Your First Security Leader Shouldn't Be a Full-Time Hire

A full-time CISO is a $300K+ bet on a fifteen-hour workload. The fractional math on security leadership, and when the full-time hire genuinely wins.

Illustration of a full solid circle beside a circle with one quarter wedge lit in sunset gradient, representing fractional leadership

The moment arrives predictably: a big customer demands security leadership, the insurer's questionnaire needs an owner, or the board wants someone accountable for cyber risk. The reflex is to open a requisition. For most growing companies, that reflex is expensive and premature — not because security leadership doesn't matter, but because the full-time version of the role is mis-sized for the actual workload. This is the same logic as the fractional AI officer argument, applied to the security seat — and the math is even more lopsided.

What the full-time hire really costs

An experienced CISO commands $200K–$300K+ in base salary, and fully loaded — benefits, bonus, equity, recruiting — the first year runs well past $300K. Then the structural costs arrive: a CISO without a team is a general without an army, so the hire begets hires; the market for security executives is brutally competitive, so retention risk is constant; and if the fit is wrong, you've spent a year and a severance discovering it. For a 100–500 person company, that's a half-million-dollar bet on a role whose actual weekly workload is often fifteen focused hours.

What the workload actually is

Be honest about the calendar. Strategy and roadmap: intensive at first, then quarterly. Board reporting: quarterly. Insurance renewal: annual, with a runway. Customer questionnaires: episodic. Policy reviews: scheduled. Incident leadership: rare and unscheduled. Vendor evaluations: as needed. This is a seniority-heavy, hours-light role — exactly the shape fractional models exist for. What fills a full-time CISO's remaining hours at most growing companies is work that operational staff or a managed partner should be doing anyway — at a fraction of executive cost.

The fractional structure

A vCISO retainer buys the decision-making layer — the strategy, the reporting, the external face, the incident command — at a defined monthly fee, typically a fifth to a third of the loaded full-time cost. Crucially, the accountability is real: named deliverables, board slides with the vCISO's name on them, written liability boundaries in the agreement. And because our seat comes attached to the team that runs the controls daily, there's no gap between the person who decides and the people who execute — the failure mode of standalone advisory CISOs who recommend into a void.

When the full-time hire is right

Honesty section, as always. Hire full-time when you're past roughly 750–1,000 employees and security leadership is genuinely a daily job; when your regulatory regime demands a dedicated named officer; when security is the product you sell; or when you've run a fractional seat for a couple of years and the workload has visibly outgrown it — at which point you'll write a far better job description, because you'll be hiring from experience instead of anxiety. The fractional seat isn't a permanent dodge; it's the right-sized bridge, and sometimes the permanent answer.

Run your own math

Estimate the honest weekly hours of executive-level security work at your company. Price the full-time hire against a fixed retainer for those hours plus the operational floor. Then ask which failure is worse: paying an executive salary for a part-time workload, or lacking the seat entirely when the questionnaire, the renewal, or the incident arrives. Book a conversation and we'll run it with your numbers — including telling you if you're the full-time case.