GuideExecutive Recruitment

Hiring your first CISO: when to hire, which profile and how to assess

Hire a first CISO when security starts deciding deals, funding or regulatory exposure, not when an audit date appears in the diary. The right profile follows from the problem: a builder where no security programme exists, a compliance-led leader where regulated buyers set the agenda, or a fractional CISO while the scope is still small. This guide covers the triggers, the rules that matter, reporting-line trade-offs and an assessment built around a realistic incident.

Reviewed 8 min read

On this page
  1. Signals that security by committee has run its course
  2. Rules that move cyber accountability onto the leadership agenda
  3. Builder, compliance-led or fractional: matching the profile to the problem
  4. Where a first CISO reports, and what each line gives up
  5. From problem-based brief to signed offer
  6. A hypothetical software company meets its first bank customer
  7. Priorities to settle with the new CISO for the opening months
  8. Questions and answers
  9. Sources

Signals that security by committee has run its course

Most companies arrive at their first CISO hire through a sales conversation rather than a breach. A bank or a government department sends a long security questionnaire, a senior engineer answers it in the evenings, and the buyer then asks for the name of the executive accountable for security. When the honest answer is "the CTO, part-time", deals start to slow.

Other signals tend to arrive together. Investors ask in diligence who reports security risk to the board. A customer contract requires incident notification within a fixed window, and nobody owns the clock. Engineering leaders spend more of their week on policies, supplier reviews and audit evidence than on product. An incident, even a minor one, was handled by whoever happened to be online.

One signal alone can usually be absorbed. When security questions shape revenue, funding and legal exposure at once, the company needs a named leader who owns them.

Rules that move cyber accountability onto the leadership agenda

Two regimes come up most often in first-CISO conversations. Check with counsel whether either applies to you.

Directive (EU) 2022/2555 (NIS2 Directive), Article 20 and Article 21

European Union, as transposed into each member state's law

Applies whenThe company is an essential or important entity under the Directive, which depends on its sector and size, or it supplies services to such entities that pass the requirements down by contract1.

  • Management bodies must approve the cybersecurity risk-management measures, oversee their implementation and can be held liable for infringements1.
  • Measures must be appropriate and proportionate, taking into account current technology, relevant standards and cost1.

SEC final rule: Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure

United States: companies reporting to the Securities and Exchange Commission

Applies whenThe company files periodic reports with the SEC, including foreign private issuers through their own forms2.

  • The annual report must describe board oversight of cybersecurity risk and management's role and relevant expertise in assessing and managing it, under Regulation S-K Item 1063.
  • A material cybersecurity incident must generally be disclosed on Form 8-K Item 1.05 within four business days of determining that it is material2.

Builder, compliance-led or fractional: matching the profile to the problem

The profile decision matters more than the title. Each of these is a legitimate first CISO for a different company.

  • If

    There is no security programme to speak of: no asset inventory, no access reviews, no incident plan, and the product is growing quickly.

    Then

    Hire a builder: someone who has set up a programme from nothing inside an engineering-led company and is comfortable writing code-adjacent controls.

    A builder creates the controls that later audits will test; a compliance specialist without engineering depth tends to document gaps rather than close them.

  • If

    Controls exist, but regulated buyers, auditors and contract negotiations now dominate the security workload.

    Then

    Hire a compliance-led CISO with experience of SOC 2 or ISO/IEC 27001 programmes, supplier assurance and customer-facing security conversations.

    The constraint is translating engineering reality into evidence buyers accept, and that is a different skill from building the controls.

  • If

    The company is small, the regulated exposure is narrow, and the main need is credible answers to questionnaires plus a roadmap.

    Then

    Engage a fractional or virtual CISO for a defined number of days, with a named internal owner for day-to-day controls.

    A full-time executive with little to lead tends to leave; a fractional arrangement buys judgement now and a clearer brief for the permanent hire later.

Where a first CISO reports, and what each line gives up

Reporting lineWhat it does wellWhere it strainsFits when
Chief executiveSignals that security is a business risk; gives direct access to commercial decisionsChief executives rarely have time for regular operational detailSecurity is a buying criterion for most customers
CTO or VP EngineeringClose to the systems; controls get built into the product quicklyConflicts arise when security slows delivery and the same person owns bothThe early work is mostly engineering and the CTO welcomes challenge
CIO or head of ITNatural fit for corporate systems, identity and endpoint controlsProduct and customer-data security can drift out of viewThe main exposure sits in internal systems rather than the product
General Counsel or COOIndependence from engineering; strong link to contracts and regulatorsDistance from engineering can turn security into paperworkRegulatory and contractual exposure outweighs technical build work

Whatever the line, give the CISO a direct route to the board or its audit or risk committee.

