Chief information security officers · the role
What does a CISO do?
The short answer · updated
A chief information security officer (CISO) leads an organisation’s information and cyber security. The CISO sets the security strategy, manages cyber risk across the business and its suppliers, prepares for attacks and leads the response when one happens, builds a security-aware culture, and advises the board on the risks it is taking and how to reduce them.
What a CISO does
The government’s Digital and Data Capability Framework says a CISO creates an environment and culture that keeps the organisation’s information and technology secure, so that it can meet its objectives and deliver its services safely. It lists the job as below.
In practice the CISO owns the security programme: the policies, the controls, the security team and the specialist suppliers, and the plan for what to improve next. The CISO decides where security money goes, and explains to the rest of the business why.
- creating a strategy for information and cyber security that supports the organisation’s strategy, and leading its delivery;
- assessing how mature the organisation’s security is now, and how to reach the level it needs;
- understanding risk across the organisation and advising the board and other leaders on how to reduce it;
- making sure the organisation is prepared for cyber attacks and can detect, respond to and recover from one;
- assessing partners and the supply chain for threats and weaknesses;
- encouraging a culture of security awareness and good practice.
The CISO and the board
Boards now answer for cyber risk. The government’s Cyber Governance Code of Practice, written for medium and large organisations, asks the board to agree senior ownership of cyber security risks, set a risk appetite, gain assurance that a cyber strategy is in place and being delivered, and check that suppliers and incident plans are in hand. The CISO is usually the executive who gives the board that assurance. The NCSC’s Cyber Security Toolkit for Boards sets out how the board should go about it.
The NCSC is blunt about whose job the conversation is. Its guidance Board-level cyber discussions: communicating clearly tells CISOs to engage boards on their terms and in their language, to explain cyber risks as business risks, and to put the most important answer first, with as little jargon as possible.
A good CISO leaves the board able to answer three plain questions: what could hurt us most, what are we doing about it, and how would we know if it failed.
Incidents, breaches and regulation
When an attack lands, the CISO usually leads the response. If personal data is affected, the law sets the pace. The ICO’s guide to personal data breaches says organisations must report certain breaches to the ICO within a fixed time of becoming aware of them, tell affected people without undue delay where the risk to them is high, and keep a record of every breach, reported or not. The CISO makes sure the process to do that exists before it is needed.
Some organisations carry extra duties. The NIS Regulations set legal security requirements for operators of essential services, such as energy, transport, water, health and digital infrastructure, and for some digital service providers. For most smaller businesses the starting point is Cyber Essentials, the government-backed scheme built on five technical controls: firewalls, secure configuration, security update management, user access control and malware protection.
For the wider picture, the government’s annual Cyber Security Breaches Survey tracks how businesses and charities approach cyber security and the breaches and attacks they report. The latest release is the place to check before a board paper.
Who a CISO reports to, and CISO vs CIO
A CISO commonly reports to the chief information officer or the chief technology officer. In some organisations the CISO reports to the chief executive, the chief operating officer or the chief risk officer instead, which keeps security separate from the people who run the systems it checks.
The CIO runs the technology the organisation uses. The CISO makes sure it is secure. The two work closely, and the tension between them is useful: the CIO wants systems delivered, the CISO wants the risk understood first. Where there is no CISO, security falls to the CIO or IT director. See what does a CIO do? for that role.
Whatever the line, the CISO needs direct access to the board or its audit and risk committee. A CISO who can only reach the board through someone else’s report struggles to give it honest assurance.
Virtual, fractional and interim CISOs
A permanent CISO is an employee who owns security for the long run. That suits a large or heavily regulated organisation, or one whose product is itself a security risk to its customers.
A fractional or virtual CISO works a set number of days a week or month, often for more than one organisation. That suits a business that needs senior security judgement, a strategy and board reporting, but not five days of it. You can hire a fractional CISO or hire a virtual CISO. An interim CISO works full-time for a fixed period, to cover a gap, prepare for an audit or lead the recovery after an incident; you can hire an interim CISO.
A fractional, virtual or interim CISO often works through their own company, so the off-payroll working rules (IR35) may apply. Status turns on how the engagement runs in practice, and a medium or large client makes the determination. Our IR35 guide sets out the tests.
What a CISO costs and earns
Pay moves with the size of the organisation, its sector and regulation, the size of the security team, and how exposed the business is. A permanent CISO is paid a salary, often with a bonus; a fractional, virtual or interim CISO a day rate.
We do not publish a figure on this page. Our CISO salary page sets out permanent and fractional pay, and our fractional CISO cost page sets out what a part-time engagement costs. Each figure there carries its source.
How to hire a CISO
Start with the risk, not the title. Write down what the organisation must protect, which regulators and customers are asking questions, and what is broken now. That tells you whether you need a permanent CISO, a fractional or virtual one, or an interim to fix something urgent.
Test for evidence. Ask for a security strategy they wrote, a board paper they presented, and an incident they led from first alert to lessons learned. Certifications such as CISSP, CISM, CISA or ISO 27001 lead implementer or auditor show knowledge; the UK Cyber Security Council, the profession’s Royal Charter body, awards professional titles up to Chartered Cyber Security Professional. None is a substitute for a track record.
Our fractional CISO page sets out how we hire a CISO. We recruit fractional, interim, part-time, temporary and permanent executives. Every brief gets a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out, after the five-stage vetting we describe.
Questions people ask
What is the difference between a CISO and a CIO?
The CIO runs the technology the organisation uses: systems, infrastructure, data and IT suppliers. The CISO leads its information and cyber security, sets security policy and controls, and tells the board how much risk it is carrying. Many CISOs report to the CIO; some report elsewhere to keep security independent.
Is a CISO a board-level role?
The CISO rarely sits on the board but reports to it, often through the audit or risk committee. The Cyber Governance Code of Practice expects the board to agree senior ownership of cyber risk, which puts the CISO in front of the board either way.
What is a virtual CISO?
A virtual CISO (vCISO) is a senior security leader who works part-time and often remotely, for one or several organisations. The job is the same as a permanent CISO’s, scaled to the days available: strategy, policy, risk, board reporting and incident readiness.
Does a small business need a CISO?
Not full-time, as a rule. It needs someone accountable for security: an IT manager, a managed provider, or a fractional or virtual CISO for a few days a month. Cyber Essentials is the usual first step.
What qualifications does a CISO need?
None is required by law. Common certifications are CISSP, CISM, CISA and ISO 27001 lead implementer or auditor. The UK Cyber Security Council awards professional titles from Associate to Chartered. Evidence of leading security in a similar organisation matters most.
How much does it cost to hire a CISO?
It depends on the engagement. A permanent CISO is paid a salary; a fractional, virtual or interim CISO a day rate. Our CISO salary and fractional CISO cost pages set out sourced figures. We set out pay or day rate for every candidate on a shortlist.
How do I hire a CISO?
Define the risk the CISO will own, choose between permanent, fractional, virtual and interim, and test candidates on strategies, board papers and incidents they have led. Our fractional CISO page sets out the process; we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out.
