The governance question behind the appointment
Fractional CISO leadership is an ongoing, part-time relationship in which one person holds the security agenda and answers for the outcomes the engagement defines. The holder owns the roadmap, sets control priorities, and reports to the board on the risk position. Within that mandate the responsibility matches what a permanent appointment carries, though a permanent CISO typically holds more besides, including line management, budget authority and daily operational duties.
That mandate has limits. The board's own accountability for cybersecurity oversight does not transfer, and permanent management remains accountable for the operations it runs. The engagement places senior judgement inside the governance structure without displacing anyone else's duties.
A permanent appointment assumes the requirement is ongoing, full-time and proportionate to a C-suite cost. Where the requirement is continuing but needs less than full-time capacity, a fractional engagement is the proportionate structure. Where it has a defined end, the organisation is looking at a different model altogether.
When ongoing fractional leadership is the right structure
The question is whether the requirement is continuing, and whether the organisation can execute without a permanent appointment.
- Continuity of the security agenda
- The organisation needs someone who owns the security agenda between board meetings, carries it forward across quarters, and holds the relationships that make it move. A requirement that ends when a piece of work ends is not this.
- Scale and proportionality
- The volume, complexity and pace of security decisions can be governed through a defined part-time allocation. Fractional leadership provides senior capability proportionate to the organisation's risk profile and operating requirement.
- Internal execution capability
- Fractional leadership sets direction and carries accountability for agreed outcomes. Delivering against that direction depends on capacity the organisation can call on.
Where the model does not fit
Fractional leadership depends on conditions the organisation controls. Building a security function from a low base is a legitimate mandate, provided delivery capacity exists alongside it, whether internal, external or a combination. The model breaks where the organisation has no delivery capacity and expects a part-time allocation to supply both leadership and execution. Where the organisation is large enough that security decisions arise daily, the availability a fractional arrangement provides becomes the constraint.
Two other cases are worth naming. An organisation using a fractional appointment to satisfy a customer or regulator on paper, without granting real authority, has bought a title. And where a permanent CISO is already in post, the requirement is usually specific support on a defined question, which is advisory work under its own terms.
What the engagement must define before it begins
Five things should be settled before the engagement starts.
- Scope and decision rights
- What the fractional CISO owns, which decisions the role is authorised to approve, which sit with permanent management, and which go to the board. An engagement that leaves this undefined places accountability imprecisely.
- Capacity
- The contracted time, expressed in days and in what those days are expected to cover. Capacity set below what the agenda requires produces a title without the means to exercise it.
- Executive access and escalation
- Direct access to the chief executive and a defined route to the board, with an agreed threshold for what gets escalated between reporting cycles. The access should match what a permanent appointment would carry.
- Periodic review
- A point at which both sides test whether the arrangement still fits, whether the conditions that justified it still hold, and whether the scope or capacity needs to change.
- Exit and handover
- How the engagement ends and what it leaves behind. Whether the conclusion is a permanent appointment, a reduced ongoing engagement or a transfer to internal ownership, the handover should be specified at the outset.