CISO EXPLAINED
What Is a CISO? Security Leadership Explained for Business Leaders
The Chief Information Security Officer owns security, risk and the board’s confidence that its controls actually work. This page explains what the role covers, why it has moved onto the board’s agenda, when you need one, and what it costs.
Book a conversationWhat a CISO actually owns
A Chief Information Security Officer owns the security of the organisation and the risk decisions that go with it. That means the security strategy, the policies and compliance regime, the response when something goes wrong, and the reporting that gives the board assurance the controls are real. A CISO is narrower and deeper than a CIO: where a CIO cares about security as one priority among many, a CISO makes it the only priority.
- Owns cyber risk: what could harm the business, how likely it is, and what to fix first
- Sets security policy and the compliance posture the business is held to
- Builds and tests the incident response so a breach is a process, not a panic
- Reports risk to the board in business terms, not technical ones
Why the role has moved onto the board’s agenda
Cyber risk is now a board responsibility, not something a board can delegate to IT and forget. The UK Cyber Governance Code of Practice sets out the actions directors are expected to own, and regulation reaching UK firms through EU supply chains makes senior management personally accountable. The cost of getting it wrong is not theoretical: the IBM Cost of a Data Breach Report 2025 puts the global average breach at USD 4.44 million, and UK regulators have shown they will act, fining British Airways £20 million in 2020 and Interserve £4.4 million in 2022.
CISO, CIO and virtual CISO: where the lines fall
A CIO owns the whole technology agenda; a CISO owns security within it. In smaller organisations one leader often carries both, which is where the combined CIO and CISO mandate earns its place. When a business needs the security remit but not a full-time hire, a virtual CISO, sometimes called a vCISO, provides the same accountability for an agreed number of days. The CIO versus CISO guide draws the line between the two cleanly.
When a business needs a CISO, and when a virtual one is enough
You need dedicated security leadership when breach risk, regulatory pressure or a customer demanding evidence of your controls has made security a board-level concern. For most mid-market and private-equity-backed businesses a virtual or fractional CISO provides everything a full-time hire would, at a fraction of the cost. A dedicated full-time CISO is usually justified only where regulation requires it or the threat profile genuinely demands someone in the seat every day.
What a CISO costs, and the virtual route
A permanent CISO in the UK commands a wide range, from roughly £95,000 to £600,000 or more depending on sector, scope and regulatory exposure, before recruitment and the time to fill the seat. A fractional or virtual CISO gives you that calibre of judgement on a monthly retainer, scaled to the risk rather than to a full-time salary. Our pricing page sets out how engagements are structured.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Having held the CISO remit alongside the CIO role at group level, Daniel has built the security programmes, incident processes and board reporting a CISO is accountable for, and can translate cyber risk into decisions a board will actually make.
Frequently asked questions
What does a CISO do?
A CISO owns security and cyber risk for the organisation: the security strategy, policy and compliance, incident response, and the reporting that gives the board assurance the controls work. The job is to decide what to protect, how, and in what order, and to answer for it at board level.
What is the difference between a CISO and a CIO?
A CIO owns the whole technology agenda, including systems, suppliers and spend. A CISO owns security and risk within it. A CIO treats security as one priority among many; a CISO makes it the only priority. In smaller organisations one leader often carries both remits.
Does a mid-market business need a full-time CISO?
Usually not. For most mid-market and private-equity-backed businesses a virtual or fractional CISO provides everything a full-time hire would at a fraction of the cost. A dedicated full-time CISO is justified mainly where regulation requires it or the threat profile demands someone in the seat every day.
How much does a CISO cost in the UK?
A permanent CISO ranges from roughly £95,000 to £600,000 or more depending on sector and scope, before recruitment. A virtual or fractional CISO is charged as a monthly retainer for an agreed number of days, scaled to the risk rather than a full-time salary.
What is a virtual or fractional CISO?
A virtual CISO, or vCISO, is an experienced security leader who owns your security programme, risk and board reporting for a set number of days rather than as a permanent employee. It gives a business CISO-level accountability without a full-time hire.
NEXT STEP
Find out whether your board can defend its security position
If you are not sure your directors could answer for the controls behind your security, the free Board Cyber Governance check shows where the accountability gaps sit before a customer or regulator finds them. When you want to talk it through, a conversation is the next step.
Board Cyber Governance check Book a conversation