CISO as a service
CISO as a service: senior security leadership, without the full-time hire
Your board keeps asking how exposed you are to cyber risk, a customer or insurer wants a named security lead on the contract, or you already know there are gaps but cannot justify a CISO on a six-figure salary. CISO as a service answers all three. You get one accountable senior practitioner on a retainer who owns the risk, reports to your board in language it understands, and gets you compliance-ready, without a permanent hire.
Book a conversationWhat is CISO as a service?
CISO as a service is the provision of a senior Chief Information Security Officer on a part-time, retained or interim basis, instead of as a full-time hire. The same role goes by several names: virtual CISO, vCISO, outsourced CISO and fractional CISO all describe the same arrangement. You get executive security leadership, the strategy, the risk ownership, the board reporting and the compliance direction, sized to what your organisation actually needs and can fund.
It is not a managed security service, and it is not a SOC. Those watch your systems and respond to alerts. A CISO as a service sets the direction those services operate within: what to protect, to what standard, against which risks, and how to prove it to a board, an auditor or an insurer. The day-to-day execution stays with your internal team or your suppliers. The accountability and the strategy sit with the CISO.
It suits mid-market companies, private-equity-backed businesses and not-for-profit organisations that have outgrown ad hoc IT security but cannot yet justify a full-time executive. If you have between roughly 50 and 1,000 staff, hold data or systems that matter, and have nobody whose job is to own security at board level, this is the model built for you.
When do you actually need it?
Most organisations do not wake up wanting a CISO. They hit a moment that forces the question. The common triggers:
- The board has started asking. A peer has been breached, the audit committee wants assurance, or a non-executive director has asked who owns cyber risk and nobody has a clean answer.
- A customer or insurer is demanding it. Larger clients now require a named security contact and evidence of controls before they sign. Cyber insurers ask the same at renewal, and price the gap.
- A compliance deadline is real. You are pursuing ISO 27001 or Cyber Essentials, you fall inside the scope of NIS2 or DORA, or UK GDPR exposure has become a board-level concern.
- Something has already happened. A breach, a near miss or a failed audit has made it obvious that hope is not a control.
- Private equity is involved. An investor expects security to be governed and evidenced, before, during or after the deal.
If none of these is true, you may not need this yet, and a credible adviser will tell you so. The honest test is simple: if your organisation suffered a serious incident next week, is there one person accountable for how you prepared and how you respond? If the answer is no, that is the gap CISO as a service fills.
What a CISO as a service actually owns
The value is not activity, it is ownership. A good engagement takes specific responsibilities off your plate and gives you decisions and evidence in return:
- The risk picture. A current, prioritised view of your real security risks, in business terms, mapped to a recognised framework such as NIST CSF or ISO 27001, with a direction of travel rather than a one-off snapshot.
- Board reporting. A regular, plain-language report the board can act on: where you stand, which risks sit outside appetite, and the decisions being asked of them. No jargon, no firewall statistics.
- A security strategy and roadmap. A costed plan that closes the gaps that matter first, aligned to the business, not a shopping list of tools.
- Compliance leadership. Direction and evidence for Cyber Essentials, ISO 27001, SOC 2, NIS2, DORA and UK GDPR, so audits and questionnaires stop being fire drills.
- Incident readiness. A tested response plan and the rehearsal to go with it, so the first time you use it is not during a live incident.
- Third-party and supply-chain risk. A grip on the vendors and partners who can hurt you, and the contract language that holds them to a standard. It sits alongside broader cyber security consulting when you need it.
How the engagement works
CISO as a service is usually delivered in one of a few shapes, and the right one depends on your situation rather than a package:
- Retained. A set number of days each month for ongoing leadership, board reporting and a steadily improving security programme. The most common model.
- Project. A defined piece of work with an end: ISO 27001 readiness, a post-incident review, due diligence for a transaction.
- Interim. Full-time cover for a gap, such as a departed security leader, available quickly and accountable from day one. See interim CIO and CISO for that model in full.
The detail that matters most is who actually does the work. Much of the market is built on platforms and rotating benches: you buy a brand, and a different junior analyst services your account each quarter. Starkhorn is the opposite. You work with one named senior practitioner throughout. The person who reports to your board is the person who did the thinking, and they do not disappear when the contract is signed.
