TL;DR
Fractional CISO UK day rates are typically best planned at around £900–£1,500 per day for many SME and mid-market assignments, with regulated, crisis or highly specialised work potentially higher. Current UK contractor benchmarks range from a £860 median in recent CISO vacancies to £1,125 in a March 2026 technology salary guide, so scope matters more than a headline rate.
A monthly retainer can be easier to manage than ad hoc days: at that planning range, two days a month is about £1,800–£3,000 and four days is about £3,600–£6,000. Last updated: 19 August 2026.
Fractional CISO UK day rates are a sensible starting point when a managing director needs senior cyber judgement without creating a full-time executive post. The question is not simply “What does a CISO charge?” It is “What level of leadership, assurance and delivery does the business need over the next six to twelve months?”
A growing company may have an IT support partner and capable staff, but still lack one person who can turn risks into board decisions. The gap appears during a customer security review, ISO 27001 programme, acquisition, serious incident or major systems change.
The market has a capacity problem. The UK Government’s 2025 cyber skills research found basic technical skills gaps in 49% of businesses and advanced gaps in 30%. Defined leadership can be more practical than waiting for a permanent hire while risk accumulates.
What do fractional CISO UK day rates cover?
A fractional Chief Information Security Officer is a senior security leader who works part time for an agreed number of days or hours. The role covers cyber strategy, risk ownership, governance, architecture decisions, supplier oversight, incident readiness and board reporting. It is different from an outsourced helpdesk: the CISO sets direction and accountability, then works with internal teams and providers to deliver it.
The brief should be tied to outcomes. One company may need a 90-day baseline and board pack. Another may need an ISO 27001 roadmap, customer assurance responses, contract requirements and a tested incident plan. A third may need an interim leader after an executive leaves. Each assignment can justify a different rate because judgement, urgency and exposure differ.
The National Cyber Security Centre’s Cyber Governance Code of Practice groups board responsibilities into Risk Management, Strategy, People, Incident Planning, Response & Recovery, and Assurance & Oversight. A good fractional CISO helps the board address those areas in plain business language, rather than presenting a long list of technical controls without priorities.
How much are fractional CISO UK day rates in 2026?
There is no single official price list, and published benchmarks measure different things. IT Jobs Watch reported a UK CISO contract median of £860 per day for vacancies in the six months to 4 February 2026. Its page notes that the UK-wide figure was based on eight matching jobs and two quoted daily rates, so treat it as an indicator rather than a quotation.
A separate March 2026 UK technology salary guide lists a £1,125 contractor day rate for CISO roles, alongside a median permanent base salary of £137,300. These benchmarks support a working budget of roughly £900–£1,500 per day for many fractional or interim briefs, with specialist regulatory, transaction, crisis or board-level work potentially higher. This is the practical context behind fractional CISO UK day rates.
At £900–£1,500 per day, two days each month works out at £1,800–£3,000 before VAT and separately commissioned technical testing; four days is £3,600–£6,000. A short diagnostic may need more time in month one, then move to a lighter rhythm once the risk register, reporting and improvement plan are in place.
Compare like with like before choosing the lowest number. Ask whether the rate includes board preparation, policy writing, supplier meetings, incident exercises, travel, out-of-hours availability and follow-through. A low rate can become expensive if the brief excludes the decisions the business needs or leaves several providers to coordinate.
What changes a fractional CISO day rate?
The day rate should reflect the risk and work involved, not just the job title. The main pricing factors are:
- Scope and days — a board briefing and roadmap differs from hands-on programme leadership four days a week.
- Regulatory exposure — financial services, healthcare, critical suppliers and public contracts can require deeper assurance and specialist knowledge.
- Urgency — planned improvement is easier to staff than a live incident, breach recovery or a deadline measured in weeks.
- Complexity — multiple sites, cloud accounts, legacy systems, acquisitions and third-party access add dependencies.
