Assurance 1 day / week
- Security strategy and risk register ownership
- Customer security questionnaires and review calls
- Board and investor reporting on security posture
- Escalation route for the IT lead or MSSP
Fractional CISO services — also sold as virtual CISO or vCISO — put an accountable security leader into the business on a defined weekly commitment. Optima Europe publishes a UK fractional CISO day rate of £1,200–£2,000, with two-to-three-day retainers at £8,000–£18,000 a month.
This page covers what the service owns, where it stops, what the published rates are, and the one thing that decides whether you need a CISO at all or a managed security provider.
A fractional CISO service puts an accountable security leader into the business part-time.
The same service is widely sold as a virtual CISO or vCISO, and the labels are interchangeable in practice — what differs between vendors is whether you get a named individual with a standing commitment or a pooled service with a rotating contact.
Ask which, early.
The scope is accountability, not operations.
A fractional CISO owns the security strategy and the risk register, decides what gets controlled and what gets accepted, runs the response to customer security reviews and certification audits, and is the person who answers the board when something goes wrong.
Monitoring, alert triage and incident response tooling belong with your internal team or a managed security service provider.
A frequent reason to buy is external pressure: an enterprise customer’s security questionnaire, an insurer, a certification body, or an investor’s diligence.
Those are all conversations someone has to own, in the language the other side expects.
If you are hiring rather than buying a service, see Fractional CISO Jobs UK; for the full pricing picture, Fractional CISO Cost and Fractional CISO Hourly Rate.
Security strategy and the risk register — what is controlled, what is accepted, and who signed that off. Certification and assurance — ISO 27001, SOC 2, Cyber Essentials: owning the programme rather than filling in the spreadsheet. Customer security review — the questionnaires and the calls that unblock enterprise deals. Policy and governance proportionate to the business. Board-level accountability for security and incident readiness.
Twenty-four-hour monitoring, alert triage, penetration testing and incident-response execution.
That is a managed security service provider or an internal team, and it costs a fraction of a CISO day rate.
The CIO owns the systems the business runs on; the CISO owns security as a discipline in its own right.
Many mid-market businesses run security as part of the CIO brief until regulation, certification or customer review makes it a standing concern of its own — at which point it becomes a separate seat.
A managed security provider watches. A CISO decides what is worth watching, what is worth fixing, and what the business will simply accept. Buying the first when you need the second leaves you with better alerts and the same exposure.
Weekly cost at the midpoint of Optima Europe’s published UK fractional CISO day rate of £1,200–£2,000 — midpoint £1,600 (FACTS 193). Figures are that midpoint × days per week. The monthly retainer band on the same source is £8,000–£18,000 at two to three days a week.
Every figure below is published by the named source. Optima Europe and Cypro publish the fractional and virtual CISO bands; Robert Half, ITJobsWatch and Barclay Simpson publish the full-time benchmarks. Nothing here is a derivation.
| Benchmark | Published figure | Source |
|---|---|---|
| Fractional CISO day rate | £1,200–£2,000 | Optima Europe (193) |
| Retainer, 2–3 days a week | £8,000–£18,000/mo | Optima Europe (193) |
| Virtual CISO (vCISO) day rate | £1,200–£2,500 | Cypro (191) |
| vCISO monthly cost | £3,000–£15,000/mo | Cypro (191) |
| Contract CISO (Global / EMEA) | £1,000–£1,500+ | Barclay Simpson (193) |
| UK CISO advertised median | £137,650 | ITJobsWatch (193) |
| London CISO salary, median | £184,000 | Robert Half (192) |
| Full-time CISO, fully loaded | £180,000–£270,000 | Cypro (191) |
The three ways a UK company gets accountable security leadership, on the dimensions that decide between them.
| Metric | Fractional / virtual CISO | Managed security provider | Full-time CISO hire |
|---|---|---|---|
| Published UK cost | £3,000–£15,000/mo (Cypro) or £8,000–£18,000/mo at 2–3 days (Optima Europe) | Per-seat or per-device monthly fee | £180,000–£270,000 fully loaded (Cypro) |
| What you are buying | Accountability and decisions | Monitoring and response capacity | Both, full-time |
| Signs the questionnaire | Yes — named, accountable | No | Yes |
| Owns certification | Yes | Supports it | Yes |
| Best when | Security is a standing concern, not yet a full-time seat | You need eyes on the estate | Regulation or scale makes it full-time work |
| Exit | Notice, or convert to core | Contract end | Redundancy or resignation |
Three situations where an accountable part-time security leader beats both an MSSP and a permanent hire.
Enterprise deals keep stalling in a questionnaire nobody internally can answer with authority. This is the fastest-paying reason to buy the seat, and it is measurable.
A certification programme needs an owner who has run one before. Consultants can prepare the documents; someone has to make the decisions the documents describe.
Post-incident, the question is not only what was fixed but who is accountable now. A named security owner is among the first things customers and insurers ask for.
Five stages: qualification, mandate fit, reference deep-dive, shortlist and analysis, kick-off. Our fee is 12% of engagement value and is only triggered when you sign — the shortlist costs nothing if you do not hire.
How we take a founder or board's brief and turn it into a delivery system across core, fractional, network, and outsourced functions.
CONFIRM — REAL PROCESSStage · pressure · the work nobody is doing.
We run The Team Architect on every brief. Stage, headcount, sector, pressure. The output is the org shape we'd build with you — including the seats to hold for now. We turn briefs down here, gracefully, when the answer is 'not yet'.
Core. Fractional. Network. Outsourced.
Each function gets a verdict and an intensity. Engineering core. Finance fractional at 2.5 d/wk. Paid-media on the network. IT helpdesk outsourced. We commit to days, IR35 status, and replacement terms in writing before search starts.
Network-first. Outbound where it needs to be.
Fractional candidates have portfolios, not job alerts. We run from our own network plus a structured outbound for the senior end. Shortlist in 8–12 days. Honest scoring against the rubric — no padding.
First-week plan. Success criteria. IR35 live.
Calibration calls. Onboarding plan written down. IR35 structure live before day one. We sit in the first cross-functional meeting if it helps. The replacement guarantee runs for 90 days.
Quarterly cadence. Bridge to core when right.
Monthly check-ins for the first quarter, quarterly after. We surface when a fractional should convert to core (Series A → Series B finance is the modal moment) and we own the bridge. Replacement, conversion, off-ramp — it's all the same firm.
Common questions about fractional CISO Services roles and engagements
Current openings and market opportunities
We don't fabricate listings to pad a feed. Register for alerts and we'll surface roles in this shape the moment they appear — exclusive, syndicated, or fractional-curious.
Additional tools, guides, and role information
More of the same shape — internal.
