SECURITY LEADERSHIP EXPLAINED

What does a CISO do? The role, the remit and when you need one

You are asking what a CISO does because someone has raised a security risk, a customer has sent a long questionnaire, or the board has started asking who owns cyber. This page tells you exactly what the role covers, where it stops, and how to get it without a full-time hire.

Book a conversation

What a CISO does, in one sentence

A CISO, or Chief Information Security Officer, owns an organisation’s information security strategy and is accountable to the board for how the business identifies, reduces and responds to cyber risk. That single sentence hides a wide brief. The CISO decides which risks matter, sets the controls and policies that address them, makes sure those controls actually work, and stands in front of the board, regulators, customers and insurers to answer for the security posture. The job is part strategist, part translator and part crisis manager. It is far more about judgement and accountability than about firewalls.

What the role actually covers day to day

The work falls into a handful of areas that recur across every organisation, whatever the sector. A CISO sets the security strategy and the risk appetite, deciding what the business will protect, to what standard, and what it is willing to accept. They build and maintain the controls that follow from that, covering access, data protection, supplier risk, monitoring and patching. They own governance and policy, so that staff know what is expected and the board can see the security position in plain language. They prepare the organisation for the bad day through an incident response plan and tested ransomware readiness, because the question is when, not if. And they manage compliance, mapping the business against frameworks and regulation such as NIS2 so that audits, certifications and customer due diligence stop being fire drills.

Increasingly the remit has stretched to cover new categories of risk. Artificial intelligence is the clearest example: a CISO now has to set policy on how the organisation uses AI safely, which is why AI governance and the problem of shadow AI sit firmly on the modern security agenda.

What a CISO is not

A CISO is not the person who configures the antivirus or resets passwords. That is the security operations and IT team, and a good CISO leads them rather than doing their work. Nor is a CISO simply a senior IT manager with a new title. The distinction matters: IT is judged on systems running well, while security is judged on risk being understood and held within the limits the board has agreed. The two pull in different directions often enough that the security view needs its own voice. A CISO is also not a compliance officer, although compliance is part of the job. Passing an audit proves you met a standard on a given day. A CISO is accountable for whether the business is genuinely defensible the other 364, which is a higher bar.

How it differs from the roles it gets confused with

The titles around this role multiply quickly, and the differences are real. A virtual CISO, often written vCISO, delivers the same accountability and strategy as a permanent CISO but on a part-time, retained basis, which suits organisations that need senior security ownership without a six-figure salaried hire. CISO as a service packages that into a defined ongoing engagement with clear deliverables. If you want the full background on the part-time model, what is a vCISO sets it out in detail. A vCIO covers technology strategy and IT leadership rather than security specifically, and many mid-market firms need both perspectives from one trusted pair of hands, which is the model behind a combined fractional CIO and CISO. Where a leadership seat falls vacant, an interim leader bridges the gap on a full-time but temporary footing.

When a business actually needs one

Most organisations reach for a CISO at a recognisable moment. A large customer or a prospective acquirer sends a security questionnaire the business cannot honestly answer. An insurer raises the cyber premium or refuses cover without evidence of controls. A near miss, or a real incident, shows the board that nobody owned the response. New regulation lands and someone has to interpret it. Investors start asking about cyber risk as part of technology due diligence. In regulated sectors the pressure arrives earlier and harder, which is why cyber security for financial services firms tends to demand named security leadership from the outset. The common thread is that risk has become a board-level question, and the board needs one person accountable for the answer.

Few mid-market firms can justify a permanent CISO, where the UK salary runs roughly £95,000 to £600,000 or more before the cost of a supporting team. That is the gap the fractional and virtual models exist to close, and you can model the trade-off directly with the CIO and CISO cost calculator.

Why the role is worth the investment

The case for security leadership is not abstract. The IBM Cost of a Data Breach Report 2025 puts the global average cost of a breach at USD 4.44 million. UK enforcement makes the point at home: the ICO fined British Airways £20 million in 2020 and Interserve £4.4 million in 2022, both following security failures. A CISO exists to make outcomes like those far less likely and far less damaging when something does go wrong. Beyond avoiding loss, mature security has become a commercial asset, opening doors with enterprise customers and regulated partners who will not contract without it. Sound board cyber governance and broader cyber security consulting turn security from a cost line into something that supports growth, and it sits naturally alongside wider IT strategy consulting and digital transformation in the mid-market.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

Having held the CIO and CISO seat at Jardine Motors Group and led group technology at a private-equity-backed group, Daniel does the CISO role described on this page as the accountable owner, not the adviser on the sidelines.

Frequently asked questions

What does CISO stand for?

CISO stands for Chief Information Security Officer. It is the senior role accountable to the board for an organisation’s information security strategy, its cyber risk, and its response when something goes wrong.

What is the difference between a CISO and a CIO?

A CIO owns technology strategy and the IT estate, judged on systems delivering for the business. A CISO owns security and risk, judged on whether that risk is understood and held within agreed limits. The roles overlap but provide deliberately different viewpoints, which is why some firms combine them in one fractional appointment.

Does a small business need a CISO?

Most small and mid-market businesses do not need a full-time CISO, but they do need the accountability the role provides once cyber risk becomes a board or customer question. A virtual or fractional CISO delivers that ownership at a fraction of the cost of a permanent hire.

Is a CISO a technical role?

It is informed by technology but it is primarily a leadership and risk role. A CISO sets strategy, makes risk decisions, writes policy and answers to the board, regulators and customers. The hands-on configuration work belongs to the security and IT team the CISO leads.

How much does a CISO cost in the UK?

A permanent UK CISO salary runs roughly £95,000 to £600,000 or more, before the cost of a team. A fractional or virtual CISO gives you the same accountability on a part-time retained basis at a far lower commitment, which is why most mid-market firms choose that route.

START HERE

Not sure whether your board owns cyber risk yet?

If reading this has left you unsure who in your organisation actually answers for security, the free Board Cyber Governance check shows you where the gaps sit in minutes. When you want to talk through what a CISO would do for you specifically, book a conversation.

Board Cyber Governance check Book a conversation