CTO VS CISO

CTO vs CISO: who actually owns technology and security in your business

You are deciding which technology leader to hire, and the titles blur together. A CTO builds the product and the platform. A CISO defends the business. They are not interchangeable, and most mid-market companies need parts of both before they can afford either full time.

Book a conversation

CTO vs CISO in one sentence

A CTO owns how technology creates value: the product, the engineering, the architecture, the technical roadmap. A CISO owns how technology is protected: risk, security controls, compliance, incident response and the board conversation about what could go wrong. One is paid to move fast and ship. The other is paid to make sure moving fast does not sink the company. When the same person tries to do both, security usually loses, because the pressure to deliver always wins the diary. That tension is the single most useful thing to understand before you write a job description.

What a CTO actually does

A CTO sits closest to the product and the engineering organisation. They decide the technology stack, set the architecture, hire and lead developers, and translate commercial ambition into a buildable roadmap. In a software business the CTO is a near-cofounder figure. In a non-software business the role looks more like a head of engineering or platform owner. Worth noting: a lot of companies say CTO when they mean something closer to a virtual CIO or IT strategy lead, someone who runs internal systems, integrations and the technology operating model rather than a product. If your need is internal IT, transformation and supplier management rather than building software, a CIO-shaped role fits better than a CTO, and our interim CIO page sets out where that gap usually appears.

What a CISO actually does

A CISO owns information security as a discipline: identifying what could harm the business, deciding which risks to accept, transfer or fix, and proving to the board, customers and regulators that security is under control. That spans security architecture, identity, monitoring, supplier risk, staff behaviour, and the plan for the day something goes wrong. The CISO is the person who can stand in front of the board and answer, honestly, how exposed are we. Much of the day-to-day work maps to what we deliver through CISO as a service and cyber security consulting: governance, controls, regulatory readiness and the documented incident response plan that turns a crisis into a managed event.

The real differences in remit, focus and cost

The cleanest way to separate them is by the question each is hired to answer. The CTO answers, can we build and ship the right thing fast enough to win. The CISO answers, will building it that way get us breached, fined or sued. Their incentives pull in opposite directions on purpose, and a healthy business keeps that creative friction rather than collapsing it into one head.

  • Primary focus. CTO: product, engineering, technical velocity. CISO: risk, controls, assurance, resilience.
  • Reports into. CTO often the CEO. CISO increasingly the board or audit committee, so security is not buried under the people it polices.
  • Measured by. CTO by delivery and platform performance. CISO by reduced risk, clean audits and how well an incident is contained.
  • Cost. Both are senior salaries with package on top. UK CISO pay alone runs roughly £95,000 to £600,000 or more depending on sector and scope, before you add a CTO. For a mid-market business, two full-time hires is rarely the right first move.

That cost picture is exactly why fractional and interim models exist, and you can size the full-time alternative with our CIO and CISO cost calculator.

Which do you need: the verdict for mid-market and PE-backed firms

Here is the honest answer most articles avoid. If you build and sell software, hire or rent a CTO first and bring in security leadership alongside as you scale. If technology supports the business rather than being the product, which describes most mid-market and private-equity portfolio companies, you do not need a CTO at all. You need credible CIO-level direction over your systems and a CISO-level grip on risk. In practice that means a fractional CIO and CISO rather than two expensive permanent hires.

For PE-backed businesses the trigger is usually a deal. Before completion you want technology due diligence to know what you are buying. After completion you want someone accountable for both the technology plan and the security posture during the hold period, when the board cares about value creation and the audit committee cares about not becoming a headline. If you are regulated, financial services security obligations and frameworks such as NIS2 make a CISO-shaped capability non-negotiable, whatever you call it. The IBM Cost of a Data Breach Report 2025 puts the global average breach at USD 4.44 million, and the ICO fined British Airways £20 million in 2020 and Interserve £4.4 million in 2022, which is the scale of downside a CISO is paid to prevent.

How Starkhorn puts both under one person

For most clients the right answer is not CTO or CISO, it is the right slice of senior leadership without the headcount. Starkhorn frequently provides CIO and CISO capability through one accountable person, so the technology plan and the risk posture stay joined up instead of arguing across two job descriptions. That can run as a virtual CISO, a fractional engagement covering both seats, or an interim leader holding the line during a transition. Where modern risk shows up, such as AI governance, shadow AI or ransomware readiness, that single point of accountability is faster and cheaper than splitting it. You can see how this is scoped and priced on our pricing page, and the board-facing view on board IT strategy and mid-market transformation.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

Having held the CIO and CISO seats at Jardine Motors Group and led group technology at VetPartners, Daniel has carried both the build-and-run remit and the risk-and-defence remit personally, which is precisely the dual accountability this comparison is about.

Frequently asked questions

What is the difference between a CTO and a CISO?

A CTO owns how technology creates value, covering product, engineering, architecture and the technical roadmap. A CISO owns how technology is protected, covering risk, security controls, compliance and incident response. One is paid to ship fast, the other to make sure shipping fast does not breach or fine the business.

Can one person be both CTO and CISO?

It happens in smaller companies, but it is a known weak point because the pressure to deliver tends to crowd out security. A cleaner model for mid-market firms is fractional CIO and CISO leadership under one accountable person, which keeps technology and risk joined up without forcing them to compete inside a single overloaded role.

Does a mid-market business need a CTO or a CISO first?

If you build and sell software, a CTO usually comes first. If technology supports the business rather than being the product, which fits most mid-market and PE-backed firms, you need CIO-level direction over systems and CISO-level control over risk, not a product CTO. A fractional model covers both without two permanent salaries.

Who should the CISO report to?

Increasingly the board or audit committee rather than the CTO or CIO, so security is not buried under the same function it is meant to police. That separation matters most in regulated sectors and PE-backed businesses, where the board needs an honest, independent read on exposure.

How much do a CTO and CISO cost in the UK?

Both are senior salaries with package on top. UK CISO pay alone runs roughly £95,000 to £600,000 or more depending on sector and scope, before you add a CTO. For most mid-market businesses, fractional or interim leadership delivers the same accountability at a fraction of two full-time hires.

START HERE

Not sure whether your board has the security grip it needs?

If the CTO versus CISO question is really about whether anyone is accountable for risk at board level, find out in minutes. The Board Cyber Governance check shows you where the gaps sit, then we can talk through whether a fractional CIO and CISO is the right fix.

Board Cyber Governance check Book a conversation