The conversation usually starts the same way. A founder or CTO has just been told, by a customer, an investor or an incident, that "someone needs to own security." The first instinct is to open a job req for a CISO. The second, a few weeks into the search, is to wonder whether a fractional CISO would do. Both instincts are reasonable. Neither is right for every company, and the wrong choice costs either a year of runway or a year of exposure.
The honest cost comparison
A full-time CISO at a venture-backed company typically lands somewhere in the $350–450K range in cash compensation before equity, and the good ones have options. The search commonly runs three to five months, and there's a ramp on the other side before the program moves. Call it six to nine months and half a million dollars before you see results, and then that cost repeats every year.
A fractional CISO costs a fraction of that, starts in weeks, and is already ramped on the frameworks. That's the pitch and it's true. What the pitch leaves out: a fractional CISO has other clients, isn't in your building every day, and has less organisational authority than an executive on your org chart. Those are real limits. Whether they matter depends entirely on what you actually need done.
Five signals you need security leadership now
These say "get someone," not "get a full-timer." Either model can answer them.
- Enterprise deals are stuck in security review. A questionnaire sat for three weeks. Procurement asked for a SOC 2 report you don't have.
- There's an audit date on the calendar. SOC 2, ISO 27001, FedRAMP, and nobody in-house has run one.
- Investors or the board are asking. Series B diligence includes security posture now, and "the CTO handles it" is no longer an answer.
- AI is in production. LLM features, agents, and a buyer asking about ISO 42001 or prompt-injection testing.
- You had a scare. A leaked key, a phishing hit, an ex-employee with access they shouldn't have had. Nothing catastrophic. Yet.
The framework: four questions
Answer these honestly and the decision mostly makes itself.
1. How many senior security hours does the work actually need each week?
List the work for the next twelve months: compliance program, questionnaires, vendor risk, architecture reviews, policies, board reporting, incident planning, AI governance. Estimate hours. At most companies under 300 people the honest number is 10 to 20 senior hours a week. That is a fractional engagement. A full-time hire either gets bored or expands scope to fill 40 hours, and expanded scope is how you end up with a security team of six before you have a security problem that needs six.
2. Is there a team to lead?
A CISO's job title has "chief" in it because they lead a function. If you have no security engineers, there is nothing to be chief of; you need an operator who will do the work and set the direction. That's fractional or embedded. If you have a security team of four or more with its own roadmap, hiring pipeline and on-call, they need a full-time leader who's in the room every day.
3. What do your board and customers need to see?
Most enterprise buyers and most boards need a name and a program: someone accountable, a roadmap, evidence that controls run. A fractional CISO satisfies that fully, and some boards prefer it because the reporting is crisper. Some contexts want more. FedRAMP and certain defence and financial-services procurements expect a named, dedicated security officer with real authority over the environment. If that's your market, plan for a full-time hire, even if fractional gets you through the first authorisation.
4. Where will you be in eighteen months?
If the answer is "Series C, 300-plus people, a security team, regulated customers," a full-time CISO is coming. The question is just sequencing. Hiring one today, before the team and the problems exist, means paying an executive to do a senior engineer's work for a year. Bringing in a fractional CISO now, building the program, then hiring full-time when there's a function to lead is usually cheaper and produces a better hire, because the fractional CISO can help you write the job description and run the loop.
Where fractional breaks
I'd rather you hear this from me than discover it in month three.
- 24/7 operations. If you need eyes on glass around the clock, you need a managed detection provider and eventually an in-house team. A fractional CISO can select and manage the provider; they cannot be the provider.
- Sustained incident command. A fractional CISO will lead an incident. A three-week breach response with regulators, counsel and customers on the line needs someone who has no other clients that month.
- Deep organisational politics. Changing how five engineering teams ship code is a full-time relationship-building job. Fractional works when leadership is aligned and wants to move; it struggles when the real work is persuading people who don't.
- A security team larger than a handful. People need a manager who's present. Fractional leadership of a real team burns out the team.
- A regulator or contract that names the role. If a document says "dedicated," believe it.
The hybrid most companies end up with
In practice, the companies that get this right rarely choose one model forever. The sequence looks like this:
- Fractional CISO now. Program built, first audit passed, questionnaires unblocked, board reporting in place. Twelve to eighteen months.
- First security hire is an engineer, not an executive. A strong security engineer or head of security who owns the day-to-day. The fractional CISO helps hire them and mentors them.
- Fractional scope shrinks to advisory. Monthly review, board prep, second opinion on the hard calls. The in-house lead runs the program.
- Full-time CISO when there's a function to lead. Usually somewhere past 250–300 people or on entering a regulated market. The fractional CISO writes the job description, sits on the panel, and hands over a program that already works.
That path costs less than hiring the executive first, and the executive you eventually hire inherits a working program instead of a blank page. The fractional engagement should be designed to end. If it isn't, ask why.
Questions to ask any fractional CISO before you sign
- Who actually does the work? You, or a bench you've never met? If there's a bench, who's accountable?
- How many clients do you have right now? There's a number above which "senior hours a week" becomes fiction. Ask for it.
- Which frameworks have you run as the vendor, not the auditor or advisor? Running SOC 2 or FedRAMP from the inside is a different skill from grading someone else's.
- What happens when we have an incident on a Saturday? Get the actual answer, not the reassuring one.
- How does this engagement end? A good answer includes a handover plan and a first-hire profile. A bad answer is a longer contract.
- Can I talk to a client whose audit you took through to the report?
One operator, four concurrent retainers, month to month. Guide, manage or execute depending on how much ownership you want to hand over. If your answers above point to a full-time hire, I'll tell you on the first call and help you write the req. See the three packages →
The bottom line
Hire a full-time CISO when there's a function to lead, a regulator or contract that demands it, or a threat model that needs someone with no other clients. Hire a fractional CISO when the work is 10 to 20 senior hours a week, there's no team yet, and you need the program built this quarter rather than next year. Most companies under 300 people are in the second group, and most of them will graduate to the first. Plan the graduation from day one.
Buy the hours the work needs, not the title the org chart wants.