Hire a Virtual CISO · Virtual CISO Jobs UK

Virtual CISO Jobs · Hire a virtual CISO, or hire a CISO

Hire a virtual CISO — remote-first security leadership on a monthly package — for businesses that need an accountable owner for security policy, customer questionnaires and board reporting, but not someone in the office every week. Need more days and a seat in the room? Hire a fractional CISO instead.

  • £3,000–£15,000 a month · Cypro 2026
  • Remote-first on site when it matters
  • 3–5 candidates on every shortlist
  • Five-stage vetting on every brief

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

£3–15k
Virtual CISO cost, a month
Cypro 2026
£1.2–2.5k
Virtual CISO day rate band
Cypro 2026
3–5
Candidates on every shortlist
Our commitment
5
Vetting stages
Our commitment

15 minutes · video or phone

Book 15 minutes to hire a virtual CISO

Tell us the scope and the days a week. We come back with virtual CISO candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

01/ the model

What is a virtual CISO?

A virtual CISO (vCISO) is an outside security leader who runs your security governance remotely, on a set monthly allowance of time. Four features set it apart from a fractional CISO.

01 · delivery

Video calls, shared documents, an agreed rhythm.

The work happens mostly off site: a monthly security review, the risk register kept current, policies written and approved, questionnaires answered. On-site days are booked for the moments that need them — a board meeting, an audit, an incident.

Remoteby default

02/ cost

Virtual CISO cost: monthly packages and day rates.

Published figures only, each with its source. Monthly packages are priced as packages, not as a day rate multiplied by days, so compare what each fee buys — days or hours, response time, on-site visits — rather than the headline alone.

Published UK day-rate bands · £ a day
  • Virtual CISO£1,200–£2,500Cypro 2026
  • Fractional CISO£1,200–£2,000Optima Europe 2026
Virtual CISO bandFractional CISO band
PackagePublished figureSource
Smaller business, 4–6 days a month£3,000–£6,000 a monthCypro 2026
Cypro’s own vCISO packages£3,995–£5,995 a monthCypro 2026
Virtual CISO, full published range£3,000–£15,000 a monthCypro 2026
Virtual CISO at 5–10 days a month£40,000–£120,000 a yearCypro 2026
Fractional CISO retainer, 2–3 days a week£8,000–£18,000 a monthOptima Europe 2026

Cypro puts a vCISO at 5–10 days a month roughly 40–70% cheaper than a full-time CISO at £180,000–£270,000 fully loaded. The cheaper end of the market is a light monthly package; see fractional CISO cost for the day-rate view.

03/ the maths

Virtual CISO cost, by the day.

Virtual CISOs are often sold as a monthly package rather than by the day. If you are pricing in days, model them here against a full-time CISO — one day a week is roughly four to five days a month.

Days a week needed2 days

£1,300 a day is within the published band for a UK virtual CISO (£1,200–£2,500, Cypro 2026).

Year-one cost

£119,600

2 d/wk · 46 weeks · day fees, before tax

Virtual CISO£119,600
Full-time CISO, loaded£180,000

Fractional costs less in year one£60,400

Book a 15-minute call →

Our arithmetic, indicative. Full-time CISO = £180,000, the low end of Cypro’s £180,000–£270,000 fully loaded range, so any saving shown is the conservative one.

04/ alternatives

Virtual CISO vs MSSP, outsourced SOC or an in-house security lead.

Three things a growing business buys when it says “we need security”, and how a vCISO differs from each.

Virtual CISOMSSP
What you buyJudgement: what to protect, what to acceptManaged tools and monitoring, run for you
Answers toYour boardIts contract and service levels
Signs the security questionnaireYes — as your named security leadSupplies evidence for it
PricingMonthly packagePer user, device or service, monthly
Works bestSetting the policy the MSSP enforcesRunning the controls the vCISO chose

→ Complements, not substitutes: the vCISO decides, the MSSP operates. Many small businesses need both.

05/ fit

When a virtual CISO is enough — and when you need a fractional CISO.

The deciding question is how much senior security time the next twelve months actually need, and whether that time has to be in the room.

ENOUGH

Steady-state governance

Policies in place, a working IT team or MSSP, and a need for someone senior to keep the risk register honest, report to the board each quarter and sign off changes. A light monthly package fits.

ENOUGH

Questionnaires and baseline certification

Enterprise customers keep sending security questionnaires, or you need Cyber Essentials and a sensible policy set. Most of this is remote work to a regular rhythm.

STEP UP

A certification with a date

ISO 27001 or SOC 2 with an auditor booked needs someone driving it every week, not once a month. That is a fractional CISO at one to three days a week.

STEP UP

A regulator, an incident or a team to lead

Regulatory scrutiny, a breach aftermath, or a security team that needs day-to-day leadership all need presence and more days than a package allows.

If two or more of the “step up” cards describe you, hire a fractional CISO. The fractional hub sets out the day rates, the responsibilities and how we vet fractional CISOs. Many businesses start with a virtual CISO and move to fractional when a certification or a regulator makes the work weekly; if an incident or a departure needs someone full-time for a fixed term, that is an interim CISO. This is our reading of how the two models are used, not a published definition.

