CISO Leadership · 7 min

Interim CISO, fractional CISO or permanent hire: which model fits?

Effective CISO support depends on the mandate. Urgency, leadership need, decision rights and the intended outcome determine the right model.

Start with the situation, not the title

A CISO vacancy, a stalled transformation and occasional executive advice can all look like a lack of security direction. Organisationally, they require different responses. The decision therefore starts with the trigger, time pressure, internal capacity and the leadership accountability that is genuinely required.

A title alone does not create control. An engagement becomes effective when management access, information rights, reporting lines, escalation and the intended outcome fit together.

  • How quickly must dependable leadership be established?
  • Who currently holds risk, budget and people decisions?
  • Is the objective to bridge a vacancy, stabilise a programme or build a permanent function?

Distinguish interim, fractional and advisory support

An Interim CISO provides time-bound security leadership during a critical phase and works towards a defined handover. A Fractional CISO establishes recurring governance within an agreed part-time scope. CISO Advisory provides executive challenge, decision support and quality assurance without assuming internal line accountability.

  • Interim: high urgency, a clear leadership gap and time-bound accountability.
  • Fractional: continuous steering within a limited and predictable scope.
  • Advisory: independent perspective where internal accountability already exists.

Define decision rights and reporting lines

The mandate should state which decisions are prepared, which actions are steered and which approvals remain solely with the authorised governing bodies. A CISO title without access to relevant information and decision-makers creates false assurance; vague delegation creates delivery and accountability risk.

A concise engagement charter should cover scope, decision boundaries, reporting recipients, escalation criteria and interfaces with IT, OT, privacy, compliance and internal audit.

Agree outcomes and handover from the outset

Time-bound leadership should be measured through usable outcomes rather than presence. Typical outputs include an executive risk brief, prioritised backlog, workable governance model and dependable reporting cadence.

Handover does not begin on the final day. Roles, open risks, decision logic, active actions and key stakeholders must be documented so the permanent organisation can continue without losing momentum.

Use transparent selection criteria

The right model follows from a transparent comparison. Hybrid arrangements can work, provided that responsibilities remain contractually and operationally clear. The model may evolve, but changes should be tied to explicit decision points.

  • Urgency and required decision speed
  • Extent of leadership and delivery accountability
  • Availability of a permanent internal role and target handover date
  • Complexity across entities, sites, IT/OT and regulatory obligations
  • Expected outcomes rather than capacity alone

Service boundary

Support may include advisory services, engagement design and explicitly agreed time-bound security leadership. Statutory duties, risk acceptance and final corporate decisions remain with the client’s authorised governing bodies.

Primary sources and further reading

Related executive perspectives

Continue with the next decision.

Two related perspectives connect this question to the wider leadership and delivery model.

From perspective to decision

What does this mean for your organisation?

A first conversation frames scope, urgency and the next sensible step.

Discuss your situation