Hire an Interim CISO · Interim CISO Jobs UK

Interim CISO Jobs · hire an interim CISO
for
the breach, or hire a CISO

Hire an interim CISO — a full-time interim Chief Information Security Officer on a fixed-term assignment — for incident recovery, a certification deadline, regulatory pressure or cover through a vacancy. Or browse live interim CISO jobs UK-wide below.

  • £1,000–£1,500+ a day (Barclay Simpson)
  • Full-time, fixed-term
  • 6–12 months typical
  • Shortlist of 3–5

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

£1.0–1.5k+
Contract CISO day rate (Barclay Simpson, 2026)
£137.7k
Advertised UK CISO median (ITJobsWatch)
3–5
Candidates on every shortlist
5
Vetting stages

15 minutes · video or phone

Book 15 minutes to hire an interim CISO

Tell us the situation and the start date. We come back with interim CISO candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the assignment and the start date
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

Interim CISO jobs · last 3 months

Live Interim CISO jobs

0 Interim CISO · 1 fractional CISO

No live Interim CISO roles in the last three months. Showing live fractional CISO roles instead.

01/ definition

What is an interim CISO?

An interim CISO is the Chief Information Security Officer, full-time, for a fixed term. Not an MSSP and not a part-time virtual CISO: the named owner of security risk until the job is done or the permanent hire arrives.

01 · cadence

The CISO seat, five days a week.

An interim CISO owns security strategy, risk, incident response and board reporting in full, not as an adviser.

5 daysa week, typically

02/ scope

What an interim Chief Information Security Officer owns

The interim CISO carries security accountability for the term; the security team and providers keep the operations.

  • Security strategy and roadmap
  • Risk register and appetite
  • Certification programmes (ISO 27001, SOC 2)
  • Incident response and recovery
  • Regulatory engagement
  • Board security reporting
  • Security team structure
  • Handover to the permanent CISO
  • 24/7 SOC monitoring
  • Hands-on penetration testing
  • Firewall and tooling configuration
  • Vulnerability patching
  • Awareness training delivery
  • SIEM tuning
ISO 27001SOC 2DORANIS2Incident responseCloud securityZero TrustBoard reporting

03/ alternatives

Interim CISO vs virtual, MSSP and permanent

The same seat, four ways of filling it.

Interim CISOVirtual / fractional CISO
CadenceFull-time, 5 days a weekA few days a month or a week
TermFixedOngoing
Published cost£1,000–£1,500+ a day, contract (Barclay Simpson)£1,200–£2,500 a day; £3,000–£15,000 a month (Cypro)
PresenceEmbedded, on site as neededUsually remote
Best forA breach, a deadline or a gapSteady security leadership for a smaller firm

→ Interim covers the whole seat for a period; virtual and fractional CISOs cover part of it indefinitely.

04/ rates

Interim CISO day rates, UK 2026

Published figures only, each with its source. Cypro puts rates above £2,000 a day in specialist domains — financial services, healthcare, M&A due diligence.

Published UK day-rate bands · £ a day
  • Contract / interim CISO£1,000–£1,500+Barclay Simpson 2026
  • Fractional CISO£1,200–£2,000Optima Europe 2026
  • Virtual CISO£1,200–£2,500Cypro 2026
Interim bandComparator band
EngagementPublished figureSource
Contract / interim CISO£1,000–£1,500+ a dayBarclay Simpson 2026 guide
Fractional CISO£1,200–£2,000 a dayOptima Europe, 2026
Virtual CISO£1,200–£2,500 a day; £3,000–£15,000 a monthCypro, 2026
Permanent CISO£140,000–£220,000 base; £180,000–£270,000 loadedCypro, 2026
Permanent CISO, advertisedMedian £137,650ITJobsWatch, mid-2026 ↗

Six months at five days a week (about 130 working days) is £130,000–£195,000 at the Barclay Simpson band — our arithmetic.