06/ uk frameworks

Virtual CISO in the UK: the frameworks a vCISO works to.

A virtual CISO in the UK works against a small set of government-backed frameworks, and a buyer should expect them to name which ones apply before the first monthly review. For most smaller businesses the starting point is Cyber Essentials, the NCSC-backed certification the government recommends as the minimum standard for organisations of every size — and one that a growing number of customers ask suppliers to hold before they will buy.

Above the technical controls sits governance. The government’s Cyber Governance Code of Practice, co-designed with the NCSC, sets out what boards and directors should do to govern cyber risk, and the NCSC’s Cyber Security Toolkit for Boards explains how to put it into practice. Much of a vCISO’s monthly allowance is spent here: turning the Code into a risk register, a reporting rhythm and decisions the board can minute.

Where personal data is involved, the UK GDPR’s security principle applies too — the ICO’s guide to data security expects appropriate technical and organisational measures that are tested and reviewed. Ask every vCISO you interview how they would map your business to these, and which they would tackle first. If the honest answer is weekly work towards ISO 27001 or a regulator, hire a fractional CISO instead; to compare what each service covers, see fractional and virtual CISO services.

07/ the buyer’s checklist

How to hire a virtual CISO.

Five questions to settle before you sign a monthly package — the ones that separate a real security owner from a subscription.

  1. 01

    Who, by name?

    Ask who will do the work and put their name in the contract. A pooled service with a rotating contact cannot build the relationship with your board and customers that the role depends on.

    NAMED LEAD
  2. 02

    What does the fee buy?

    Days or hours a month, what happens to unused time, which deliverables are included, and how many on-site visits.

    ALLOWANCE
  3. 03

    How fast in an incident?

    A vCISO carries other clients. Agree a response time for a live incident and who covers when they are unavailable.

    RESPONSE TIME
  4. 04

    Whose name goes on it?

    Confirm they will own the risk register and answer customer security reviews as your security lead — not just advise someone else who does.

    ACCOUNTABILITY
  5. 05

    How does it end?

    Notice terms, handover of every document and account, and whether they will help write the brief for a fractional or permanent successor.

    EXIT

08/ questions

Virtual CISO FAQ.

Common questions from businesses buying a virtual CISO and security leaders working as one.

A virtual CISO (vCISO) is an outside security leader who runs your security governance remotely on a monthly package: the risk register, policies, customer security questionnaires, board reporting and the incident plan. They are usually shared across several clients, which is what keeps the cost below a full-time hire.

Cypro publishes £3,000–£15,000 a month, or £1,200–£2,500 a day, with specialist work in financial services, healthcare and M&A above £2,000 a day (Cypro, 2026). At 5–10 days a month Cypro puts it at £40,000–£120,000 a year — roughly 40–70% cheaper than a full-time CISO at £180,000–£270,000 fully loaded.

Yes, at the light end of the market. Cypro puts a smaller business taking 4–6 days a month at £3,000–£6,000 a month, and its own packages at £3,995–£5,995. Check what the fee includes — days, response time, on-site visits — because the cheapest package is only good value if it covers the questionnaires and board reporting you actually need.

The terms overlap and are often used interchangeably. The usual difference is shape: a virtual CISO is remote-first and sold as a monthly package; a fractional CISO is embedded one to three days a week, priced by the day, and in the room for the board. If you need the second, see hire a fractional CISO.

Often both. An MSSP runs security tools and monitoring for you; a vCISO decides what those tools should protect, what risk the business accepts, and answers for it to the board and to customers. An MSSP supplies evidence for a security questionnaire; a vCISO answers it as your security lead.

A vCISO can own the programme, but a certification with an audit date usually needs more time than a light monthly package provides. If the auditor is booked, budget for weekly involvement — at that point a fractional CISO is usually the better fit.

Submit a brief with the scope, the monthly time you expect and whether you need on-site presence. We come back with a shortlist of 3–5, each with rate, availability and IR35 position set out. You interview.

Usually three, in this order: Cyber Essentials for the baseline technical controls; the government’s Cyber Governance Code of Practice for what the board should oversee; and, where personal data is involved, the ICO’s security guidance under the UK GDPR. ISO 27001 or SOC 2 come later, usually with a fractional CISO driving them.

It depends on how the engagement runs in practice — control, substitution and mutuality of obligation — not on the label. A medium or large client makes the status determination. See the IR35 guide.

Book 15 minutes · shortlist of 3–5

Bring the brief.
We find the security lead.

A shortlist of 3–5. Five-stage vetting. IR35 position on every brief.

For hiring companies

Book a call or submit a virtual CISO brief — scope, monthly time and on-site needs; we come back with a shortlist of 3–5 candidates.

For virtual CISOs

Browse live remote and part-time security leadership roles from our jobs feed, or get in touch about the searches we run.

Fractional Quest logo — how to hire a virtual CISO, virtual CISO jobs UK