Introduction
Cyber security often becomes a priority at an awprospective customer sends a lengthy security questionnaire. An investor asks how cyber risks are managed. The business needs Cyber Essentials, ISO 27001 or SOC 2. A client contract introduces new security obligations. Alternatively, an incident exposes weaknesses that had previously been accepted or overlooked.
At this stage, the business may need experienced security leadership but not necessarily a full-time Chief Information Security Officer.
A virtual or fractional CISO can fill that gap, giving startups and SMEs access to senior cyber security expertise for an agreed portion of the time and cost of a permanent executive.
What is a vCISO?
A virtual Chief Information Security Officer, commonly called a vCISO, is an external security professional who provides strategic leadership, governance and oversight without being employed as the organisation’s full-time CISO.
A fractional CISO usually performs a similar role but is often more closely embedded in the company for an agreed number of days each month or week.
In practice, the terms overlap:
- Virtual CISO often describes an outsourced service that may be delivered largely remotely.
- Fractional CISO usually emphasises that the organisation is buying a defined fraction of an experienced CISO’s time.
- CISO as a Service may involve a wider provider team supporting the named CISO.
There is no standardised legal definition of these terms, so the scope matters more than the label. Some providers offer primarily policies and compliance support, while others provide genuine executive leadership covering business risk, technology, product security, incident readiness and board reporting. Published UK service descriptions reflect this variation in delivery models and scope. does a fractional CISO actually do?
A good fractional CISO connects cyber security decisions to the organisation’s commercial objectives.
Their work will commonly include:
- Assessing the company’s current security position.
- Identifying and prioritising material cyber risks.
- Developing a practical security strategy and roadmap.
- Helping leadership define acceptable levels of risk.
- Establishing policies, responsibilities and governance.
- Reporting security risks and progress to the board.
- Preparing the organisation for incidents.
- Supporting customer and supplier security assessments.
- Advising on Cyber Essentials, ISO 27001, SOC 2 and regulatory requirements.
- Helping product and engineering teams build security into technology decisions.
- Coordinating specialist providers such as penetration testers, managed security services and incident-response firms.
The role should not be limited to producing documents. Its purpose is to give the organisation clear security leadership: deciding what matters, who owns it, what should be done first and how progress will be measured.
This reflects the UK National Cyber Security Centre’s Cyber Governance Code of Practice, which identifies five core governance areas: risk management, strategy, people, incident planning and recovery, and assurance and oversight. The NCSC emphasises that these areas require leadership and proactive engagement at board level. o startups and SMEs need security leadership?
Smaller organisations sometimes assume they are unlikely to be targeted. The latest UK government evidence does not support that assumption.
The 2025/2026 Cyber Security Breaches Survey found that 43% of UK businesses had identified a cyber breach or attack during the previous 12 months. The figure was 42% for microbusinesses, 46% for small businesses and 65% for medium-sized businesses. Phishing remained the most common type of attack. ame time, many businesses lack basic governance and preparation:
- Only 36% of businesses reported having formal cyber security policies.
- Only 33% had a business continuity plan covering cyber security.
- Only 25% had a formal cyber incident-response plan.
- Only 31% had a board member with explicit responsibility for cyber security. owing company, cyber security is not only about preventing attacks. It can affect the company’s ability to:
- Win larger or more regulated customers.
- Complete customer security due diligence.
- Demonstrate responsible governance to investors.
- Obtain or maintain cyber insurance.
- Enter new markets.
- Protect intellectual property.
- Meet contractual and regulatory obligations.
- Recover quickly when something goes wrong.
The NCSC advises that prospective suppliers should be able to provide evidence of their security approach. It also notes that demonstrating good cyber security can help organisations win supplier contracts, particularly where standards such as Cyber Essentials are required. can also feature in investment decisions. The UK National Protective Security Authority advises investors to consider security risks during pre-investment due diligence and to use their influence to help portfolio companies grow securely. onal CISO helps turn these external expectations into an achievable programme rather than a last-minute scramble whenever a customer, insurer or investor asks a difficult question.
