Interim CISO · Chief Information Security Officer · Fixed term

Interim CISO · what one does, how long, what it costs

An interim CISO is a Chief Information Security Officer who takes the whole security seat, full-time, for a fixed term: to lead the recovery from a breach, get a certification over the line, answer a regulator or hold the seat through a vacancy. They own security risk, the incident plan and the board report while they are there, then hand over.

Across every discipline, the Institute of Interim Management’s 2026 survey puts the average interim assignment at 10.0 months. Below: what an interim CISO does stage by stage, what one costs, and how the role differs from a fractional or permanent CISO. We recruit interim, fractional, part-time, temporary and permanent security leaders.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

£1,000–£1,500+
Contract CISO day rate · Global / EMEA CISO
Barclay Simpson, 2026
10.0 months
Average assignment · all interim disciplines
IIM survey, 2026
£907
Average interim day rate · all disciplines, not a CISO rate
IIM survey, 2026
3–5
Shortlist · with day rate, availability and IR35 set out

15 minutes · video or phone

Book 15 minutes to hire an interim CISO

Tell us the scope and the days a week. We come back with interim CISO candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

On the board · last 3 months

Interim CISO jobs on the board

0 Interim CISO · 1 fractional CISO

No Interim CISO roles on the board in the last three months. Showing fractional CISO roles instead.

Live interim and fractional CISO roles

How fractional recruitment agencies compare is set out in one place, including how we work: a interim CISO brief and a shortlist of three to five.

01/ the role

What is an interim CISO? The named owner of security risk, for a fixed term

What is an interim CISO? A senior security executive who runs the CISO seat in full for a set period, usually against a defined outcome, then leaves. The Institute of Interim Management defines interim management as leadership by an independent, board or near-board level manager or executive, over a finite time span. An interim CISO holds the authority of the seat: the security budget, the team, the providers and the report to the board.

Not a service, a person

A managed security provider runs monitoring and response. A virtual CISO advises for a few days a month. An interim CISO is neither: one named person, on site as the work needs, who is accountable for the risk and can be asked to explain it to the board, the auditors or a regulator. The security operations centre, the penetration testers and the tooling stay where they are; the interim CISO directs them.

CISO, CIO or head of information security?

A CISO owns information security and cyber risk across the business and usually reports to the CEO, the CIO or the risk committee. A CIO runs the technology estate and its suppliers; if the brief is a systems programme with a security strand, an interim CIO may be the better hire. A head of information security usually runs the function a level below. For the permanent remit, see what a CISO does.

02/ scope

How to hire an interim CISO

Write down the outcome before the job title: the incident closed and reported, the certificate issued, the regulator’s findings answered, the permanent CISO appointed. Decide who the interim reports to, what they can sign off and which providers they direct. Then hire for that outcome, not for the title: an interim who has led a ransomware recovery is not automatically the right person for a first ISO 27001 audit.

Take a reference from the board member or audit chair the candidate last reported to, not only their line manager. To hire an interim CISO through us, brief us on the interim CISO hiring page, or browse interim CISO jobs there. We send a shortlist of 3–5, each with day rate, availability and IR35 position set out, after five-stage vetting.

03/ economics

What an interim CISO costs the day rate, and what moves it

An interim CISO is paid a day rate for the days worked, usually five a week, with no bonus, pension or notice period on top. No source we trust publishes an interim CISO day rate as such. The nearest published figure is Barclay Simpson’s 2026 Cyber Security Salary Guide, which puts a contract CISO at Global or EMEA level at £1,000 to £1,500 or more a day, against a permanent base of £180,000 or more.

For context across all disciplines, not for CISOs alone, the IIM’s 2026 Interim Management Survey puts the average interim day rate at £907 and the private-sector average at £1,004. Treat those as the floor for senior interims, not as a CISO rate. Urgency, regulation and the size of the estate move the rate more than the title does.

Against a permanent hire, Robert Half’s 2026 guide puts a London CISO between £131,000 at the 25th percentile and £220,000 at the 75th, with a median of £184,000, before employer costs. For part-time security leadership, see the fractional CISO cost page.

04/ comparison

Interim, fractional or permanent three ways to fill the seat

The same CISO seat, filled three ways. Choose by how many days the work needs and whether it has an end.

Interim CISOFractional CISOPermanent CISO
Days a weekUsually fiveA few days a week or a monthFive
TermFixed, tied to an outcomeOngoing, reviewedOpen-ended
How paidDay rateDay rate or monthly retainerSalary and benefits
Published costContract CISO £1,000–£1,500+ a day (Barclay Simpson)Virtual CISO £1,200–£2,500 a day (Cypro)London median £184,000 (Robert Half)
Best forA breach, a deadline or a gapSteady security leadership part of the weekLong-term ownership of security

05/ vetting

How we vet interim CISOs

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify interim CISO tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

06/ interim ciso

Interim CISO: what one does, stage by stage

An interim CISO works through an assignment in stages. The IIM’s guide to interim management names five: entry, diagnosis, proposal, implementation and exit. On a security assignment they map onto the incident or the programme.

