DECISION GUIDE
When to bring in a vCISO
You are searching this because security has become a board question and nobody in the building owns the answer. This page sets out what the role does, the signs you have crossed the line into needing it, and how a fractional or interim arrangement delivers it without a six-figure permanent hire.
Book a conversationWhat a vCISO actually does
A vCISO, or virtual Chief Information Security Officer, is an experienced security leader who carries the responsibilities of a head of security on a part-time, retained or fixed-term basis. The job is not to run the firewall. It is to own the security strategy, set the risk appetite with the board, decide where the money goes, and make sure the organisation can answer for its decisions to customers, regulators and insurers. You bring one in when the security questions you face have outgrown the people you have to answer them, but the volume of work does not yet justify a permanent executive. The full definition sits on our what is a vCISO page, and the delivery model sits on our virtual CISO service.
The core responsibilities
Good security leadership covers a defined set of things, and a vCISO carries all of them rather than the convenient few. They build and maintain a security strategy tied to commercial priorities, not a generic framework lifted off the shelf. They own risk: identifying it, quantifying it in language the board understands, and deciding what to accept, transfer or fix. They set policy and make it stick. They run the controls programme, from access management to vulnerability handling. They prepare the organisation for the bad day with a tested incident response plan and clear ransomware readiness. And they handle compliance and assurance, whether that is NIS2 compliance, customer security questionnaires or audit. The distinguishing mark of the role is that it connects all of these into a single defensible position rather than running them as disconnected tasks.
What good looks like
A vCISO is doing the job well when the board stops being surprised. Risk is on the agenda before an incident forces it there. Decisions are written down with the reasoning attached, so when a customer or insurer asks why you chose a particular control, there is an answer. Spending is proportionate to real exposure rather than to the loudest vendor pitch. The security programme is documented well enough that a new starter, an auditor or a buyer in a technology due diligence process can follow it without a guided tour. And the leadership team can describe its own security posture in plain terms. If your current arrangement cannot produce that, you do not have the role covered, you have a collection of tools and hope.
The signs you need this role
Most organisations cross the line gradually and then all at once. The clearest signals are concrete. A major customer or your cyber insurer is now demanding evidence of security governance you cannot produce. You are inside a regulated supply chain and a directive such as NIS2 has landed on you. You are raising capital or selling, and the buyer’s diligence questions are exposing how thin the security function is. An incident has happened, or nearly happened, and the post-mortem showed nobody owned the response. Staff are quietly putting company data into AI tools and nobody is governing it, which is the shadow AI problem that needs an owner alongside a proper AI governance position. Or simply: your board has started asking security questions and the answers are coming from someone whose actual job is something else. Any one of these means the work now exists. The next question is how to resource it.
Why fractional or interim, not full-time
A permanent CISO in the UK commands a salary running from roughly £95,000 to £600,000 or more depending on sector and scope, before you add recruitment, equity, benefits and the months it takes to fill the seat. For a mid-market business the work is real but it does not fill five days a week, every week. That mismatch is exactly what the fractional and interim model resolves. A fractional CIO and CISO gives you senior judgement on a defined cadence, scaled to the actual demand. The CISO as a service model packages it as a retained capability. You get the strategy, the board presence and the decision ownership immediately, and you pay for the level you need rather than a fixed full-time cost. Our pricing sets out how that is structured, and the CIO and CISO cost calculator lets you compare it against a permanent hire directly.
Interim versus fractional, and when each fits
The two are not the same. Interim is a full-time, time-boxed appointment to hold a seat through a transition: a sudden departure, a crisis, a transformation programme, or the gap before you recruit permanently. That is the interim leadership gap scenario, and it is intensive while it lasts. Fractional is a steady, part-time arrangement for organisations that need senior security leadership on an ongoing basis but not a full-time one. Many businesses start with an interim engagement to stabilise and then move to a fractional rhythm once the urgent work is done. The same logic applies on the technology side through our vCIO service when the gap is broader than security alone.
How an engagement starts
A sensible first step is an honest assessment of where you stand, not a sales pitch dressed as a diagnostic. That means understanding your current exposure, your obligations, and what the board actually needs to see, then setting a strategy and a roadmap before touching any tooling. From there the work splits into the strategic agenda the vCISO owns and the delivery that gets executed underneath it, supported where useful by broader cyber security consulting and aligned to your wider IT strategy. Financial services firms with specific regulatory weight have their own version of this through our cyber security for financial services work, and organisations in the middle of change can fold it into a mid-market digital transformation. The goal of the first ninety days is the same everywhere: a board that knows its risk, a documented position, and a plan with owners.
Why Starkhorn
Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.
That combination of interim leadership inside a private-equity-backed group and a permanent CIO and CISO seat at a national motor retailer is exactly the experience that tells you when a vCISO is the right call and when a full-time hire is, because it has been both.
Frequently asked questions
When should you bring in a vCISO rather than recruit a permanent CISO?
Bring in a vCISO when the security work is real but does not fill a full-time executive role, or when you need senior judgement immediately and cannot wait months to recruit. If the demand genuinely justifies a permanent seat and you can fill it, hire one. For most mid-market organisations the fractional or interim model fits the actual volume of work and the budget far better.
What is the difference between a vCISO and an interim CISO?
An interim CISO is a full-time, time-boxed appointment to hold the seat through a transition or crisis. A vCISO is an ongoing, part-time arrangement for organisations that need security leadership continuously but not full-time. Many start interim to stabilise, then move to a fractional rhythm.
What does a vCISO actually do day to day?
They own the security strategy, set risk appetite with the board, decide where security spending goes, keep policy current and enforced, run the controls programme, prepare incident response, and handle compliance and customer assurance. The role connects all of these into a single defensible position rather than running them as separate tasks.
How much does a vCISO cost compared with a full-time hire?
A permanent UK CISO salary runs from roughly £95,000 to £600,000 or more before recruitment, equity and benefits. A vCISO scales to the demand you actually have, so you pay for the level of senior input you need rather than a fixed full-time cost. Our cost calculator lets you compare the two directly.
What are the clearest signs we need a vCISO now?
A customer or insurer demanding security governance you cannot evidence, a regulatory directive landing on you, diligence questions during a raise or sale exposing a thin security function, a recent incident with no clear owner, ungoverned use of AI tools, or a board asking security questions that nobody whose actual job it is can answer.
START HERE
Find out whether your board has the security oversight it needs
If your board has started asking security questions and the answers are coming from the wrong place, that is the signal. The Board Cyber Governance check shows you, in a few minutes, where your oversight is strong and where it leaves you exposed. Run it first, then bring the results to a conversation and we will tell you honestly whether a vCISO is the right call.
Board Cyber Governance check Book a conversation