Interim CISO · Chief Information Security Officer · Fixed term
Interim CISO · what one does, how long, what it costs
An interim CISO is a Chief Information Security Officer who takes the whole security seat, full-time, for a fixed term: to lead the recovery from a breach, get a certification over the line, answer a regulator or hold the seat through a vacancy. They own security risk, the incident plan and the board report while they are there, then hand over.
Across every discipline, the Institute of Interim Management’s 2026 survey puts the average interim assignment at 10.0 months. Below: what an interim CISO does stage by stage, what one costs, and how the role differs from a fractional or permanent CISO. We recruit interim, fractional, part-time, temporary and permanent security leaders.
How a brief runswhat we undertake
- 01Brief30-MINUTE SCOPING CALLDay 0
- 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
- 03InterviewsYOU MEET THE SHORTLISTYour diary
- 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
- 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief
Shortlist3–5
15 minutes · video or phone
Book 15 minutes to hire an interim CISO
Tell us the scope and the days a week. We come back with interim CISO candidates, their day rates and availability.
- 0115 minutes, video or phone
- 02We scope the role and the days a week
- 03A shortlist of 3–5 after the call
- 04Fractional, interim and permanent briefs
Pick a day that suits · live availability
On the board · last 3 months
Interim CISO jobs on the board
No Interim CISO roles on the board in the last three months. Showing fractional CISO roles instead.
Live interim and fractional CISO roles
How fractional recruitment agencies compare is set out in one place, including how we work: a interim CISO brief and a shortlist of three to five.
01/ the role
What is an interim CISO? The named owner of security risk, for a fixed term
What is an interim CISO? A senior security executive who runs the CISO seat in full for a set period, usually against a defined outcome, then leaves. The Institute of Interim Management defines interim management as leadership by an independent, board or near-board level manager or executive, over a finite time span. An interim CISO holds the authority of the seat: the security budget, the team, the providers and the report to the board.
Not a service, a person
A managed security provider runs monitoring and response. A virtual CISO advises for a few days a month. An interim CISO is neither: one named person, on site as the work needs, who is accountable for the risk and can be asked to explain it to the board, the auditors or a regulator. The security operations centre, the penetration testers and the tooling stay where they are; the interim CISO directs them.
CISO, CIO or head of information security?
A CISO owns information security and cyber risk across the business and usually reports to the CEO, the CIO or the risk committee. A CIO runs the technology estate and its suppliers; if the brief is a systems programme with a security strand, an interim CIO may be the better hire. A head of information security usually runs the function a level below. For the permanent remit, see what a CISO does.
02/ scope
How to hire an interim CISO
Write down the outcome before the job title: the incident closed and reported, the certificate issued, the regulator’s findings answered, the permanent CISO appointed. Decide who the interim reports to, what they can sign off and which providers they direct. Then hire for that outcome, not for the title: an interim who has led a ransomware recovery is not automatically the right person for a first ISO 27001 audit.
Take a reference from the board member or audit chair the candidate last reported to, not only their line manager. To hire an interim CISO through us, brief us on the interim CISO hiring page, or browse interim CISO jobs there. We send a shortlist of 3–5, each with day rate, availability and IR35 position set out, after five-stage vetting.
03/ economics
What an interim CISO costs the day rate, and what moves it
An interim CISO is paid a day rate for the days worked, usually five a week, with no bonus, pension or notice period on top. No source we trust publishes an interim CISO day rate as such. The nearest published figure is Barclay Simpson’s 2026 Cyber Security Salary Guide, which puts a contract CISO at Global or EMEA level at £1,000 to £1,500 or more a day, against a permanent base of £180,000 or more.
For context across all disciplines, not for CISOs alone, the IIM’s 2026 Interim Management Survey puts the average interim day rate at £907 and the private-sector average at £1,004. Treat those as the floor for senior interims, not as a CISO rate. Urgency, regulation and the size of the estate move the rate more than the title does.