Entry and diagnosis

The first weeks go on what is really there: the assets, the controls that work and the ones that only exist on paper, the providers and their contracts, the open findings and the risk register. After a breach, the first read is the incident itself. The NCSC’s incident management guidance covers how to detect, respond to and resolve cyber incidents, and links the response plan to disaster recovery, business continuity and crisis management.

The proposal

Then a plan to the sponsor: what to fix now, what to accept and record, what to buy and what to build. The IIM expects the interim’s proposal to challenge the original brief where the diagnosis says it should, and a security diagnosis often does.

Implementation

Running the programme and the function together. Where personal data is involved, the clock matters: the ICO’s breach reporting guidance sets a short legal deadline for notifying a reportable breach, and expects an organisation to report early and update later. On a certification brief the work is building an information security management system that meets ISO/IEC 27001, or getting the five technical controls of Cyber Essentials in place for a contract that requires them.

Exit and handover

A written record of risks, controls, providers and open decisions, a team that can run what was built, and often help appointing the permanent CISO. Before leaving, many interims set the board up to govern the risk itself: the government’s Cyber Governance Code of Practice shows boards and directors how to manage digital risks, and is the natural framework for that handover.

07/ interim ciso vs fractional ciso

Interim CISO vs fractional CISO: an outcome, or continuity

Interim CISO vs fractional CISO comes down to days and duration. An interim CISO takes the whole seat, full-time, for a fixed term, usually to deliver one outcome. A fractional CISO takes part of the seat, a few days a week or a month, with no set end, to give security senior direction the business could not otherwise afford.

Choose interim when an incident, an audit date or a regulator needs someone senior every day, or when the CISO has left in the middle of one. Choose fractional when security runs well enough day to day but nobody senior owns the strategy, the risk register or the board report. Cypro, which sells a virtual CISO service, publishes £1,200 to £2,500 a day for one, or £3,000 to £15,000 a month, against £140,000 to £220,000 base for a full-time CISO. For part-time roles, see virtual CISO jobs.

08/ when to hire

When to hire an interim CISO and for how long

Four situations account for most interim CISO briefs. A breach: an incident that needs a senior owner while it is contained, reported and learned from. A deadline: ISO 27001, SOC 2 or a supplier assurance requirement with a date attached. A regulator or an auditor: findings that need answering by someone who can sign for them. A departure: the CISO leaves with a programme half done and the board still asking about risk. If the work is steady rather than urgent, hire a fractional CISO instead; see the CISO jobs page for permanent roles.

How long? Tie the term to the outcome rather than a round number of months, with a review point and an agreed way to extend if an audit date moves. Across all disciplines the IIM’s 2026 survey puts the average assignment at 10.0 months; it is an all-discipline average, not a CISO rule.

09/ questions

Interim CISO FAQ

The questions people ask before bringing in an interim CISO.

A Chief Information Security Officer who takes the whole security seat full-time for a fixed term, usually to lead a breach recovery, a certification or the function through a vacancy, then hands over. They hold the authority of the seat: the budget, the team, the providers and the board report.
Diagnoses the security position, proposes a plan to the sponsor, runs the programme and the function, and exits with a written handover, following the stages the Institute of Interim Management describes. They direct the security providers rather than replace them.
Until the outcome agreed at the start, with a review point. The IIM’s 2026 survey puts the average interim assignment, across all disciplines, at 10.0 months; that is not a CISO-specific figure.
A day rate for the days worked. No source we trust publishes an interim CISO rate as such; Barclay Simpson’s 2026 guide puts a contract CISO at Global or EMEA level at £1,000 to £1,500 or more a day. Across all interim disciplines the IIM’s 2026 survey puts the average day rate at £907. We set out each candidate’s day rate on the shortlist.
An interim CISO works full-time for a fixed term, usually against one outcome. A fractional CISO works part of the week or month on an ongoing basis. Interim for a breach, a deadline or a gap; fractional for steady part-time direction of security.
After a breach that needs a senior owner, before a certification or supplier assurance deadline, when a regulator or auditor has findings to answer, or when the CISO leaves in the middle of a programme.
Name the outcome, the reporting line, what the interim can sign off and who they hand over to, then send us the brief through the interim CISO hiring page. We send a shortlist of 3–5 interim CISOs, each with day rate, availability and IR35 position set out. You interview and choose.
It depends on how the assignment runs in practice, contract by contract. In most cases the client decides; for a small client outside the public sector, the interim’s own company decides (HMRC). Our IR35 guide sets out the tests.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

For hiring managers

Bring the brief. We bring the shortlist.

Sign up now →Book a call

  1. A shortlist of 3–5, each with day rate, availability and IR35 position
  2. Fractional, interim, part-time, temporary or permanent — and non-executive directors
  3. Every candidate through our five-stage vetting
  4. Your briefs and their candidates, in one room
Fractional Quest logo — how to hire an interim CISO, interim CISO