Tag: vCISO

  • What is a Fractional CISO?

    What is a Fractional CISO?

    What is a Fractional CISO?
    Published: March 17, 2026

    If you’ve started looking at your cyber risk and realised you need someone senior in the room — but a full-time CISO at £120,000–£180,000 a year isn’t on the cards — a Fractional CISO is probably what you’re looking for.

    The term gets used loosely. Let me give you a straight answer about what it actually means, what a Fractional CISO does day-to-day, and how to tell whether you need one.

    The Short Version

    A Fractional CISO is a senior security leader who works with your organisation on a part-time or interim basis — typically one to three days a week, often on a fixed-term engagement. You get the strategic judgement and hands-on experience of someone who has run security at enterprise level, without hiring them full-time.

    The “fractional” model exists because most SMEs and growing businesses don’t need a full-time CISO. What they need is serious security leadership a few days a week — someone who can set the direction, own the risk, talk to the board, and make sure the technical team is pointed the right way.

    What a Fractional CISO Actually Does

    This varies by engagement, but in practice the work falls into a few consistent areas:

    Security strategy and governance — defining your security posture, setting policy, building a roadmap that’s proportionate to your risk and your budget. Not a 200-page document nobody reads. A working plan the business can execute.

    Risk and compliance — owning your risk register, preparing for Cyber Essentials or Cyber Essentials Plus, supporting ISO 27001 if that’s relevant, making sure you’re meeting your contractual and regulatory obligations. For many UK businesses this increasingly means GDPR accountability as well.

    Incident readiness — making sure you have a plan before something goes wrong, not after. Running tabletop exercises, reviewing your backup and recovery position, knowing who calls who at 2am.

    Board and leadership communication — translating technical risk into business language. A board doesn’t need to understand CVE scores. They need to understand what they’re liable for and what it would cost if something went wrong. That’s a skill most technical security people don’t have, and it’s where a good CISO earns their fee.

    Vendor and supplier oversight — reviewing what your MSP is actually doing, checking your cloud configuration, making sure the security tooling you’re paying for is configured correctly. In my experience, most SMEs have the right tools and the wrong settings.

    What a Fractional CISO Is Not

    They’re not a one-off consultant who delivers a report and disappears. That’s a security audit. Useful, but different.

    They’re not a managed security service (MSSP). An MSSP monitors your environment and responds to alerts. A Fractional CISO sets the strategy that determines what you’re monitoring and why.

    They’re not a replacement for a good IT team or MSP. They work alongside your existing technical resource, not instead of it.

    Who Needs a Fractional CISO?

    The businesses I typically work with fit one of a few patterns:

    • Growing SMEs (50–500 people) who have outgrown “IT does security” but aren’t ready to hire a full-time CISO. Often triggered by a new enterprise customer asking about your security posture, or a cyber insurance renewal that suddenly requires evidence.
    • PE-backed portfolio companies where the fund needs consistent security governance across multiple portfolio businesses. One fractional CISO across two or three companies is far more cost-effective than three separate hires.
    • Businesses going through change — acquisition, cloud migration, rapid headcount growth. Security debt accumulates fast in these moments. A fractional engagement through the transition prevents problems that are very expensive to fix later.
    • Businesses post-incident who need someone to come in, stabilise, and build something better. This is the most urgent version of the engagement and usually the most intensive.

    What It Costs

    Engagement structures vary, but a typical fractional CISO arrangement in the UK runs between £3,000 and £8,000 per month depending on days committed and scope. Compare that to the fully-loaded cost of a permanent hire — salary, NI, benefits, pension, recruitment fees — and the economics are usually straightforward.

    For most SMEs, the right entry point is a Discovery Audit: a structured review of your current security posture that produces a prioritised roadmap. It gives you a clear picture of where you stand and what to fix first, and it’s the starting point for any ongoing engagement.

    The Question Worth Asking

    Most businesses don’t call a Fractional CISO until something prompts them — a near-miss, a contract requirement, a board conversation. The ones that get the most value engage before that moment, when there’s time to build something properly rather than fix something broken.

    If you’re not sure whether your business is in a good position, the honest answer is: you probably don’t know, and that’s worth finding out. The way I structure this work is described on the Security & Compliance Strategy service page.

    Book a 30-minute call to talk through your situation — no pitch, just a frank conversation.

  • What Does a Fractional CISO Cost in the UK? (2026 Guide)

    What Does a Fractional CISO Cost in the UK? (2026 Guide)

    If you’ve started looking into fractional CISO arrangements, you’ve probably noticed that nobody publishes rates. You get vague talk about “competitive pricing” and “tailored engagements” but no actual numbers.

    This is my attempt to fix that. I’ll give you the real ranges, explain what moves the price, and give you the comparison you actually need: fractional versus a permanent hire.

