SECURITY LEADERSHIP

When does a business need a CISO?

You are probably here because security has stopped being something IT handles quietly and started landing on your desk: a client security questionnaire you cannot answer, a board asking about cyber risk, an incident that scared everyone. This page sets out what a Chief Information Security Officer actually does, the signs you need one, and how a fractional or interim arrangement gives you that leadership without a full-time hire.

Book a conversation

What a CISO does, in plain terms

A business needs a CISO when security decisions carry enough weight that they cannot sit unowned, and no one in the organisation has the authority or mandate to own them. The CISO is the person accountable for protecting the company’s information: deciding what to defend, how much to spend, which risks to accept and which to remove. It is a leadership role, not a technical one. The work is judgement under uncertainty, translating threats into business language, and making sure the board understands what it is signing off. A good CISO sets the security strategy, owns the risk register, runs the response when something goes wrong, and answers to the board for all of it. If you want the fuller picture of how this maps to the technology leadership it sits beside, our CISO as a service and virtual CISO pages cover the engagement models in detail.

The core responsibilities

Strip away the job titles and a CISO owns five things. First, strategy: a written, prioritised plan for what gets protected and in what order, tied to what the business actually does. Second, risk: a live register that the board can read, where each entry has an owner and a decision attached. Third, governance and compliance: making sure the organisation meets its obligations, whether that is contractual security clauses, sector regulation, or frameworks like NIS2. Fourth, response: a tested incident response plan so that when an attack lands, people know who decides what and in what order. Fifth, assurance to the board: turning technical posture into a few honest sentences a non-technical director can act on. Everything else, the tooling, the audits, the awareness training, exists to serve those five.

What good looks like

You can tell a security function is led well without reading a single technical report. The board gets a short, plain account of the top risks and what is being done about them, and it is the same story quarter to quarter rather than a fresh panic each time. Client security questionnaires get answered quickly and truthfully because the evidence already exists. When an incident happens, and it will, the response is calm and rehearsed rather than improvised. Spending is proportionate: money goes to the risks that matter, not to whatever the last vendor demonstration was about. And the answer to “are we secure?” is never “yes” or “no” but a clear statement of what is covered, what is not, and what that costs to change. If that is not what you are getting today, the gap is leadership, not tools. Our cyber security consulting work usually starts by closing exactly that gap.

The signs you need this role now

A handful of triggers reliably mean the role can no longer stay unowned. Customers or insurers are demanding security assurances you cannot evidence. You hold sensitive data, financial, health, or personal, at a scale where a breach would be material. You are entering a regulated market or a sector where security obligations are explicit, such as financial services. You are going through a transaction and security is part of the technology due diligence. You have just had a near miss, or a real one, and the board now wants accountability. Or you are adopting AI quickly and nobody owns the new risk it creates, the territory we cover under AI governance and shadow AI. If two or more of these are true, you have already crossed the line.

  • Clients or insurers want security evidence you cannot produce.
  • You handle sensitive data at a scale where a breach would hurt.
  • You are entering regulated territory or facing new compliance duties.
  • A deal is underway and security is in scope for diligence.
  • You have had an incident, and the board wants someone accountable.

Why most mid-market firms outsource it

A full-time CISO is expensive and, for many firms, underused. UK salaries for the role run from roughly £95,000 to £600,000 or more depending on sector and scale, before recruitment, benefits and the months it takes to fill the seat. More to the point, a company that needs security leadership rarely needs forty hours a week of it. What it needs is senior judgement, a credible plan, and a steady hand on governance, delivered at the level of intensity the risk actually warrants. That is why so many mid-market organisations take the role fractionally: a fractional CIO and CISO gives you board-grade security leadership for a few days a month, scaling up around an audit, a deal or an incident, and down again once the work is steady. If you want to compare that against the cost of a permanent hire, the CIO and CISO cost calculator makes the numbers concrete.

How a fractional or interim arrangement delivers it

There are two shapes to this. A fractional CISO is an ongoing, part-time leader: they own your security strategy and risk on a continuing basis, attend the board, and grow the function over time. An interim CISO is a full-time appointment for a fixed period, used to cover a sudden departure, steer a transformation, or stabilise things after a serious incident, the same pattern as an interim leadership gap on the CIO side. Both give you experience you could not justify hiring permanently, and both start by establishing what matters: a risk picture the board can trust, a plan with priorities, and the governance to keep it honest. From there the work is steady and unglamorous, raising your ransomware readiness, tightening board cyber governance, and making sure security supports rather than blocks the business. For how this connects to wider technology direction, see our IT strategy consulting and vCIO work, and the pricing page for how engagements are structured.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

That combination of holding the CISO seat at a national group and stepping into interim technology leadership at a private-equity-backed business is exactly the vantage point you want when deciding whether your firm needs a CISO yet, and how much of one.

Frequently asked questions

How big does a company need to be before it needs a CISO?

Size matters less than exposure. A small firm holding sensitive client data or operating in a regulated sector needs security leadership sooner than a larger one with little data and low risk. The real test is whether security decisions now carry consequences that no one currently owns.

What is the difference between a CISO and a virtual or fractional CISO?

The role is the same; the arrangement differs. A virtual or fractional CISO performs the function part-time, on an ongoing basis, giving you board-grade security leadership without a permanent salary. Our what is a vCISO page explains the model in full.

Can our IT team or managed service provider just do this instead?

They can run the controls, but they cannot own the risk. A CISO sets priorities, makes the trade-offs, accepts risk on the board’s behalf and answers for it. That accountability sits above day-to-day IT and is precisely what an IT team or provider is not positioned to hold.

How much does a CISO cost?

A permanent UK CISO salary runs from roughly £95,000 to £600,000 or more depending on sector and scale, before recruitment and benefits. A fractional arrangement costs a fraction of that because you buy the days you need; the cost calculator lets you compare directly.

We have just had an incident. Is it too late to bring in a CISO?

No. An interim CISO is often appointed in exactly that situation to stabilise the response, fix what failed and rebuild board confidence. The aftermath of an incident is one of the clearest moments to put accountable security leadership in place.

START HERE

Not sure whether your board has security covered?

If the questions on this page hit home, the fastest way to find out where you stand is to look at it from the board’s seat. The free Board Cyber Governance check shows you what your directors should be able to see and answer, and where the gaps are. Run it, then let us talk through what it surfaces.

Board Cyber Governance check Book a conversation