Hire a Fractional CISO · Fractional CISO Jobs UK

Hire a fractional CISO
UK in 48 hours.

Hire a fractional CISO — cybersecurity leadership 1–3 days a week — for companies facing compliance requirements, security audits, and board-level risk reporting. Or browse live fractional CISO jobs UK-wide.

£1,275 median2 days typicalOutside IR35Compliance & risk
~/ciso-missionslive
scanning CISO mandates…
CISO
FinTech, FCA compliance
LONDON · 2D/WK · REGULATED
£1,650
FIT 97
CISO
Scale-up, ISO 27001 cert
MANCHESTER · 2D/WK · GROWTH
£1,200
FIT 94
vCISO
SaaS, SOC 2 Type II
BRISTOL · 1D/WK · COMPLIANCE
£1,100
FIT 90
CISO
Healthcare, NHS DSP Toolkit
EDINBURGH · 3D/WK · HEALTHCARE
£1,400
FIT 88
SEC
Post-breach recovery
LEEDS · 3D/WK · INCIDENT
£1,500
FIT 85
avg match time48h
£1.275k
Median CISO day rate
48h
Avg brief to shortlist
2d
Typical weekly cadence
156
CISO placements tracked
01 / definition

What is a fractional CISO?

Part-time Chief Information Security Officer jobs UK. Not a consultant, not an MSSP: the CISO, 1–3 days a week.

01

Part-time hire

01 · cadence

A chief information security officer, 1–3 days a week.

Senior, certified CISO capability across a defined slice of the week. You get the security leadership you need without a full-time salary or a five-day commitment.

2 daystypical cadence
02

Embedded

03

Outside IR35

04

Time-bound

02 / scope

CISO responsibilities

What fractional CISOs own versus what they delegate.

OWNS

  • Security strategy & roadmap
  • Risk register & appetite
  • Compliance programmes (ISO, SOC 2)
  • Incident response planning
  • Board reporting & metrics
  • Security team structure
  • Vendor selection & management
  • Policy & governance framework

× DELEGATES

  • 24/7 SOC monitoring
  • Hands-on penetration testing
  • Day-to-day ticket resolution
  • Firewall configuration
  • Vulnerability patching
  • Security awareness training delivery
  • Log analysis & SIEM tuning
  • Identity management operations
ISO 27001SOC 2GDPRRisk ManagementIncident ResponseCloud SecurityZero TrustBoard Reporting
03 / alternatives

Fractional CISO vs alternatives

How a fractional CISO compares to other security solutions.

Fractional CISO
Virtual CISO
Model
On-site + remote hybrid
Fully remote typically
Presence
Board meetings in person
Video calls only
Integration
Embedded in leadership
External advisor
Accountability
Named risk owner
Advisory role
Best for
Regulated industries
SMEs & startups
Fractional CISO = embedded leadership. Virtual CISO = remote advisory.
04 / economics

Cost to hire a fractional CISO, by sector

Day rates vary with regulatory requirements and company complexity.

SectorTypical scenarioDay rate rangeMedian
SME/StartupFirst security hire, basic compliance£700–£900£800
Scale-upISO 27001, SOC 2, growing team£900–£1,350£1,125
EnterpriseComplex estate, multi-framework£1,350–£1,650£1,500
RegulatedFinancial services, healthcare£1,650–£2,500£2,075
component · calculator
05 / economics

Part-time CISO cost.

Model the cost vs a full-time CISO, or what you could earn across your portfolio.

Day rate £1,275
Days per week needed2 days
Weeks engaged / year46 weeks
Your £1,275/day sits at the 58th percentile for UK fractional CISOs 900–£1,650 band).
Your cost
£131,376
Total year-1 cost · 2 days/week · incl. our 12% fee
Total year-1 cost
Fractional
£131,376
Full-time
£244,800
You save £113,424 (46%)
Indicative. Full-time loaded = base + 25% recruitment + 15% employer NI + 20% benefits/equity.
06 / decision

When to hire a fractional CISO

Four scenarios where it pays to hire a fractional CISO — and where fractional CISO jobs deliver highest impact for UK businesses.

scenario 1

Compliance deadline

ISO 27001, SOC 2, or sector-specific cert needed for growth or contract.

→ 6-month certification sprint
→ Need credible leadership
→ Board needs assurance
scenario 2

Post-incident recovery

Breach happened. Need credible leadership to rebuild trust and programme.

→ Regulator engagement
→ Programme rebuild
→ Board confidence
scenario 3

Regulatory pressure

New regulations (NIS2, DORA, FCA) require board-level security ownership.

→ Named accountability
→ Formal risk ownership
→ Audit readiness
scenario 4

M&A or funding

Due diligence needs credible security leadership and mature programme.

→ Security DD prep
→ Risk quantification
→ Investment protection
07 / structure

IR35 structured correctly

Outside IR35 from day one. No retrospective HMRC risk.

TEST 1

Right of Substitution

The CISO can send a qualified substitute. You contract the limited company, not the individual.

PASSES
TEST 2

Control

They control how, when and where they deliver. You define outcomes, not the working pattern.

PASSES
TEST 3

Mutuality

No obligation to offer or accept work beyond the agreed mandate. True contractor relationship.

PASSES
08 / process

How we vet CISOs

Every fractional CISO is verified across four dimensions before they reach you.

01

Security credibility

Verify real track record leading security at your stage — not just audit or pen-testing background.

SOURCING
02

Certification check

Validate certs (CISSP, CISM, sector-specific) and ongoing CPE compliance.

VERIFICATION
03

Reference validation

Speak to recent fractional clients, boards. Real outcomes, not just tenure.

DUE DILIGENCE
04

Shortlist delivery

3–5 candidates, each with rate percentile, fit score and IR35 structure.

48 HOURS
09 / questions

Fractional CISO FAQ

Common questions about hiring and working as a fractional CISO.

What is a fractional CISO?
A part-time chief information security officer who owns your security programme within a defined scope — risk management, compliance, governance and incident response. Not a consultant, not an MSSP: the CISO, 1–3 days a week.
How much does it cost to hire a fractional CISO?
UK median is around £1,275/day, typically 2 days a week — roughly £156K all-in for the year, versus ~£288K loaded for a full-time CISO. Use the calculator above for your numbers.
Can I hire a Chief Information Security Officer part-time?
Yes — that's exactly what a fractional CISO is: a Chief Information Security Officer working 1–3 days a week, embedded in your leadership team and owning the security programme, risk register and compliance roadmap.
Fractional CISO vs Virtual CISO — what's the difference?
A fractional CISO is embedded — attends board meetings in person, owns risk formally, leads the team. A virtual CISO is typically fully remote and more advisory. We place both — you can hire a virtual CISO through the same 48-hour process.
What certifications should they have?
Look for CISSP, CISM, or CCSP as baseline. For regulated sectors, specific certs like QSA (PCI DSS) or CISA (audit) matter. Experience trumps certs though.
How do I hire a fractional CISO?
Submit your brief and we'll shortlist 3–5 vetted fractional CISOs within 48 hours, each with our analysis layer (rate percentile, fit, IR35) attached.
Are fractional CISOs outside IR35?
Yes — outside IR35 by default. Our contract carries right of substitution, no mutuality of obligation, contractor-controlled working; CEST-tested.
10 / resources

Related resources

Deep dives on fractional CISO topics.

Book a meeting