CIO, CTO AND CISO COMPARED
CIO vs CTO vs CISO: which technology leader does your business actually need?
If you are weighing a CIO against a CTO against a CISO, you almost certainly have one budget line and three problems competing for it. This page tells you what each role really does, where they overlap, what each costs, and which one to hire first.
Book a conversationThe short answer: three different jobs that people keep confusing
A CIO runs the technology your business depends on to operate: systems, infrastructure, data, vendors, the IT team and the budget that holds it all together. A CTO builds the technology your business sells: the product, the engineering function and the technical roadmap that drives revenue. A CISO protects all of it: they own security strategy, risk, compliance and the response when something goes wrong. The titles get used loosely, but the remits are genuinely distinct, and hiring the wrong one is an expensive way to find that out.
What a CIO does
The CIO is your internal technology leader. They are accountable for the platforms staff use every day, the resilience of those platforms, the IT operating model, supplier relationships and the cost and risk of the estate. In a mid-market or private equity backed business, the CIO is usually the person who turns a sprawling, under-invested estate into something that can scale, integrate after an acquisition, and survive due diligence. If your pain is unreliable systems, runaway IT spend, a stalled ERP or integration programme, or a team without senior direction, that is CIO territory. This is the work covered by our IT strategy consulting and mid-market digital transformation services, and where an virtual CIO earns its keep.
What a CTO does
The CTO owns the technology you take to market. They lead engineering, set the product architecture, make build versus buy decisions and answer for whether the roadmap can be delivered. A CTO matters most when technology is the product, or a core part of it: a software business, a platform, a digital service. The distinction that trips people up is direction of travel. A CIO points inward at how the company runs. A CTO points outward at what the company sells. A traditional services or asset-heavy business often needs a strong CIO and no CTO at all, while a SaaS firm needs both and frequently conflates them.
What a CISO does
The CISO owns security and the risk that sits underneath it. They set the security strategy, run the controls, handle compliance with regimes such as NIS2, prepare the business for incidents and lead the response when an attack lands. Security is no longer an IT subtopic. The IBM Cost of a Data Breach Report 2025 put the global average breach at USD 4.44 million, and UK regulators have shown they will act: the ICO fined British Airways £20 million in 2020 and Interserve £4.4 million in 2022. If your board cannot answer how exposed the business is, or a customer or insurer is demanding evidence of controls, you need security leadership through a virtual CISO, CISO as a service, a tested incident response plan and genuine ransomware readiness.
The real differences in remit, focus and cost
Remit is the cleanest way to tell them apart. The CIO is measured on whether the business runs well on its technology. The CTO is measured on whether the product gets built and sold. The CISO is measured on whether risk is understood and contained. Their priorities pull in different directions on purpose: a CISO will slow down a change the CIO wants shipped, and that friction is the system working, not failing.
Cost is where the decision gets real. A full-time CISO in the UK can run anywhere from roughly £95,000 to £600,000 or more depending on sector and seniority, and CIO and CTO packages sit in a similar bracket at the top end. For most mid-market and PE-backed companies, carrying one of these as a permanent hire is hard to justify against the actual demand, which is why fractional and interim models exist. Our CIO and CISO cost calculator and pricing page let you compare the numbers honestly rather than guessing.
Where the roles overlap, and where it goes wrong
The overlap is real and it is usually where things break. Data governance sits between CIO and CISO. Product security sits between CTO and CISO. Cloud architecture touches all three. When responsibilities are blurred, security becomes nobody’s job, or it becomes the CIO’s afterthought, which is how organisations end up with a competent IT function and a wide-open risk position. The fix is not always three executives. It is clear ownership of each remit, held by someone with the authority to act. New pressures such as AI governance and shadow AI sharpen this further, because they cut across operations, product and security at once and expose any gap between the three.
Which do you need: a verdict for mid-market and PE-backed businesses
Here is the decision without the fence-sitting. If technology is how you operate, not what you sell, hire CIO capability first, and fold security into the brief from day one. If technology is your product, you need a CTO for the build and a CISO for the risk, and you should not let the CTO mark their own security homework. If you have just been acquired, are mid-deal, or facing technology due diligence, you need a CIO and a CISO viewpoint quickly, often through an interim CIO who can close the leadership gap in weeks rather than the months a permanent search takes.
For most mid-market and PE-backed companies the honest answer is that you need CIO and CISO judgement more than a CTO, and you need it part-time, not permanent. That is precisely what Starkhorn provides: a single experienced leader covering both remits through fractional CIO and CISO engagements, backed by hands-on cyber security consulting and, in regulated sectors, focused financial services security work. One person, two seats, a fraction of the cost of two hires.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Having held the CIO and CISO seats at Jardine Motors Group and led group technology inside a private equity backed group, Daniel has run both the operational and the security side of these roles in exactly the mid-market and PE-backed settings where this decision matters most.
Frequently asked questions
What is the difference between a CIO, a CTO and a CISO?
A CIO runs the technology the business uses to operate, a CTO builds the technology the business sells, and a CISO protects all of it by owning security strategy, risk and compliance. The CIO points inward, the CTO points outward, and the CISO sits across both.
Do I need all three roles?
Rarely. Most mid-market and PE-backed companies need strong CIO and CISO capability and have little use for a CTO unless technology is their product. The priority is clear ownership of each remit, not three separate executives on the payroll.
Can one person be both CIO and CISO?
Yes, and for many mid-market businesses it is the most sensible model. Starkhorn frequently provides CIO and CISO leadership under one experienced person through a fractional engagement, which closes both gaps at a fraction of the cost of two permanent hires.
Which role should a PE-backed business hire first?
If technology is how you operate rather than what you sell, hire CIO capability first and build security into the brief. After an acquisition or during due diligence, you usually need CIO and CISO judgement quickly, which an interim or fractional leader can provide far faster than a permanent search.
How much does a full-time CISO cost in the UK?
A permanent UK CISO can cost anywhere from roughly £95,000 to £600,000 or more depending on sector and seniority, with CIO and CTO packages similar at the top end. For most mid-market companies a fractional model delivers the same seniority without the full-time bill.
START HERE
Not sure whether your gap is operational or security?
If the question keeping you up is whether your board can actually answer how exposed the business is, start with the free Board Cyber Governance check. It shows you in minutes where the CISO side of this decision really sits, and from there we can talk through the right CIO, CTO or CISO mix for your business.
Board Cyber Governance check Book a conversation