Chief information officers · the role

What does a CIO do?

The short answer · updated

A chief information officer (CIO) runs an organisation’s information technology: the IT strategy, systems, infrastructure, data and budget, and the teams and suppliers that deliver them. The CIO keeps technology secure and reliable, decides where to invest, and advises the board on technology risk, including cyber security. The CIO is an executive, usually reporting to the chief executive.

What a CIO does

The Office for National Statistics classes the CIO with IT directors. Its Standard Occupational Classification (unit group 1137) says they plan, organise, direct and co-ordinate the work and resources needed to provide and operate IT infrastructure and services: networks, devices, servers and the software that runs on them. The tasks it lists are below.

The government’s Digital and Data Capability Framework describes the equivalent public-sector role, the chief digital and information officer, in wider terms: shaping the organisation’s strategy through digital, data and technology, keeping it safe from cyber attack, securing investment, and acting as a trusted adviser to the board on all matters of digital, data and technology.

In short, the CIO owns the technology the business runs on. That covers the systems staff use every day, the data the business holds, the suppliers it depends on, and the plan for what changes next.

  • developing the IT strategy with the rest of senior management;
  • directing how that strategy, the infrastructure, procurement, procedures and standards are put in place;
  • setting the IT business plan and operating budget to deliver agreed service levels;
  • deciding IT staffing levels, overseeing recruitment and directing training;
  • prioritising and scheduling major IT projects;
  • making sure new technologies are researched and evaluated against what the organisation needs.

The CIO and the board: cyber and data risk

Boards now answer for cyber risk. The government’s Cyber Governance Code of Practice, written for medium and large organisations, asks the board to agree senior ownership of cyber security risks, set a risk appetite, and gain assurance that critical technology, suppliers and incident plans are in hand. The CIO is usually the executive who gives the board that assurance. The NCSC’s Cyber Security Toolkit for Boards sets out how.

For a smaller business the starting point is Cyber Essentials, the government-backed scheme built around five technical controls: firewalls, secure configuration, security update management, user access control and malware protection. Getting and keeping it is typically on the CIO’s or IT director’s list.

Data protection sits alongside. Where an organisation must appoint a data protection officer, the ICO says the DPO must be independent, report to the highest level of management, and not hold other duties that create a conflict of interest. A CIO who decides how personal data is processed should think hard before also taking the DPO role.

Who a CIO reports to

A CIO reports to one of the executive directors. Commonly that is the chief executive; in some organisations it is the chief operating officer or the finance director. The line says something about how the business sees technology: as part of the strategy, part of operations, or a cost to manage.

Reporting to the chief executive gives the CIO a direct voice in strategy. Reporting to finance can keep the focus on cost control, and can make it harder to argue for investment. Neither is wrong; the choice should match what the organisation needs from its technology.

A CIO who sits on the board is a company director, with the seven general duties under the Companies Act 2006. Companies House guidance notes the duties also apply to someone who acts as a director without being formally appointed.

CIO vs CTO vs IT director

The CIO looks inward. The CIO runs the technology the organisation uses: internal systems, infrastructure, data, security and IT suppliers. The CTO looks outward. The government framework calls the chief technology officer the organisation’s technology strategist, setting the technical direction and the architecture. In a company that sells software, the CTO usually runs the engineering team that builds the product.

Many organisations have only one of the two. A software company with a small back office may have a CTO and no CIO; a retailer, charity or professional firm may have a CIO and no CTO. Where both exist, the CIO serves the business and the CTO serves the product.

An IT director does much of the CIO’s job, often with a narrower remit and without a board seat; the ONS puts both titles in the same group. A chief information security officer (CISO), where there is one, leads security and often reports to the CIO. For each, see fractional IT director, fractional CISO and fractional CTO roles.

Fractional, interim and part-time CIOs vs a permanent CIO

A permanent CIO is an employee who owns technology for the long run. That suits an organisation whose technology estate needs full-time leadership every week.

A fractional or part-time CIO works a set number of days a week or month, often for more than one organisation. That suits a business that needs senior IT judgement, a strategy and supplier oversight, but not five days of it. You can hire a fractional CIO for that. An interim CIO works full-time for a fixed period: to cover a gap, run a migration or steady things after an incident. You can hire an interim CIO for that.

A fractional or interim CIO often works through their own company. The off-payroll working rules (IR35) may then apply. Status turns on how the engagement runs in practice, and a medium or large client makes the determination. Our IR35 guide sets out the tests.

What a CIO costs and earns

Pay moves with the size of the organisation, its sector and regulation, the size of the technology estate, and whether the CIO sits on the board. A fractional or interim CIO is paid a day rate; a permanent CIO a salary, often with a bonus.

We do not publish a figure on this page. Our CIO salary page sets out permanent and fractional pay, each figure with its source, and our fractional CIO cost page sets out fractional CIO day rates and what a part-time engagement costs, each with its source.

How to hire a CIO

Start with the problem, not the title. Write down what technology must do for the business over the next two to three years, what is broken now, and which decisions the CIO will own. That tells you whether you need a permanent CIO, a fractional one, an interim, or a different role such as a CTO or IT director.

Test for evidence, not vocabulary. Ask for a strategy they wrote, a budget they ran, a major migration or incident they led, and how they reported risk to a board. Professional registration such as BCS Chartered IT Professional (CITP) is a useful signal of competence and conduct, though not a requirement.

Our CIO headhunter page sets out how we hire a CIO. We recruit fractional, interim, part-time, temporary and permanent executives. Every brief gets a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after the five-stage vetting we describe.

Questions people ask

What is the difference between a CIO and a CTO?

The CIO runs the technology the organisation uses: internal systems, infrastructure, data and IT suppliers. The CTO sets the technical direction of what the organisation builds, and in a software company usually runs engineering. Many organisations have only one of the two.

Is a CIO a board-level role?

It can be. Some CIOs sit on the board as executive directors; many report to a board member without a seat. The Cyber Governance Code of Practice expects the board to agree senior ownership of cyber risk, which puts the CIO in front of the board either way.

Is a CIO the same as an IT director?

The jobs overlap. The ONS occupational classification lists chief information officer and IT director in the same unit group. In practice a CIO title usually signals a wider, more strategic remit and a closer link to the board.

Does a small business need a CIO?

Not full-time, as a rule. A small business needs someone accountable for its systems, data and cyber security, which may be an IT manager, an outsourced provider, or a fractional CIO for a few days a month to set the strategy and oversee suppliers.

What qualifications does a CIO need?

There is no required qualification. The ONS notes that candidates usually hold a degree or equivalent with substantial relevant experience. Registration such as BCS CITP shows professional standing. What matters most is evidence of running technology for a business of similar size and risk.

How much does it cost to hire a CIO?

It depends on the engagement. A permanent CIO is paid a salary; a fractional or interim CIO a day rate. Our CIO salary and fractional CIO cost pages set out sourced figures. We set out pay or day rate for every candidate on a shortlist.

How do I hire a CIO?

Define the problem the CIO will solve, choose between permanent, fractional and interim, and test candidates on evidence of strategies, budgets and incidents they have owned. Our CIO headhunter page sets out the process; we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out.

Fractional Quest logo — how to hire a CIO, what does a CIO do