FRACTIONAL CISO PRICING

Fractional CISO cost and pricing, explained honestly

You want a senior security leader without a six-figure permanent salary, and you need to know what that actually costs before you take it to the board. This page sets out what drives the price, compares the engagement models so you can budget, and shows you why fractional or interim cover is usually cheaper than a full-time hire for the same work.

Book a conversation

What does a fractional CISO cost?

A fractional CISO costs a fraction of a permanent Chief Information Security Officer because you buy a slice of senior time, not a full salary plus employer National Insurance, pension, bonus and benefits. There is no single figure, because the price tracks three things: the scope of work, the seniority of the person doing it, and the engagement model you choose. The honest answer is that the price is built from those drivers rather than read off a list. Our published rates live on the Starkhorn pricing page, and you can model a realistic monthly number for your own situation with the Fractional CIO Cost Calculator.

The three engagement models you can budget against

There are three sensible ways to buy security leadership, and they cost very differently for the same calendar.

The first is a day rate. You pay for days actually worked, which suits a defined piece such as a board paper, a due diligence exercise or a remediation sprint. It is the most flexible model and the easiest to start, but the per-day figure is the highest of the three because you are not committing to volume. A short engagement on technology due diligence or an incident response plan often runs on day rate.

The second is a monthly retainer, which is how most fractional and virtual CISO arrangements work. You agree a fixed number of days or a fixed scope each month, the rate per day drops because the commitment is steady, and you get continuity: the same person in your governance meetings month after month. This is the model behind CISO as a service and the one most organisations find easiest to forecast.

The third is a full-time permanent salary. A UK CISO salary runs roughly £95,000 to £600,000 or more depending on sector, regulatory exposure and company size, before you add the employer costs on top. For a mid-market organisation that needs senior judgement rather than forty hours a week of it, paying a full salary for a part-time workload is the most expensive way to solve the problem.

What actually drives the price up or down

Scope is the biggest lever. A board that wants quarterly assurance and a risk register maintained costs less than one rebuilding a security programme from scratch, chasing NIS2 compliance, and standing up ransomware readiness at the same time. Regulatory load matters too: a firm inside financial services cyber security rules carries more obligation, and more cost, than a lightly regulated one. Maturity is the third driver. An organisation with no policies, no asset inventory and unmanaged shadow AI needs more days up front than one that simply wants a steady hand on existing controls. Use the cost calculator to see how these levers move the monthly figure rather than guessing.

Why fractional or interim is usually cheaper than hiring

The work a CISO does is not a constant flow. Most months it is governance, oversight and a handful of decisions; some months it is intense. A permanent hire bills you full price every month regardless, plus recruitment fees that often equal months of salary, plus the cost of the role sitting empty while you search. A fractional CIO and CISO arrangement matches spend to the actual shape of the work. You also skip the leaving cost: when the programme matures and you need less, you scale down rather than manage a redundancy. For a gap rather than a permanent need, an interim leader covering a leadership gap covers the seat for a fixed term without the long-term liability.

When a fractional CISO is the wrong answer on cost

Honesty cuts both ways. If you have a large in-house security team that needs full-time daily management, a permanent CISO is the better buy and a fractional one will frustrate everyone. If your need is broader than security, you may want a blended virtual CIO mandate covering IT strategy and digital transformation alongside security, which changes the scope and the price. And if you only need a one-off project, project-based cyber security consulting on a day rate is cheaper than any retainer. The point of asking the question properly is to avoid paying for a model that does not fit.

What the cost buys you in practice

A fractional CISO buys board-grade judgement at the table. The cost of getting security wrong dwarfs the fee: the IBM Cost of a Data Breach Report 2025 puts the global average breach at USD 4.44 million, and UK regulators have shown they will act, with the ICO fining British Airways £20 million in 2020 and Interserve £4.4 million in 2022. For that fee you get someone who runs board cyber governance, owns the security elements of board IT strategy, sets a defensible AI governance position, and translates risk into language the board can act on. That is the value the price is set against.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

That experience setting and defending technology and security budgets at group level is exactly what tells you whether a day rate, a retainer or a permanent hire is the right spend for your scope.

Frequently asked questions

How much does a fractional CISO cost in the UK?

There is no single number, because the price is built from scope, seniority and engagement model. A defined project on a day rate prices differently from a steady monthly retainer. The most reliable way to get a figure for your situation is to model it with the Fractional CIO Cost Calculator and check the published Starkhorn pricing page.

Is a fractional CISO cheaper than hiring a permanent one?

For most mid-market organisations, yes. A UK CISO salary runs roughly £95,000 to £600,000 or more before employer National Insurance, pension and benefits, and before recruitment fees and the cost of an empty seat. A fractional arrangement matches spend to the actual shape of the work, which is rarely full-time.

What is the difference between a day rate and a monthly retainer?

A day rate pays for days actually worked and suits defined pieces of work, with the highest per-day figure because there is no volume commitment. A monthly retainer fixes a scope or number of days each month at a lower effective rate, and gives you continuity with the same person in your governance meetings.

What makes one engagement cost more than another?

Scope, regulatory load and current maturity. A board wanting quarterly assurance costs less than one rebuilding a security programme, chasing NIS2 compliance and standing up ransomware readiness at once. A heavily regulated firm carries more obligation, and a low-maturity organisation needs more days up front.

When is a fractional CISO the wrong choice on cost?

If you have a large security team needing full-time daily management, a permanent CISO is the better buy. If you only need a one-off project, day-rate cyber security consulting is cheaper than any retainer. The aim is to match the model to the need rather than overpay for time you will not use.

SEE YOUR NUMBER

Work out what a fractional CISO would cost you

Stop guessing at the figure for your board paper. The Fractional CIO Cost Calculator turns your scope, seniority and engagement model into a realistic monthly number in a couple of minutes. If you would rather talk it through against your actual situation, book a conversation.

Fractional CIO Cost Calculator Book a conversation