SECURITY LEADERSHIP, EXPLAINED
What is a fractional CISO?
You have outgrown ad hoc security but cannot justify a full time Chief Information Security Officer. A fractional CISO closes that gap: this page explains exactly what the role is, what they do, when you need one, and how it differs from the titles it gets confused with.
Book a conversationWhat a fractional CISO is
A fractional CISO is an experienced Chief Information Security Officer who leads your security on a part time, ongoing basis instead of as a full time employee. You get the same accountability, board reporting and strategic ownership of cyber risk that a permanent CISO provides, but for a few days a month rather than five days a week. The word fractional refers to the time commitment, not the seniority. The person is a genuine security leader who has carried the title before, scaled down to the hours your organisation actually needs.
This model exists because security leadership is lumpy. A mid sized firm may need a CISO to set strategy, satisfy an audit, win a major contract or steady the ship after an incident, without needing that person at full salary indefinitely. Starkhorn delivers this through its fractional CIO and CISO service, sized to the risk in front of you.
What a fractional CISO actually does
The role is about ownership, not task work. A fractional CISO sets the security strategy, decides what to prioritise, reports cyber risk to the board in language directors understand, and holds the organisation to the plan. They translate threats into business decisions: which risks to accept, which to mitigate, which to insure against, and what each choice costs.
In practice the work spans the risk picture and the roadmap to improve it, the security policies and the controls that enforce them, supplier and third party risk, and readiness for the day something goes wrong. That last point matters most. A credible incident response plan and tested ransomware readiness are the difference between a contained event and a business stopping crisis. A fractional CISO also owns emerging exposures such as shadow AI and the governance of AI tools across the business, covered in depth on the AI governance page.
When a business needs one
The clearest trigger is a customer or regulator asking who owns security. Enterprise buyers, insurers and frameworks increasingly demand a named, accountable security leader, and a junior IT manager wearing the hat part time rarely satisfies that test. If you are bidding for larger contracts, the absence of a CISO can quietly lose you the work.
The second trigger is regulation. Firms touching financial services or those caught by NIS2 compliance need demonstrable security governance, not good intentions. The third is growth: when you cross from a handful of staff to a few hundred, informal security stops scaling and someone has to own it properly. A fractional CISO answers all three without committing you to a permanent hire before the workload justifies it. If you also lack senior technology leadership, the same logic applies to the interim CIO leadership gap.
How it differs from the roles it gets confused with
Fractional CISO, virtual CISO and CISO as a service describe broadly the same thing from different angles. The fractional framing emphasises a senior individual giving you a slice of their time. The virtual CISO framing emphasises remote, flexible delivery, and you can read a fuller breakdown on the what is a vCISO explainer. The CISO as a service framing emphasises a packaged, subscription style engagement. The practical question is not the label but whether you are getting a real security leader with accountability, or a thin advisory layer.
The role is distinct from a CISO and a CIO. A CISO owns security and risk. A CIO owns technology strategy and delivery, the fractional version of which Starkhorn offers as a vCIO. The two overlap but answer different questions: a CIO asks whether technology is serving the business, a CISO asks whether it is protecting it. It is also not the same as cyber security consulting, which delivers a defined project and then leaves. A fractional CISO stays, owns the outcome, and is answerable for it over time.
What it costs, and why the maths works
A permanent UK CISO salary runs roughly £95,000 to £600,000 or more depending on sector and scope, before recruitment, equity, benefits and the cost of a vacant seat while you search. A fractional arrangement gives you that calibre of leadership for the days you use, which for most mid market firms is a fraction of a full time package. You can model the comparison directly with the CIO and CISO cost calculator, and see how Starkhorn structures engagements on the pricing page.
The downside risk sharpens the case. The IBM Cost of a Data Breach Report 2025 puts the global average breach at USD 4.44 million, and UK regulators have shown they will act: the ICO fined British Airways £20 million in 2020 and Interserve £4.4 million in 2022. Set against figures like those, accountable security leadership is cheap insurance.
How Starkhorn provides a fractional CISO
Starkhorn embeds a senior security leader into your organisation at the cadence the risk demands, from a steady monthly rhythm to intensive support around an audit, a deal or an incident. The engagement starts by establishing where you actually stand, then setting a prioritised roadmap and reporting it to the board so directors can govern cyber risk with confidence, the remit covered on the board cyber governance page. Where security overlaps with wider technology decisions, the same leadership can extend into IT strategy consulting, board IT strategy and technology due diligence for transactions and change programmes.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
Carrying both the CIO and CISO titles at Jardine Motors Group means a fractional CISO engagement with Starkhorn comes from someone who has owned security as an accountable leader inside a large, regulated business, not advised on it from the outside.
Frequently asked questions
What is the difference between a fractional CISO and a virtual CISO?
There is little practical difference. Fractional emphasises a senior leader giving you part of their time, while virtual emphasises flexible, often remote delivery. Both describe an experienced CISO leading your security without being a full time employee.
How many days a month does a fractional CISO work?
It varies with the risk and stage of the business, from a few days a month for steady governance to more intensive support around an audit, a major deal or an incident. Starkhorn sizes the commitment to what the work actually requires rather than a fixed package.
When does a business need a fractional CISO rather than a consultant?
Use a consultant for a defined project with a clear end. Use a fractional CISO when you need someone to own security and cyber risk over time, report it to the board, and be accountable for the outcome, without the cost of a permanent hire.
Can a fractional CISO satisfy customers, insurers and regulators?
Yes. A fractional CISO is a genuine, named security leader who can answer enterprise buyer questionnaires, support insurance applications and demonstrate the governance that frameworks such as NIS2 expect.
Is a fractional CISO the same as a CIO?
No. A CISO owns security and risk, while a CIO owns technology strategy and delivery. The roles overlap but answer different questions. Starkhorn can provide either, or both, depending on where your gaps are.
START HERE
See whether your board can actually govern cyber risk
If you are weighing up a fractional CISO, the first question is whether your board has the information to govern cyber risk today. The free Board Cyber Governance check tells you in minutes where the gaps are, and a short conversation turns the answer into a plan.
Board Cyber Governance check Book a conversation