CIO VS CDO
CIO vs CDO: which technology leader does your business actually need?
You are deciding which senior role to hire, and the titles overlap enough to make the choice expensive to get wrong. This page sets out what a CIO and a CDO each really do, where they differ on remit, focus and cost, and gives you a clear verdict for a mid-market or private equity backed business.
Book a conversationThe short answer: CIO runs the engine, CDO changes the vehicle
A CIO (Chief Information Officer) owns the systems your business runs on today: infrastructure, applications, networks, support, security posture and the budget that keeps all of it working. A CDO (Chief Digital Officer) owns change: new digital products, customer journeys, data as a commercial asset and the shift of revenue toward digital channels. Put plainly, the CIO keeps the lights on and makes them brighter, the CDO decides what the building should become. If you only remember one line, remember this: the CIO is accountable for operational technology that already exists, the CDO is accountable for the technology and propositions that do not exist yet.
What a CIO does, in practice
The CIO is the senior person accountable for technology operations and risk. That means the core platforms, the cloud estate, the vendor relationships, the cyber security defences and the resilience of the whole environment when something breaks. In a mid-market business the CIO is usually the person who also has to think like a CISO, because there is rarely budget for two separate hires. They set the multi year direction, run the technology budget, and answer to the board when a system fails or a supplier underdelivers. If your pain is that IT feels reactive, costs are creeping, projects slip and nobody owns the roadmap, you are describing a gap a CIO fills. We cover that remit in detail on the fractional CIO and CISO page and the wider IT strategy consulting service.
What a CDO does, in practice
The CDO exists to grow the business through technology rather than to administer it. They build digital products, redesign customer experiences, turn data into decisions and revenue, and challenge the operating model itself. A genuine CDO mandate is commercial: more digital sales, better margins, new propositions, faster time to market. The risk with the role is that it becomes a slide deck function with no operational teeth. A CDO with no grip on the underlying platforms produces strategy that the existing technology cannot deliver. That is why CDO ambitions so often stall: the engine was never ready. If your aim is a step change in how customers buy from you or how data drives the business, that is CDO territory, and it sits close to what we describe under digital transformation for the mid-market.
The real differences: remit, focus, cost and reporting line
On remit, the CIO owns run and protect, the CDO owns grow and change. On focus, the CIO measures uptime, cost, risk and delivery, the CDO measures revenue, adoption, customer outcomes and speed. On reporting, a CIO commonly reports to the CEO or CFO with the technology budget attached, a CDO more often reports to the CEO with a transformation or commercial mandate. On cost, both are expensive permanent hires, and the CDO premium can be higher because the role is scarcer and harder to define well. For a mid-market business, paying two full executive salaries to cover run and change at the same time is rarely justified by the workload, which is the core reason the fractional model exists. You can model the real cost of a permanent hire against fractional cover using our CIO and CISO cost calculator, and our approach to fees is set out on the pricing page.
Where the CISO fits, because two roles are often three
Security is the role that gets squeezed out of this conversation, and that is the dangerous mistake. A CDO chasing digital revenue can ship customer facing systems that quietly widen your attack surface, and a CIO under cost pressure can defer the security work that only matters the day you are breached. The numbers make the case better than any argument: the IBM Cost of a Data Breach Report 2025 puts the global average cost of a breach at USD 4.44 million, and UK regulators have shown they will act, with the ICO fining British Airways twenty million pounds in 2020 and Interserve four point four million pounds in 2022. Whether you call it a CISO as a service arrangement, a virtual CISO or simply security baked into the CIO remit, someone senior has to own defence. Our cyber security consulting and incident response planning work exists precisely so digital growth does not outrun your protection.
Which do you need: a verdict for mid-market and PE-backed firms
Here is the decision without the fence sitting. If your technology is unreliable, your costs are unclear, your roadmap is missing and your board is nervous about cyber risk, you need a CIO first, and you almost certainly need that CIO to carry security too. Change initiatives launched on shaky foundations fail, so fix run before you chase grow. If your platforms are sound, your operations are stable and your real problem is commercial growth through digital channels and data, then a CDO mandate earns its keep. Most mid-market and private equity backed businesses sit in the first camp, which is why the practical answer is usually a single experienced operator who can stabilise and run technology, own security, and lead the change agenda in sequence rather than all at once. That is the model we deliver, often combining what would otherwise be two or three permanent hires under one person through our virtual CIO service. For PE owned firms specifically, that same person can run technology due diligence before a deal and then carry the value creation plan afterwards, and can cover a sudden vacancy through interim leadership in a CIO gap. Where AI is now part of the growth story, that leader also has to own AI governance and the risk of shadow AI before it becomes a board level problem.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
That blend of running large technology estates and owning security at board level is exactly what the CIO versus CDO question demands, because the same person has had to stabilise operations, defend the business and lead change rather than treat them as separate jobs.
Frequently asked questions
What is the main difference between a CIO and a CDO?
A CIO is accountable for the technology your business already runs on, including infrastructure, applications, support, cost and security. A CDO is accountable for change and growth: new digital products, customer experiences and turning data into revenue. The CIO runs and protects, the CDO grows and transforms.
Does a mid-market business need both a CIO and a CDO?
Rarely. Two permanent executive salaries are seldom justified by the workload in a mid-market firm. Most need a CIO mandate first to stabilise and run technology and own security, with the change agenda led in sequence. A single experienced operator can carry both, which is the fractional model Starkhorn provides.
Who owns cyber security, the CIO or the CDO?
Security needs an explicit owner and it is dangerous to assume either role covers it by default. In most mid-market businesses security sits with the CIO or with a dedicated CISO function. A CDO pursuing digital growth can widen the attack surface, so defence has to be designed in, not bolted on later.
Is a CDO more expensive than a CIO?
The CDO premium can be higher because the role is scarcer and harder to define well, but both are costly permanent hires. The more useful question for a mid-market or PE-backed firm is whether you need full time cover at all, or whether fractional leadership delivers the same outcome at a fraction of the cost.
Which should a PE-backed business hire first?
Usually a CIO with security responsibility, because value creation depends on stable, well run and well defended technology before any digital growth agenda can succeed. The same operator can run technology due diligence before a deal and lead the value creation plan afterwards, often as an interim or fractional appointment.
START HERE
Not sure whether you need run, grow or both?
If the real question behind CIO versus CDO is whether your business is ready to grow through digital and AI, start by finding out where you actually stand. Our free AI Readiness check gives you an honest read in minutes, and from there we can talk through whether you need a CIO, a CDO mandate, security cover, or one person who can carry all three.
AI Readiness check Book a conversation