The interim CISO: when to hire one, what it costs and how to measure success
A complete guide to interim and fractional security leadership — when it beats a permanent hire, what the first 90 days should deliver, and how to plan the handover.
Interim security leadership is often treated as a stopgap between permanent hires. Used well, it is a deliberate intervention with a defined job to do: reset direction, stabilise delivery, and leave behind a function that works without the person who built it.
Interim, fractional or virtual CISO?
The terms are used loosely, and the differences matter when you are budgeting.
- Interim CISO. Full-time or near full-time, for a fixed period, usually three to twelve months. Carries the mandate of the permanent role, including board reporting and budget ownership.
- Fractional CISO. A defined number of days per month on an ongoing basis, typically two to six. Suits organisations that need senior judgement and accountability but not a full-time leader.
- Virtual CISO. Usually a lighter, advisory arrangement delivered largely remotely — governance, policy, assurance support and periodic reviews — often with a wider team behind it.
The right choice follows from what you need decided. If someone must own risk acceptance decisions in front of a board, you need interim or fractional accountability, not advice.
When an interim is the right answer
- A permanent CISO has left mid-programme and delivery is drifting.
- A transformation, acquisition or regulatory commitment needs senior ownership now, not in six months.
- The organisation is unsure what shape the permanent role should be, and hiring against the wrong specification would be an expensive mistake.
- A customer, insurer or regulator has asked who owns security, and the honest answer is currently "several people, partly".
- You have a capable security team but no one at the table when the budget and priorities are set.
Getting the shape of the role right before you commit is the same discipline we describe in our guide to cyber security recruitment.
What it costs, and how to think about the number
Interim day rates for genuinely senior UK security leaders sit well above the equivalent daily cost of a permanent salary, and that comparison is the wrong one. An interim has no notice period to serve, no ramp-up subsidy, no recruitment fee, and no long-term liability. You are buying a defined outcome over a defined window.
Frame the business case around what the engagement removes or unlocks: stalled programme spend, a contract that cannot be signed without security sign-off, remediation that keeps slipping, or a permanent hire made against the wrong specification. Fractional arrangements are often the better value where the need is continuous judgement rather than continuous presence.
What good looks like in the first 90 days
Weeks one to four: understand
Understand the estate, the obligations and the people. Read the last two years of audits, incidents and board papers. Meet the sceptics as well as the sponsors. Establish what is actually running versus what is on the architecture diagram — the gap is usually the story.
Weeks five to eight: decide
Publish an honest position on risk, a prioritised plan and the funding required. Kill the initiatives that no longer earn their place. This is often where an independent health check and gap analysis earns its keep, because it gives the plan an evidence base rather than an opinion base.
Weeks nine to twelve: deliver and stabilise
Land the first visible wins, put governance and reporting on a stable rhythm, and start defining the permanent operating model and role specification. Progress people can see is what buys the mandate for the harder work in months four to nine.
How to measure an interim CISO
Agree the measures before the engagement starts. Useful ones:
- A current, board-agreed risk position, with named owners and accepted risks documented.
- A costed, sequenced remediation plan, with the first tranche actually delivered rather than only planned.
- Governance operating on a fixed cadence, with reporting a successor can pick up unchanged.
- Reduced exposure on the specific issues that triggered the engagement — audit findings closed, controls enforced, tooling consolidated.
- A permanent role specification and hiring plan, or a documented decision that the fractional model continues.
Avoid measuring activity. Number of policies written is not an outcome; policies that are followed and enforced are.
The handover is the deliverable
An interim who becomes indispensable has failed. Success is a functioning team, a plan with owners, board reporting that continues without them, and a permanent hire set up to succeed rather than to firefight. Ask for that outcome to be written into the engagement from day one, including a documented handover pack and an overlap period with the incoming permanent leader.
Common mistakes
- Hiring an interim with no mandate over budget or priorities, then wondering why nothing changed.
- Letting the engagement become open-ended, with the exit criteria never written down.
- Using an interim to avoid a difficult permanent decision about the operating model.
- Choosing a supplier whose interim leadership recommends only that supplier's products. Independence matters here more than anywhere; it is why we deliberately sell no product, as explained on our about page.
- No handover overlap, so eighteen months of context leaves on the last day.
Where to go next
We provide interim and fractional security leadership through our programme leadership and interim CISO service, backed by an associate network for scalable resourcing when the plan needs delivery hands as well as direction. You can also read more of our leadership writing or arrange an intro call.