- Experience — board communication, regulated-sector experience and difficult-change leadership may matter more than a certification.
- Delivery support — clarify whether the CISO does the work, directs a team, manages suppliers or provides assurance.
- Location and travel — remote work may be priced differently from regular on-site leadership or exercises.
How a fractional CISO engagement works
A useful engagement starts with short discovery. The CISO meets the MD, finance lead, technology owner and suppliers; reviews the risk register, policies, contracts and incidents; and identifies systems and information that matter most. The output is a concise view of priorities, owners, decisions and immediate gaps.
The next step is a time-boxed plan. It might include privileged-access improvements, backup and recovery testing, supplier assurance, security awareness, penetration-test remediation, an ISO 27001 workstream or a board reporting cadence. Each action should have an owner, target date and evidence of completion. The CISO should be able to explain why an action matters commercially and what can wait.
Imagine a 120-person software business losing enterprise deals because it cannot answer security questionnaires consistently. A fractional CISO could establish the control baseline, assign evidence owners, close high-risk gaps, coordinate an independent test and give sales a reliable assurance pack. The business pays for focused leadership while building capability its people can maintain.
This model also makes it easier to increase or reduce support. Add days during a certification push, acquisition or incident exercise; reduce to a monthly board and risk rhythm when the programme is stable. The contract should state response expectations, confidentiality, ownership of work products and what happens if an incident occurs outside planned days.
How to choose the right fractional CISO
Start with the decision you need the leader to make. Ask candidates to show how they translated cyber risk for boards, challenged suppliers, prepared for incidents and prioritised controls with limited budget. Experience should fit your size, sector, customer expectations and technology estate, not just a list of acronyms.
Test the working relationship as well as technical knowledge. A strong CISO collaborates with an IT provider without becoming dependent on it, gives an MD a clear answer when evidence is incomplete and explains trade-offs to non-specialists. Ask what the first 30 days produce and how progress is reported.
Finally, get commercial clarity in writing: day or monthly rate, minimum commitment, travel, availability, deliverables, data handling and notice terms. Leadership Services’ fractional CISO service can start within one week, draws on 500+ directors, is available from £1,795/month and has no long-term tie-ins.
Frequently asked questions
Are fractional CISO UK day rates cheaper than hiring a full-time CISO?
They can be lower in total when the business needs senior leadership for a few days each month rather than five days a week. Compare salary, employer costs, benefits, recruitment, notice periods and unused capacity. Fractional work is not automatically cheaper for an intensive, full-time crisis or transformation assignment.
What is the difference between a fractional CISO and a vCISO?
The terms are often used for similar part-time security leadership. “Fractional CISO” usually emphasises a named executive working with the leadership team, while “vCISO” can also describe a remote or broader provider model. Check who is accountable, how much time is reserved and whether the same person attends board and incident discussions.
How many days a month does an SME usually need?
Many SMEs can begin with two to six days a month, depending on their starting position and objectives. A baseline or customer assurance pack may need a concentrated first month; ongoing oversight may then settle at one or two days. Measure progress against agreed outcomes, not attendance.
Should a fractional CISO also carry out penetration testing?
Usually the CISO should define the requirement, select or oversee an independent tester, interpret findings and make sure remediation is owned. Independent testing gives the board confidence and avoids asking one person to mark their own work. The CISO can still coordinate the technical response and verify evidence.
Can a fractional CISO help during a cyber incident?
Yes, if responsibilities and availability are agreed beforehand. They can establish decision rights, coordinate technical and legal specialists, brief the board, manage communications and lead lessons learned. A live incident may require a separate surge or on-call arrangement, so normal monthly days should not be assumed to provide unlimited emergency cover.
Ready to find your fractional CISO?
Leadership Services can introduce a fractional CISO who starts within one week, backed by 500+ directors, from £1,795/month, with a same-working-day response and no long-term tie-ins. Tell us the risk, deadline or board decision you need help with and we will outline the right level of support.