CISO ROLE EXPLAINED

CISO job description: the role, the responsibilities, and how to fill it

If you are writing a CISO job description, you are usually deciding one of two things: whether to hire one, or whether you can afford not to. This page sets out what the role actually does, what good looks like, the signals that tell you it is time, and how a fractional or interim arrangement delivers the same outcome without a full-time salary on the books.

Book a conversation

What a CISO does

A Chief Information Security Officer owns the security of an organisation’s information, systems and data, and answers to the board for it. The role is accountable, not just operational: the CISO sets the security strategy, decides where to spend, decides which risks to accept and which to treat, and is the person the board turns to when something goes wrong. Everything else in a CISO job description is a consequence of that one fact. A good security manager runs controls. A CISO decides which controls matter, why, and what they are worth against the risk they reduce. If the job description reads like a list of tools to administer, it describes a security engineer, not a CISO.

Core responsibilities to put in the job description

A workable CISO job description covers a handful of distinct areas rather than a long undifferentiated list. The first is security strategy and governance: owning the risk register, setting policy, and reporting risk to the board in language a board can act on. The second is risk management: identifying what could hurt the business, deciding what to do about it, and tracking it over time. The third is the security programme itself, the controls, the architecture, the identity and access decisions, and the supplier and third-party risk that comes with them.

The fourth, and the one most job descriptions underweight, is incident readiness. A CISO is judged on the bad day, so the description should make them accountable for the incident response plan and for ransomware readiness, not just for prevention. The fifth is compliance and regulation, which now includes obligations such as NIS2 compliance and, increasingly, the security implications of AI governance and the shadow AI that staff bring in without anyone signing it off. The sixth is people: building security awareness, working with engineering rather than against it, and translating between the technical floor and the boardroom.

What good looks like

A strong CISO is fluent in two languages. They can sit with engineers and challenge an architecture decision, and they can sit in front of the board and explain, without jargon, what the organisation’s real exposure is and what reducing it would cost. The weak version of the role hides behind frameworks and produces a heat map nobody acts on. The strong version makes the trade-offs explicit so the board can own them.

  • Reports risk in business terms, not control counts, so the board can make decisions
  • Prioritises ruthlessly: fixes the few things that would actually cause material harm first
  • Treats security as an enabler of the commercial plan, not a brake on it
  • Has a tested plan for the breach, not just a policy that prevention will hold
  • Knows where the regulatory and contractual obligations bite and gets ahead of them

This is why a CISO sits closer to a Chief Information Officer than to a network administrator. The remits overlap, which is why some organisations look at a combined fractional CIO and CISO rather than two separate hires, and why a vCIO arrangement often sits alongside the security mandate.

Signs you need this role now

You rarely need a CISO because you ticked a box. You need one when the signals stack up. A new contract or a larger customer is asking security questions your current team cannot answer with confidence. A regulator, an insurer or an investor is asking who owns security and the honest answer is nobody. You have had a near miss, or a breach, and realised there was no plan. You are raising, selling or buying, and security is now part of the technology due diligence. Or your technology estate has grown past the point where security can sit as a side responsibility on the IT manager’s desk.

Any one of these is a prompt. Two or more, and the cost of not having clear security accountability is already higher than the cost of fixing it. The question then is not whether you need the role, but how to fill it without overcommitting.

The full-time hire problem

A permanent CISO is expensive and hard to find. A UK CISO salary runs roughly £95,000 to £600,000 or more depending on sector and scale, before recruitment fees, equity, benefits and the months it takes to fill the seat. For a mid-market business that needs senior security judgement but not a full-time executive every day of the week, that is a poor fit. You either overpay for capacity you do not use, or you under-hire and put a title on someone who cannot carry the accountability when it counts.

The cost is not only the salary. A breach carries its own price: the IBM Cost of a Data Breach Report 2025 puts the global average at USD 4.44 million, and UK regulators have shown they will act, with the ICO fining British Airways £20 million in 2020 and Interserve £4.4 million in 2022. The point of the role is to make that outcome less likely, and to have a plan if it happens anyway. You can run the numbers for your own situation with the CIO and CISO cost calculator and see how the options compare on pricing.

How a fractional or interim CISO delivers it

For most mid-market organisations, the work in a CISO job description does not require a full-time hire to do well. It requires senior judgement applied to the right things at the right cadence. That is what a fractional arrangement provides: an experienced CISO for the days you need, owning the strategy, the risk register and the board reporting, without the full-time cost. Delivered as CISO as a service or a virtual CISO, it gives you the accountability and the boardroom voice from day one rather than after a six-month search. If you want the plain-English version of how the model works, what is a vCISO sets it out.

An interim CISO is the other shape: full attention for a defined period, to lead through a transformation, a post-incident recovery, or a gap while you recruit. It is the same answer many businesses reach for the technology seat when they hit an interim CIO leadership gap. Either way, you get the role filled by someone who has carried the accountability before, supported where needed by broader cyber security consulting and, in regulated settings, cyber security for financial services. The board still gets a named owner; you simply stop paying for time you do not use.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

Having held the combined CIO and CISO seat, Daniel writes and fills CISO mandates from the inside: he knows which responsibilities in the job description actually carry the accountability and which are administration that belongs further down the team.

Frequently asked questions

What are the core responsibilities of a CISO?

A CISO owns security strategy and governance, manages risk and reports it to the board, runs the security programme and its controls, ensures incident and ransomware readiness, handles compliance and regulation, and builds security awareness across the organisation. The defining duty is accountability to the board for the organisation’s security risk.

What is the difference between a CISO and an IT manager?

An IT manager runs systems and controls. A CISO decides which security risks matter, what they are worth treating, and answers to the board for the result. It is an accountability role first and a technical role second. When a job description reads as a list of tools to administer, it describes a security engineer, not a CISO.

How much does a CISO cost in the UK?

A UK CISO salary runs roughly £95,000 to £600,000 or more depending on sector and scale, before recruitment fees, benefits and the time it takes to fill the role. A fractional or interim CISO gives you the same senior judgement and board accountability for the days you actually need, at a fraction of the full-time cost.

When do we actually need to hire a CISO?

When the signals stack up: customers or regulators asking security questions you cannot answer, an investor or insurer asking who owns security, a near miss or breach with no plan in place, a transaction that puts security into due diligence, or an estate that has outgrown security sitting as a side duty. Two or more of these, and the cost of having no clear owner is already higher than the cost of the role.

Can a fractional CISO carry the same accountability as a full-time one?

Yes. A fractional or interim CISO owns the strategy, the risk register and the board reporting as a named accountable owner, and is reachable when an incident hits. The difference is cadence and cost, not responsibility. You get an experienced operator from day one rather than after a long search, without paying for full-time time you do not use.

START HERE

Not sure if your board really owns security yet?

Before you write the job description, find out where the gaps are. The Board Cyber Governance check shows you, in a few minutes, whether security is genuinely owned at board level or quietly falling between desks, and what a CISO would need to put right first. Then book a conversation and we will talk through whether a fractional, interim or full-time route fits your situation.

Board Cyber Governance check Book a conversation