How much does a vCISO cost in the UK?
There is no standard UK tariff for fractional CISO services. Costs vary according to:
- The number of days or hours required.
- The seniority and experience of the CISO.
- The size and complexity of the business.
- Whether the organisation operates in a regulated sector.
- The number of products, systems and locations involved.
- The maturity of the existing security programme.
- Whether hands-on implementation is included.
- Whether support is required outside normal working hours.
- The amount of customer, audit or certification support required.
Published UK provider guides currently place fractional or virtual CISO day rates broadly between £1,000 and £3,500 per day. Published monthly retainers commonly fall between approximately £3,000 and £15,000 per month, with specialist, regulated or more heavily embedded engagements at the upper end. These are advertised market ranges rather than an independently calculated national average. trative structure might look like this:
| Engagement | Typical use | Illustrative monthly cost |
|---|---|---|
| Light-touch advisory | Regular leadership advice and roadmap reviews | £2,000–£5,000 |
| Core fractional support | Governance, risk management and delivery oversight | £4,000–£10,000 |
| Embedded fractional CISO | One or two days per week with substantial delivery responsibility | £8,000–£15,000+ |
| Defined project | Assessment, certification readiness or remediation programme | Fixed according to scope |
These figures should be treated as budgeting guidance, not a quote. A low-cost service providing standard templates is not directly comparable to an experienced CISO who participates in leadership meetings, challenges business decisions, works with engineering teams and remains accountable for delivering a measurable security programme.
Businesses should therefore compare scope, outcomes and access, rather than comparing monthly fees alone.
How does that compare with an in-house CISO?
A permanent CISO provides full-time leadership and becomes deeply integrated into the company. For organisations with significant scale, regulation, security teams or daily executive demands, this can be the right model.
However, recruiting an experienced CISO represents a substantial commitment.
Morgan McKinley’s 2026 salary guide places the average London CISO salary at approximately £130,000 to £160,000, with more experienced roles extending beyond that range. Barclay Simpson’s 2026 cyber security salary guide lists global or EMEA CISO positions at £180,000 or more, while smaller-team Head of Information Security roles range from approximately £100,000 to £160,000.
Salary however is only part of the cost. Employers must also consider recruitment, National Insurance, pension contributions, bonuses, benefits, training, equipment, leave and the cost of any supporting security team.
The comparison is therefore not simply “full-time CISO versus cheaper consultant”. The two models solve different organisational needs.
| Area | Fractional or virtual CISO | In-house CISO |
|---|---|---|
| Availability | Agreed days or hours | Full-time |
| Cost | Flexible retainer or project fee | Salary plus employment costs |
| Organisational knowledge | Builds over the engagement | Usually deeper over time |
| Independence | Strong external perspective | More embedded in internal culture |
| Flexibility | Can scale up or down | Harder to change quickly |
| Specialist experience | May bring experience from several organisations | Depends on the individual |
| Day-to-day leadership | Limited by contracted availability | Continuously available |
| Long-term team building | Can establish the function | Better placed to lead it permanently |
A fractional CISO is usually most appropriate when the business needs senior judgement and direction but does not yet have enough continuous executive-level security work to justify a permanent position.
An in-house CISO becomes more appropriate when cyber security requires daily leadership, the company has a significant internal security team, regulatory accountability is extensive or the organisation’s complexity makes part-time coverage impractical.
When should a startup engage a fractional CISO?
A startup does not necessarily need a retained vCISO from its first day of trading. Early-stage companies may gain more value from a focused security assessment, a prioritised roadmap and periodic advisory support.
The need for a fractional CISO tends to become clearer when the company:
- Starts selling to enterprise or public-sector customers.
- Handles significant volumes of sensitive or regulated data.
- Enters healthcare, financial services, defence or other regulated markets.
- Begins preparing for ISO 27001, SOC 2 or similar assurance.
- Receives repeated customer security questionnaires.
- Is preparing for investment or acquisition due diligence.
- Expands its engineering team or technology estate rapidly.
