Hiring your first CISO: when to hire, which profile and how to assess
Hire a first CISO when security starts deciding deals, funding or regulatory exposure, not when an audit date appears in the diary. The right profile follows from the problem: a builder where no security programme exists, a compliance-led leader where regulated buyers set the agenda, or a fractional CISO while the scope is still small. This guide covers the triggers, the rules that matter, reporting-line trade-offs and an assessment built around a realistic incident.
On this page
- Signals that security by committee has run its course
- Rules that move cyber accountability onto the leadership agenda
- Builder, compliance-led or fractional: matching the profile to the problem
- Where a first CISO reports, and what each line gives up
- From problem-based brief to signed offer
- A hypothetical software company meets its first bank customer
- Priorities to settle with the new CISO for the opening months
- Questions and answers
- Sources
Signals that security by committee has run its course
Most companies arrive at their first CISO hire through a sales conversation rather than a breach. A bank or a government department sends a long security questionnaire, a senior engineer answers it in the evenings, and the buyer then asks for the name of the executive accountable for security. When the honest answer is "the CTO, part-time", deals start to slow.
Other signals tend to arrive together. Investors ask in diligence who reports security risk to the board. A customer contract requires incident notification within a fixed window, and nobody owns the clock. Engineering leaders spend more of their week on policies, supplier reviews and audit evidence than on product. An incident, even a minor one, was handled by whoever happened to be online.
One signal alone can usually be absorbed. When security questions shape revenue, funding and legal exposure at once, the company needs a named leader who owns them.
Rules that move cyber accountability onto the leadership agenda
Two regimes come up most often in first-CISO conversations. Check with counsel whether either applies to you.
Directive (EU) 2022/2555 (NIS2 Directive), Article 20 and Article 21
European Union, as transposed into each member state's lawApplies whenThe company is an essential or important entity under the Directive, which depends on its sector and size, or it supplies services to such entities that pass the requirements down by contract1.
SEC final rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure
United States: companies reporting to the Securities and Exchange CommissionApplies whenThe company files periodic reports with the SEC, including foreign private issuers through their own forms2.
- The annual report must describe board oversight of cybersecurity risk and management's role and relevant expertise in assessing and managing it, under Regulation S-K Item 1063.
- A material cybersecurity incident must generally be disclosed on Form 8-K Item 1.05 within four business days of determining that it is material2.
Builder, compliance-led or fractional: matching the profile to the problem
The profile decision matters more than the title. Each of these is a legitimate first CISO for a different company.
- If
There is no security programme to speak of: no asset inventory, no access reviews, no incident plan, and the product is growing quickly.
ThenHire a builder: someone who has set up a programme from nothing inside an engineering-led company and is comfortable writing code-adjacent controls.
A builder creates the controls that later audits will test; a compliance specialist without engineering depth tends to document gaps rather than close them.
- If
Controls exist, but regulated buyers, auditors and contract negotiations now dominate the security workload.
ThenHire a compliance-led CISO with experience of SOC 2 or ISO/IEC 27001 programmes, supplier assurance and customer-facing security conversations.
The constraint is translating engineering reality into evidence buyers accept, and that is a different skill from building the controls.
- If
The company is small, the regulated exposure is narrow, and the main need is credible answers to questionnaires plus a roadmap.
ThenEngage a fractional or virtual CISO for a defined number of days, with a named internal owner for day-to-day controls.
A full-time executive with little to lead tends to leave; a fractional arrangement buys judgement now and a clearer brief for the permanent hire later.
Where a first CISO reports, and what each line gives up
| Reporting line | What it does well | Where it strains | Fits when |
|---|---|---|---|
| Chief executive | Signals that security is a business risk; gives direct access to commercial decisions | Chief executives rarely have time for regular operational detail | Security is a buying criterion for most customers |
| CTO or VP Engineering | Close to the systems; controls get built into the product quickly | Conflicts arise when security slows delivery and the same person owns both | The early work is mostly engineering and the CTO welcomes challenge |
| CIO or head of IT | Natural fit for corporate systems, identity and endpoint controls | Product and customer-data security can drift out of view | The main exposure sits in internal systems rather than the product |
| General Counsel or COO | Independence from engineering; strong link to contracts and regulators | Distance from engineering can turn security into paperwork | Regulatory and contractual exposure outweighs technical build work |
Whatever the line, give the CISO a direct route to the board or its audit or risk committee.
From problem-based brief to signed offer
Write the brief around problems, not certifications
List the problems the hire must solve in their first year, such as answering bank questionnaires without engineering time, building an incident plan the board has rehearsed, or preparing for a first ISO/IEC 27001 audit. Capabilities and the profile follow from that list. Certifications become a tiebreaker, not a filter.
Agree the panel and the scoring
Include the executive the CISO will report to, an engineering leader who will live with the controls and, ideally, a non-executive director. Fix structured questions and anchored scores before anyone meets a candidate.
Run the structured interview
Ask about past decisions, not hypotheticals: a programme they built, a control they chose not to implement, a time they told a board something unwelcome. Press until the candidate's own part is clear.
Set the incident-timeline work sample
Give shortlisted candidates a fictional but realistic incident timeline, then ask them to walk through their decisions and draft the board update it requires. Look for how they separate facts from assumptions, when they would notify customers or authorities, and whether the board note is short and decision-ready.
Reference with managers, peers and the team
Ask former managers how the candidate handled disagreement with engineering, ask peers whether controls were adopted or worked around, and ask people they led whether they grew. Referees identified independently, with the candidate's consent, add the most.
Agree priorities before the offer
Settle the opening-month priorities, budget authority and reporting route in writing with the preferred candidate. Disagreement here is cheaper to discover before signature than after.
A hypothetical software company meets its first bank customer
Priorities to settle with the new CISO for the opening months
Agree these in the onboarding plan so that the board and the CISO judge progress against the same list.
Questions and answers
Does a company need a CISO before a SOC 2 or ISO 27001 audit?
Not necessarily. Auditors look for an operating set of controls, assigned responsibilities and evidence over time, not for a particular job title. Many companies reach a first audit with a fractional CISO or a security lead inside engineering. The case for a full-time CISO is stronger when audits, customer assurance and incident readiness together outgrow what a part-time owner can carry.
Should the first CISO also run IT?
It can work in a small company where corporate IT is modest, but it creates a conflict: the person setting security requirements also decides whether IT meets them. If you combine the roles, give an audit or risk committee a direct view of security risk, and plan to separate them as regulated customers start asking who checks the checker.
Will enterprise buyers accept a fractional or virtual CISO?
Many will, provided the arrangement is real: a named person, a defined time commitment, authority over policy and incident decisions, and an internal owner for daily controls. Buyers become uneasy when a fractional CISO cannot answer questions about the company's own systems or is unreachable during an incident, so write availability and incident duties into the contract.
How much weight should certifications carry when shortlisting CISO candidates?
Treat certifications as evidence of a baseline, not as proof of fit. Two candidates with identical credentials can differ sharply in whether they have built a programme, faced a regulator or briefed a board during a live incident. Shortlist on the problems in the brief, then use certifications to separate otherwise similar candidates or where a buyer contract names a specific qualification.
Sources
- Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) — EUR-Lex · checked 10 October 2026
- SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies — U.S. Securities and Exchange Commission · checked 10 October 2026
- Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, Final Rule (Release No. 33-11216) — U.S. Securities and Exchange Commission · checked 10 October 2026