05/ calculator

What an interim CISO costs

Model a fixed-term interim CISO against a permanent Chief Information Security Officer over the same period.

Days a week5 days

£1,250 a day is within the published Interim CISO band (£1,000–£1,500, Barclay Simpson 2026).

Interim cost for the term

£162,500

130 working days · 5 d/wk · 6 mo · before tax

Interim CISO£162,500
Permanent CISO, same period£120,444

Interim costs more over 6 months£42,056

Book a 15-minute call →

Our arithmetic, indicative. Permanent = the £137,650 advertised CISO median (ITJobsWatch) pro rata for the same months, plus 15% employer NI, plus a 30% search fee on the annual base (UK retained search runs 25–35%, Headhunters.co.uk). Excludes pension, bonus and equity.

InterimPermanent hireLines cross at month 3: shorter than that, interim costs less.
£0k£81k£163k£244k£325k0123456789101112months
Month 6: interim £162,500 · permanent £120,444

06/ tax

Is an interim CISO tax-deductible?

General position under UK rules, with the HMRC source for each point. Not tax advice — check your own case with your accountant.

01 · DEDUCTIBLE

The fees are a business expense

An interim CISO’s fees, like a salary, are deductible against profits when incurred wholly and exclusively for the trade (HMRC BIM37000). At the 25% main rate, each £1,000 of fees costs a profitable company £750 after relief.

02 · EMPLOYER NI

Employer NI follows IR35 status

A permanent CISO carries employer National Insurance at 15% (gov.uk). An interim engaged through their own company carries none when the engagement is outside IR35; inside IR35, the fee-payer deducts tax and NI and pays employer NI. Status depends on how the engagement runs in practice.

03 · WHO DECIDES

IR35 status, by company size

Medium and large clients determine the interim’s status themselves; for a small private-sector client, the interim’s own company decides (HMRC off-payroll guidance).

07/ decision

When to hire an interim CISO

Four situations where companies hire an interim CISO — and where most interim CISO jobs come from.

Which sounds like you?

The incident is contained; now the board, the regulator and customers need a credible owner.

  • → Regulator engagement
  • → Programme rebuild
  • → Board confidence

ISO 27001 or SOC 2 is needed to win or keep a contract, by a date.

  • → Gap analysis
  • → Controls
  • → Audit

DORA, NIS2 or FCA expectations require named, board-level security ownership.

  • → Accountability
  • → Risk ownership
  • → Readiness

Security due diligence before a sale, an investment or an acquisition.

  • → DD pack
  • → Risk quantified
  • → Remediation plan

08/ guide

Hiring an interim CISO: what to get right

Start with the outcome. Most interim CISO assignments exist because of a date — an audit, a regulator, a completion, a board after an incident. Put the outcome and the date in the brief.

Choose between interim and virtual or fractional. If security needs a full-time owner for a few months, hire an interim CISO. If it needs senior direction a few days a month, a virtual CISO or fractional CISO costs less — Cypro puts vCISO retainers at £3,000–£15,000 a month.

Budget from the published bands. Barclay Simpson’s 2026 guide puts contract CISO day rates at £1,000–£1,500+; six months at five days a week is roughly £130,000–£195,000 — our arithmetic. A full-time CISO is £140,000–£220,000 base and £180,000–£270,000 fully loaded (Cypro).

Check certifications and track record against your situation — CISSP or CISM are expected; incident recovery, certification and regulatory work are different skills. Take references from recent assignments; we do the same before anyone reaches a shortlist.

If you are looking for interim CISO jobs rather than hiring, the live board below lists current interim CISO roles; fractional CISO jobs cover the part-time market.

08.1/ after a breach

Hire an interim CISO after a breach: the first decisions

Many boards hire an interim CISO in the middle of an incident, so the first days are about decisions, not strategy. If personal data is involved, the deadline is a legal one: under the UK GDPR, notifiable personal data breaches must be reported to the ICO within a strict statutory time limit of becoming aware of them, individuals must be told without undue delay where the risk to them is high, and every breach must be recorded whether or not it is reported (ICO guide to personal data breaches).