- Needs someone to report cyber risks to the board.
- Has experienced a significant incident.
- Has several security suppliers but nobody providing overall direction.
Outsourcing security expertise is already common among smaller UK organisations. The 2025/2026 government survey found that 64% of small businesses and 70% of medium-sized businesses used an external cyber security provider. rtant question is whether those external services are being coordinated against a coherent business strategy. Buying tools, penetration tests and compliance support separately does not automatically create effective security leadership.
What a vCISO is not
A fractional CISO should not be confused with:
- An outsourced IT support provider.
- A managed security operations centre.
- A penetration tester.
- A data protection officer.
- A compliance auditor.
- A person who simply sells security products.
- A guarantee that the organisation will never experience an incident.
These services may all contribute to the security programme, but they perform different functions.
The fractional CISO should provide leadership and oversight across them. They should help the organisation decide which services are needed, define the expected outcomes and ensure gaps or duplicated responsibilities are addressed.
What should be included in the engagement?
A well-defined vCISO agreement should set out:
The business outcomes
These might include improving customer assurance, reducing priority risks, achieving certification, establishing board reporting or preparing for investment.
The scope
The agreement should clarify whether the service covers governance only or also includes implementation, technical architecture, supplier reviews, audit support and incident management.
Time and availability
The company should know how many days are included, how meetings are handled and what happens when urgent support is required.
Named responsibilities
The vCISO cannot own every security task personally. Responsibilities should be divided between leadership, IT, engineering, operations, suppliers and the vCISO.
Deliverables
Expected outputs might include a risk register, strategy, roadmap, policies, board reports, incident plans, supplier standards and assurance evidence.
Measures of progress
Success should be demonstrated through risk reduction and business outcomes.
Additional costs
The contract should explain whether travel, emergency support, certification work, technical testing and tooling are included or charged separately.
An exit or transition plan
A fractional CISO should help the organisation build sustainable internal capability. This may eventually include recruiting a permanent security leader and handing over the established programme.
How to choose the right fractional CISO
Look beyond certifications and job titles. A suitable fractional CISO should be able to demonstrate:
- Experience with organisations of a similar size and growth stage.
- Relevant knowledge of your sector and customer base.
- The ability to communicate with directors, investors and technical teams.
- A balance of technical, risk and governance experience.
- Clear examples of practical outcomes delivered for other clients.
- Independence from unnecessary product sales.
- A defined delivery method and reporting cadence.
- Appropriate professional insurance and contractual protections.
- Willingness to challenge leadership constructively.
- Clear boundaries around availability and incident support.
Be cautious where a service promises rapid compliance without meaningful involvement from your business, provides a library of generic policies as the main deliverable, or cannot clearly explain how its work will support your commercial priorities.
Is a fractional CISO worth it?
A fractional CISO is not automatically the correct answer for every startup or SME.
For a very small company with limited data and a simple technology environment, a focused assessment and practical improvement plan may be sufficient. At the opposite end, a complex or heavily regulated organisation may need a permanent CISO and an internal security team.
Between these points, however, many growing businesses face a genuine leadership gap. They are too exposed to continue managing security informally, but not yet large enough to justify a full-time security executive.
A good fractional CISO fills that gap. The real value is not simply access to cyber security knowledge. It is having an experienced leader who can translate risk into business decisions, prioritise limited investment and build the level of trust that customers, investors and regulators increasingly expect.
Cyber security then becomes more than a defensive cost. It becomes part of the company’s ability to win business, protect its value and grow with confidence.
Principal sources
This article draws on the following current UK evidence:
- Department for Science, Innovation and Technology, Cyber Security Breaches Survey 2025/2026.
- National Cyber Security Centre, Cyber Governance Code of Practice.
- National Cyber Security Centre, Supply Chain Security Guidance.
- National Protective Security Authority, Secure Innovation: Investor Guidance.
- Morgan McKinley, 2026 UK CISO Salary Guide.
- Barclay Simpson, 2026 Cyber Security Salary Survey and Recruitment Trends Guide.
