
Bring the brief.
We architect the team.
A shortlist of 3–5. Five-stage vetting. IR35 position on every brief.
For hiring companies
Book a call or submit your fractional CISO brief; we come back with a shortlist of 3–5 candidates.
For fractional CISOs
Browse live fractional and interim CISO roles from our jobs feed, or get in touch about the searches we run.