Against a permanent hire, Robert Half’s 2026 guide puts a London CISO between £131,000 at the 25th percentile and £220,000 at the 75th, with a median of £184,000, before employer costs. For part-time security leadership, see the fractional CISO cost page.
04/ comparison
Interim, fractional or permanent three ways to fill the seat
The same CISO seat, filled three ways. Choose by how many days the work needs and whether it has an end.
05/ vetting
How we vet interim CISOs
What we undertake on every brief, before a candidate reaches you.
- 01
Qualification screen
Verify interim CISO tenure, sector context and stage fit.
SOURCING - 02
Mandate fit
Match to your situation — stage, board dynamics, timing.
MATCHING - 03
Reference deep-dive
We take references ourselves, from recent past clients — real outcomes, not titles.
VERIFY - 04
Shortlist
Three to five candidates with day rate, availability and IR35 position set out.
SHORTLIST OF 3–5
06/ interim ciso
Interim CISO: what one does, stage by stage
An interim CISO works through an assignment in stages. The IIM’s guide to interim management names five: entry, diagnosis, proposal, implementation and exit. On a security assignment they map onto the incident or the programme.
Entry and diagnosis
The first weeks go on what is really there: the assets, the controls that work and the ones that only exist on paper, the providers and their contracts, the open findings and the risk register. After a breach, the first read is the incident itself. The NCSC’s incident management guidance covers how to detect, respond to and resolve cyber incidents, and links the response plan to disaster recovery, business continuity and crisis management.
The proposal
Then a plan to the sponsor: what to fix now, what to accept and record, what to buy and what to build. The IIM expects the interim’s proposal to challenge the original brief where the diagnosis says it should, and a security diagnosis often does.
Implementation
Running the programme and the function together. Where personal data is involved, the clock matters: the ICO’s breach reporting guidance sets a short legal deadline for notifying a reportable breach, and expects an organisation to report early and update later. On a certification brief the work is building an information security management system that meets ISO/IEC 27001, or getting the five technical controls of Cyber Essentials in place for a contract that requires them.
Exit and handover
A written record of risks, controls, providers and open decisions, a team that can run what was built, and often help appointing the permanent CISO. Before leaving, many interims set the board up to govern the risk itself: the government’s Cyber Governance Code of Practice shows boards and directors how to manage digital risks, and is the natural framework for that handover.
07/ interim ciso vs fractional ciso
Interim CISO vs fractional CISO: an outcome, or continuity
Interim CISO vs fractional CISO comes down to days and duration. An interim CISO takes the whole seat, full-time, for a fixed term, usually to deliver one outcome. A fractional CISO takes part of the seat, a few days a week or a month, with no set end, to give security senior direction the business could not otherwise afford.
Choose interim when an incident, an audit date or a regulator needs someone senior every day, or when the CISO has left in the middle of one. Choose fractional when security runs well enough day to day but nobody senior owns the strategy, the risk register or the board report. Cypro, which sells a virtual CISO service, publishes £1,200 to £2,500 a day for one, or £3,000 to £15,000 a month, against £140,000 to £220,000 base for a full-time CISO. For part-time roles, see virtual CISO jobs.
08/ when to hire
When to hire an interim CISO and for how long
Four situations account for most interim CISO briefs. A breach: an incident that needs a senior owner while it is contained, reported and learned from. A deadline: ISO 27001, SOC 2 or a supplier assurance requirement with a date attached. A regulator or an auditor: findings that need answering by someone who can sign for them. A departure: the CISO leaves with a programme half done and the board still asking about risk. If the work is steady rather than urgent, hire a fractional CISO instead; see the CISO jobs page for permanent roles.
How long? Tie the term to the outcome rather than a round number of months, with a review point and an agreed way to extend if an audit date moves. Across all disciplines the IIM’s 2026 survey puts the average assignment at 10.0 months; it is an all-discipline average, not a CISO rule.
09/ questions
Interim CISO FAQ
The questions people ask before bringing in an interim CISO.

Book 15 minutes · shortlist of 3–5
Bring the brief. We architect the team.
A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.