From problem-based brief to signed offer

  1. Write the brief around problems, not certifications

    List the problems the hire must solve in their first year, such as answering bank questionnaires without engineering time, building an incident plan the board has rehearsed, or preparing for a first ISO/IEC 27001 audit. Capabilities and the profile follow from that list. Certifications become a tiebreaker, not a filter.

    Output
    Approved search brief
    Owner
    CEO and reporting executive
  2. Agree the panel and the scoring

    Include the executive the CISO will report to, an engineering leader who will live with the controls and, ideally, a non-executive director. Fix structured questions and anchored scores before anyone meets a candidate.

    Output
    Question set and rating anchors
    Owner
    Search lead with the panel
  3. Run the structured interview

    Ask about past decisions, not hypotheticals: a programme they built, a control they chose not to implement, a time they told a board something unwelcome. Press until the candidate's own part is clear.

    Output
    Independent scores per panel member
    Owner
    Interview panel
  4. Set the incident-timeline work sample

    Give shortlisted candidates a fictional but realistic incident timeline, then ask them to walk through their decisions and draft the board update it requires. Look for how they separate facts from assumptions, when they would notify customers or authorities, and whether the board note is short and decision-ready.

    Output
    Scored work sample
    Owner
    Panel with a technical reviewer
  5. Reference with managers, peers and the team

    Ask former managers how the candidate handled disagreement with engineering, ask peers whether controls were adopted or worked around, and ask people they led whether they grew. Referees identified independently, with the candidate's consent, add the most.

    Output
    Reference report
    Owner
    Search lead
  6. Agree priorities before the offer

    Settle the opening-month priorities, budget authority and reporting route in writing with the preferred candidate. Disagreement here is cheaper to discover before signature than after.

    Output
    Draft onboarding plan
    Owner
    Reporting executive and candidate

A hypothetical software company meets its first bank customer

Priorities to settle with the new CISO for the opening months

Agree these in the onboarding plan so that the board and the CISO judge progress against the same list.

0 of 5 checked

Questions and answers

Does a company need a CISO before a SOC 2 or ISO 27001 audit?

Not necessarily. Auditors look for an operating set of controls, assigned responsibilities and evidence over time, not for a particular job title. Many companies reach a first audit with a fractional CISO or a security lead inside engineering. The case for a full-time CISO is stronger when audits, customer assurance and incident readiness together outgrow what a part-time owner can carry.

Should the first CISO also run IT?

It can work in a small company where corporate IT is modest, but it creates a conflict: the person setting security requirements also decides whether IT meets them. If you combine the roles, give an audit or risk committee a direct view of security risk, and plan to separate them as regulated customers start asking who checks the checker.

Will enterprise buyers accept a fractional or virtual CISO?

Many will, provided the arrangement is real: a named person, a defined time commitment, authority over policy and incident decisions, and an internal owner for daily controls. Buyers become uneasy when a fractional CISO cannot answer questions about the company's own systems or is unreachable during an incident, so write availability and incident duties into the contract.

How much weight should certifications carry when shortlisting CISO candidates?

Treat certifications as evidence of a baseline, not as proof of fit. Two candidates with identical credentials can differ sharply in whether they have built a programme, faced a regulator or briefed a board during a live incident. Shortlist on the problems in the brief, then use certifications to separate otherwise similar candidates or where a buyer contract names a specific qualification.

Sources

  1. Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive) — EUR-Lex · checked 10 October 2026
  2. SEC Adopts Rules on Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure by Public Companies — U.S. Securities and Exchange Commission · checked 10 October 2026
  3. Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure, Final Rule (Release No. 33-11216) — U.S. Securities and Exchange Commission · checked 10 October 2026

More in Executive Recruitment

Back to Executive Recruitment

Next step

Send us the security questions your buyers keep asking

Share a recent questionnaire or the customer request that prompted this search. We will tell you which CISO profile it points to, or whether a fractional arrangement would serve you better for now.

Discuss a CISO search