    What You’re Actually Buying

    Before we get to numbers, it’s worth being clear about what a Fractional CISO engagement actually covers — because the answer affects the cost.

    A Fractional CISO is not a security consultant who writes reports. That’s a different engagement model. A Fractional CISO is a part-time member of your senior leadership, operating as your de facto Chief Information Security Officer with all the accountability that implies.

    In practice, that means:

    Ownership of your security posture. Not advice about it. Actual ownership — setting strategy, making decisions, reporting to the board or CEO on risk.

    Ongoing availability. Not just fixed project days. A good Fractional CISO is reachable when something happens — a supplier breach, an insurance questionnaire, a board request for a risk briefing.

    Day-to-day security leadership. Reviewing controls, managing incidents, overseeing your IT team or MSP on security matters, making sure the work actually gets done.

    External credibility. Being able to put a named CISO on a client questionnaire, a contract, or an audit scope. For mid-market businesses dealing with enterprise customers, this alone is often worth the fee.

    That distinction matters because it separates fractional from project-based work, and the price reflects it.

    Typical Cost Ranges in the UK Market

    Here are the real numbers as of 2026, based on the UK market specifically:

    Entry-level engagement: £2,500–£4,000/month
    Usually one day a week, or a structured retainer. Covers governance, policy, and light-touch oversight. Right for smaller businesses (20–80 people) who need a documented security posture and someone accountable for it, but don’t have complex infrastructure or active compliance requirements.

    Mid-range engagement: £4,000–£7,000/month
    One to two days a week. This is the most common arrangement for UK SMEs between 80 and 300 people. Covers strategy, compliance (Cyber Essentials Plus, ISO 27001 readiness, GDPR accountability), board reporting, incident management, and oversight of your technical security team or MSP.

    Higher-intensity engagement: £7,000–£12,000/month
    Two to three days per week, or a fixed-scope intensive engagement (post-incident stabilisation, pre-acquisition security readiness, major compliance programme). At this level you’re getting something close to a full-time CISO presence without the full-time cost.

    Some providers price by day rate rather than monthly retainer. In that case, expect senior Fractional CISO day rates in the UK to sit between £900 and £1,800 per day, depending on experience and specialism.

    What Affects the Price

    The same fractional CISO will charge differently for different engagements. Here’s what moves the number:

    Days committed per month. The main variable. More days, more cost — but also more hands-on delivery versus purely strategic oversight.

    Compliance scope. If you’re pursuing ISO 27001, preparing for a major enterprise audit, or navigating sector-specific requirements (financial services, healthcare, defence supply chain), the workload increases substantially. Expect to pay for it.

    Incident history. Starting from scratch is easier than cleaning up after a breach or a failed audit. Post-incident engagements are more intensive and more expensive in the early months.

    Organisation complexity. 50 people in one office with a single cloud environment is a different engagement to 200 people across four countries with a mix of legacy systems, SaaS, and on-premise infrastructure.

    Urgency. A phased 12-month engagement costs less per month than a 90-day sprint to get you through a due diligence process. You pay for speed.

    Fractional vs Full-Time: The Real Comparison

    A permanent CISO in the UK costs, on a fully-loaded basis:

    • Base salary: £90,000–£160,000 (senior hire in London; less outside)
    • Employer NI: ~13.8% on salary
    • Pension contributions: typically 5–8%
    • Benefits package: private health, life assurance, income protection
    • Recruitment fees: typically 20–25% of first-year salary if using an agency

    Add it up and a full-time CISO typically costs £130,000–£220,000 per year all-in before you’ve counted their office space, equipment, management overhead, or the time it takes to find the right person.

    A mid-range fractional engagement at £5,000/month is £60,000 per year. You get senior-level security leadership at roughly half the cost, with no recruitment risk, no notice period to serve, and the ability to scale the days up or down as your needs change.

    For most UK SMEs, the only reason not to go fractional is if your security workload genuinely justifies full-time attention — and that usually means you’re above 500 people with a complex regulatory environment, active threat landscape, or significant security-critical product development.

    The Starting Point: A Discovery Audit

    For most businesses, the right first engagement isn’t a retainer. It’s a Discovery Audit: a structured review of your current security posture that takes two to three days and produces a prioritised action plan.

    It answers the question: where do we actually stand? It removes the uncertainty from any ongoing engagement that follows, and it’s the honest way to scope a fractional arrangement — you don’t know what you’re buying until you know what the problems are.

    If you’re comparing providers, ask whether they’ll do a discovery engagement before committing to a retainer. If the answer is no, that’s a signal.


    If you’d like to talk through what a fractional CISO engagement might look like for your business — scope, cost, timeline — see the Security & Compliance Strategy service or get in touch directly. I’ll give you a straight answer about whether it makes sense.