The NCSC’s incident management guidance sets out what a basic response plan needs: key contacts, escalation criteria, a process covering the whole incident life cycle and guidance on legal and regulatory requirements. It also stresses careful records, because regulators or courts may review the response later (NCSC incident management). An interim CISO should take ownership of that plan, or write it if it does not exist.

In interview, ask candidates to walk through an incident they led: who they escalated to, what they reported and what changed afterwards. If the wider technology function also needs a leader, see hiring an interim CIO; for ongoing part-time cover afterwards, a virtual CISO.

09/ contract

Interim CISO jobs: how the assignment is contracted

Interim CISO jobs are usually contracted through the interim’s own limited company, on a fixed-term agreement that sets out the scope, the term, the day rate, the days a week and notice on each side. The scope is the outcome from the brief: the recovery, the certification, the regulatory readiness or the cover the assignment exists to deliver.

IR35 status turns on how the assignment runs in practice, not on what the contract calls it. HMRC looks at substitution, control and whether either side must offer or accept further work. Medium and large clients make the status determination; for a small private-sector client, the interim’s own company does (HMRC off-payroll guidance). See the IR35 guide.

TEST 1

Substitution

Whether the interim’s company could send a suitably qualified substitute, and whether that right is genuine in practice.

What HMRC looks at

TEST 2

Control

Who decides how the work is done, as distinct from what the assignment must deliver.

What HMRC looks at

TEST 3

Mutuality

Whether either side is obliged to offer or accept work beyond the agreed assignment.

What HMRC looks at

10/ process

How to hire an interim CISO with us

What we undertake on every brief.

  1. 01

    Brief

    A 30-minute call on the assignment, the start date and what the interim CISO must have delivered by the end of the term.

    DAY 0
  2. 02

    Search

    We search and screen against that brief: track record at your stage and in your situation, and references we take ourselves.

    SCREENING
  3. 03

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5
  4. 04

    Start

    You interview and choose. The interim you choose contracts with you.

    YOU CHOOSE

11/ questions

Interim CISO FAQ

Hiring an interim Chief Information Security Officer, or looking for interim CISO jobs.

An interim CISO is a full-time Chief Information Security Officer on a fixed-term assignment who leads security through an incident, a certification deadline, regulatory pressure or a vacancy and then hands over.

Send us a brief: the situation, what must be true by the end of the term and your start date. We aim to send a shortlist of three to five interim CISOs, with day rate, availability and IR35 position set out. You interview and choose.

Barclay Simpson’s 2026 guide puts contract CISO day rates at £1,000–£1,500+. Six months at five days a week is roughly £130,000–£195,000 (our arithmetic).

An interim CISO works full-time for a fixed term. A virtual CISO works a few days a month, usually remotely — Cypro puts that at £3,000–£15,000 a month.

After a breach, before a certification or regulatory deadline, during security due diligence, or while you recruit a permanent CISO.

You send a brief; we send a shortlist of three to five interim CISOs, each with day rate, availability and IR35 position set out. You interview and choose, and the start date depends on the chosen interim’s availability.

Sometimes. Agree any conversion terms at the start so the option exists without surprises.

Establish what happened, contain it and decide what must be reported. Under the UK GDPR, notifiable personal data breaches must be reported to the ICO within a strict time limit, and every breach recorded (ICO). The NCSC’s incident management guidance covers escalation, records and the post-incident review.

It depends on how the assignment runs in practice, not on what the contract calls it. HMRC looks at substitution, control and mutuality of obligation. Medium and large clients make the status determination; for a small private-sector client, the interim’s own company does (HMRC).

Book 15 minutes · shortlist of 3–5

Hiring an interim CISO? Start with the brief.

Book 15 minutes.

Fractional Quest logo — how to hire an interim CISO, interim CISO jobs UK