What it costs, against a full-time CISO
A full-time Chief Information Security Officer is a major fixed cost. In the UK, CISO salaries run from around £95,000 to well over £600,000 depending on sector and scale, according to recruiter DWH, before benefits, recruitment fees and the months it takes to hire. CISO as a service replaces that fixed cost with a variable one: you pay for the seniority and the days you need, and nothing else.
| Cost | Full-time UK CISO | CISO as a service |
|---|---|---|
| Base salary | £95,000 to £600,000+ (DWH) | Retainer for the days you need |
| Benefits, pension, NI | Significant on top | None |
| Recruitment | Agency fees, months to hire | None, available in weeks |
| Seniority on day one | After onboarding | Immediate |
For most mid-market organisations the maths is straightforward: a fraction of the cost of a full-time hire buys the same seniority where it counts. Day rates and retainer ranges are on the pricing page, and the fractional CIO and CISO model sets out how the days are used.
vCISO, virtual CISO, fractional CISO, outsourced CISO: the same thing?
For practical purposes, yes. They all mean senior security leadership without a full-time hire, and the market uses them interchangeably. The only distinction worth drawing is between a genuine senior practitioner and a productised service: a vCISO who has actually carried the accountability of the role is a different proposition from a dashboard with a job title. If you want the full definition, the virtual CISO page covers it, and CIO versus CISO explains where the role sits against the wider technology remit.
Why this is a board accountability, not an IT problem
Regulators treat cyber security as a board responsibility, and the cost of getting it wrong is now a board-level number. The global average cost of a data breach reached USD 4.44 million in 2025, according to IBM’s Cost of a Data Breach Report. In the UK, the Information Commissioner’s Office fined British Airways £20 million in 2020 after a breach exposed the data of more than 400,000 customers, and Interserve £4.4 million in 2022 after a phishing attack, criticising the company for failing to act on an earlier alert. In each case the controls were management’s job, but the accountability was the board’s. A CISO as a service is how directors discharge that duty, and the evidence that they did.
How to choose a CISO-as-a-service provider
The market is crowded and uneven. Five questions separate a real engagement from a logo:
- Who does the work? One named senior person, or whoever is free that week. Ask to meet them, not the sales team.
- Have they carried the accountability? Advising on security is not the same as having owned it. Ask what they were responsible for, not what they have read.
- Can they talk to a board? The role lives or dies on translating risk into decisions. A technical-only adviser leaves the hardest part undone.
- Do they fit your context? Mid-market, PE-backed and not-for-profit organisations have different pressures from enterprises. Generic playbooks miss them.
- Are they independent? An adviser who also sells you the tools has a conflict. Independence is part of the value.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles. He has held the combined technology and security remit at scale: Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
What that means for you: the person who owns your security risk and reports to your board has carried that accountability before, understands the commercial pressures of a mid-market or PE-backed business, and sees security and technology as one remit rather than two silos. You get one senior practitioner, not a bench. If that is the kind of security leadership you need, the next step is a short conversation, or a free diagnostic that shows you exactly where you stand.
Frequently asked questions
What does CISO as a service cost in the UK?
Far less than a full-time hire. A UK CISO salary runs from around £95,000 to over £600,000 before benefits and recruitment, according to recruiter DWH. CISO as a service is charged as a retainer or day rate for the seniority and time you actually need, so most mid-market organisations pay a fraction of the full-time cost. Current ranges are on the pricing page.
Is a vCISO the same as a CISO as a service?
Yes. vCISO, virtual CISO, outsourced CISO and fractional CISO all describe the same model: senior security leadership on a part-time or retained basis rather than a full-time hire.
Who is more senior, the CIO or the CISO?
Neither is automatically senior. The CIO owns technology and how it serves the business; the CISO owns security and risk. In many organisations the CISO reports to the CIO, but the two roles are increasingly held as one combined remit, which is how Starkhorn delivers them.
What is cyber security as a service?
It is an umbrella term for buying security capability on demand rather than building it in house. CISO as a service is the leadership layer of that: the strategy, risk ownership and board reporting that sit above the tools and the monitoring.
When should you use CISO as a service rather than hiring?
When you need senior security leadership but cannot justify or fill a full-time role, when you need it quickly, or when the work is defined and finite such as ISO 27001 readiness or interim cover. If you have the budget and a steady, full-time workload, a permanent hire may be the better answer.
Board-level technology and security leadership
See where your board’s cyber exposure actually sits
The Board Cyber Governance check shows you, in a few minutes, where your board is exposed and what to fix first. If you would rather talk it through, book a conversation and we will tell you what usually breaks next for an organisation like yours.
Run the Board Cyber Governance check Book a conversation