INTERIM SECURITY LEADERSHIP
What is an interim CISO?
If your security leader has just left, or you are facing a deal, a breach or a regulatory deadline with no senior voice in the room, you need cover now, not after a three month search. This page explains what an interim CISO is, what they do, when you need one, and how they differ from the roles they are often confused with.
Book a conversationWhat an interim CISO is
An interim CISO is an experienced Chief Information Security Officer brought in on a temporary, full attention basis to lead an organisation’s security function for a defined period, usually while a permanent leader is recruited or while a specific situation is brought under control. They carry the same accountability as a permanent CISO: they own the security strategy, the risk picture, the controls, the team and the relationship with the board. The difference is duration and intent. An interim is there to stabilise, decide and hand over, not to occupy the chair indefinitely.
The role exists because security accountability cannot pause. When a CISO resigns, the regulatory obligations, the live threats and the audit deadlines do not wait for the recruitment process. An interim steps into that gap with full authority from day one. For a wider view of how fractional and interim security leadership fits together, see our fractional CIO and CISO overview.
What an interim CISO actually does
In the first weeks an interim CISO reads the real position rather than the reported one. They assess the controls that exist, the controls that are claimed, the open risks, the in flight projects, the team and the commitments already made to the board, auditors and customers. They find the things that were quietly parked when the previous leader left.
From there the work is concrete. An interim owns the security roadmap and keeps regulated and contractual obligations on track. They run or rebuild the incident response plan so the organisation can act under pressure, and they raise ransomware readiness where the exposure is highest. They represent security to the board in language a board can act on, which is the discipline behind board cyber governance. They steady the team, protect the people worth keeping, and leave a documented handover so the permanent hire inherits clarity rather than a mess.
When a business needs one
The most common trigger is a sudden departure. A CISO leaves, is signed off, or is dismissed, and the board realises that security accountability now sits with nobody. An interim closes that gap quickly and credibly.
Other triggers are situational. A company in or after a serious incident needs a steady hand who has run breaches before. A business facing a regulatory deadline, such as NIS2 compliance, needs someone who can build the evidence rather than promise it. A firm under buyer or investor scrutiny needs security represented properly through technology due diligence. And organisations grappling with new risk classes, including AI governance and shadow AI, often need senior judgement before they commit to a permanent shape. Regulated sectors feel this most sharply, which is why we set out a dedicated view on cyber security in financial services.
How an interim CISO differs from the roles it is confused with
An interim CISO is full attention and time bound. That is the distinction that matters. A CISO as a service arrangement is ongoing and shared across the week, designed for organisations that need senior security leadership permanently but not at full time cost. A virtual CISO, sometimes written vCISO, is the same idea of part time senior leadership delivered remotely; we explain the term in detail at what is a vCISO.
The interim is the one you reach for when the need is acute and temporary. The fractional or virtual model is the one you reach for when the need is steady and long term. Many organisations start with an interim to stabilise, then move to a fractional arrangement once the immediate crisis has passed. An interim CISO is also distinct from a security consultant who advises and leaves: the interim holds the accountability and makes the decisions, which is a different thing from the advisory work covered under cyber security consulting.
What it costs, and why interim is efficient
A permanent UK CISO commands a salary that runs roughly from £95,000 to £600,000 or more, before recruitment fees, equity, employer costs and the months of vacancy while you search. An interim removes the vacancy risk entirely and is engaged only for as long as the need lasts, so you pay for senior judgement during the period that judgement is critical and stop when it is not.
The cost of getting this wrong is the part boards underestimate. The IBM Cost of a Data Breach Report 2025 puts the global average breach at USD 4.44 million, and UK regulators have shown they will act: the ICO fined British Airways £20 million in 2020 and Interserve £4.4 million in 2022. A leadership gap during a live threat or a deadline is precisely when those costs land. To compare the economics for your own situation, use our CIO and CISO cost calculator, and see how we structure engagements on the pricing page.
How Starkhorn provides an interim CISO
Starkhorn places a single accountable security leader who works the way a permanent CISO would, owns the risk picture, and reports to your board directly. We start by reading the real position, stabilise what is urgent, and build toward a clean handover so the engagement has a defined end rather than an open ended drift. The same model applies on the technology side, where an interim CIO closing a leadership gap follows the same discipline, and it connects naturally to wider IT strategy consulting and board IT strategy work where security and technology decisions overlap.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
That mix of interim leadership at a private equity backed group and a substantive CIO and CISO post at a national motor retailer is exactly the experience an interim CISO engagement calls for: someone who has held the accountability, reported to a board and handed over cleanly under real conditions.
Frequently asked questions
What is an interim CISO?
An interim CISO is an experienced Chief Information Security Officer engaged on a temporary, full attention basis to lead an organisation’s security function while a permanent leader is recruited or while a specific situation is brought under control. They hold the same accountability as a permanent CISO but for a defined period.
How is an interim CISO different from a virtual or fractional CISO?
An interim CISO is time bound and gives full attention to one organisation, usually to cover a gap or a crisis. A virtual or fractional CISO is an ongoing, part time arrangement for organisations that need senior security leadership permanently but not at full time cost. Many businesses start interim to stabilise, then move to fractional.
When does a business need an interim CISO?
Most often after a sudden departure that leaves security accountability with nobody. Other triggers include responding to a serious incident, meeting a regulatory deadline such as NIS2, going through due diligence for a deal, or getting new risk classes like AI under control before committing to a permanent hire.
How quickly can an interim CISO start?
Far faster than a permanent hire. An interim is engaged to start within days rather than the months a recruitment process takes, which is the point of the model: security obligations, live threats and audit deadlines do not pause while you search.
How long does an interim CISO engagement last?
For as long as the need lasts and no longer. Engagements are scoped around the situation, whether that is covering a recruitment cycle, steadying the function after an incident, or hitting a deadline, and they end with a documented handover to the permanent leader.
START HERE
Not sure how exposed your board really is?
If you are reading this because security leadership just changed hands, the first question is how well your board can see and govern the risk right now. Our free Board Cyber Governance check gives you that read in minutes, and if the answer worries you, a conversation is the next step.
Board Cyber Governance check Book a conversation