The trigger is rarely strategic. A security questionnaire from a major customer sits in the inbox, a framework agreement passes ISG duties on to you, or somebody on the board asks who actually leads information security. In many SMEs the honest answer is: nobody really. So the search for an external CISO begins. And that is where it gets murky. Under the same term, consultancies sell projects, managed service providers sell tool bundles with a CISO thrown in, platforms sell standardised programmes and individuals sell day rates. Everything has the same name, almost nothing is comparable. In this article we sort the models and show how to tell in a selection call who is selling you security leadership and who is selling a different product.
External CISO is an umbrella term for at least five models, from the interim manager to the vCISO platform. More important than the model is whether somebody takes accountability for delivery and how they make their money. Anyone who earns on tools or managed services will rarely recommend switching something off. Which is exactly what would be the most effective first step in many SMEs.
Which models hide behind the term external CISO?
Behind the term external CISO sit essentially five models: the interim CISO (full-time for a period), the fractional CISO (recurring part-time mandate with delivery accountability), vCISO platforms (standardised programmes, mostly remote), security consulting with a CISO label (recommends but does not deliver), and managed service providers who run a vCISO as a side dish to the tool package. Providers mix these terms at will, so it pays to look at what you get for your money.
The interim CISO fills a vacancy or leads through a crisis: full-time, fixed term, on day rates. That is a sensible instrument for organisations that have a CISO position and cannot fill it temporarily. In an SME with 150 employees that position usually never existed, so the model rarely fits.
The fractional CISO works for you on a recurring basis, typically one to four days per week, and carries the accountability on the mandate that agreed measures actually get implemented. They sit in the steering meeting, report to management and the board, and help answer customer questionnaires. The difference from all other models is continuity: after six months the same person knows your systems, your customers and your conflicts. That knowledge makes security decisions faster and cheaper. What the role covers in detail is described in our primer on what a fractional CISO is.
vCISO platforms deliver questionnaires, policy templates and a dashboard, plus a human by the hour. That scales superbly for the provider. Whether it works for you depends on whether your problem is a template problem. It sometimes gets you through a customer questionnaire. A management team that wants to know which risks the business carries gets no answer out of a dashboard.
Security consulting delivers clean analyses and recommendations, project by project. After that the delivery is yours again. That is not a flaw in consulting, it is their business model. It only becomes a problem when you were actually looking for someone who stays.
Finally, the vCISO from a managed service provider arrives as part of a package of SOC, monitoring and licences. The monthly price often looks attractive. How the provider makes money is on page two of the quote.
When is which model worth it?
The short answer: interim for a vacancy or a crisis, consulting for bounded individual questions, a platform when you have to pass exactly one questionnaire, a fractional CISO for ongoing security leadership in an SME between 50 and 500 employees. Anyone who already has a good IT or security lead often needs no full mandate, but a second opinion in a sparring arrangement.
Let us be honest: not every SME needs an external CISO. Below around 50 employees, solid basic hygiene and an annual check are often enough. Above a certain size and regulatory density the role belongs filled internally. In between lies the range where a full-time position is too expensive but "the IT lead does it on the side" no longer holds: at the latest when customers demand evidence or the board wants answers.
One detail is easily overlooked when choosing a model: the time horizon of the trigger. The customer questionnaire on the table today comes back next year, then from the next customer, then from the cyber insurer. The ISG requirements a major customer passes on by contract do not disappear after the audit. Answering a recurring trigger with a one-off project means buying the same analysis again in two years, only with a new logo on the cover.
So the model question is answered quickly. The harder question comes afterwards, when choosing the provider. And there, something other than the label decides.
The most important selection question is not the model, it is the incentive system. Anyone who earns on the sale of tools, licences or managed services will rarely recommend switching something off. An independent CISO earns on judgement, not on the licence. That is why they can say out loud what is overdue in many grown security landscapes: more protection, fewer tools, lower cost.
How to recognise good providers in a selection call
In our experience six questions say more about a provider than any price list:
- Who sits at the table later? The partner comes to the sales call, the junior comes to the mandate. Ask for the name of the person who will lead your mandate, and speak to them before you sign.
- Do you take accountability for delivery? Plenty of people write recommendations. Ask who stands behind the measures in the report being implemented in six months, and how you will measure that together.
- What else do you earn on? Commissions from tool vendors, reselling, your own managed services. None of that is forbidden. You just need to know whether your future CISO judges neutrally or fills a pipeline.
- What would you switch off at our company? The most revealing question in the whole conversation. A provider who only wants to add new purchases has your budget in view, not your risk.
- What does your reporting to management and the board look like? Ask for an anonymised example. Four clear pages is a good sign. A slide deck with traffic lights on every page is not.
- Who do you work with in our size class? Large-corporate experience is nice, but it helps you little when the methods are built for an organisation with its own legal department and its own SOC.
Add a look at the contract. A minimum term of six months is reasonable, because security leadership needs a run-up before it shows effect. Multi-year commitments you do not need, and a provider convinced of their own effect does not need them either. And settle before signing how availability during an incident is arranged. The moment you check that for the first time should not be an emergency.
An example from practice
A Swiss industrial supplier, around 160 employees, received a security questionnaire from its largest customer and discovered that nobody in the house could give the answers. In the end three quotes were on the table: a consultancy with a gap analysis and a recommendation report, a managed service provider with a vCISO in the package, and a fractional mandate. Asked what they would switch off, the consultancy answered "the analysis will show that". The provider answered with a list of additional modules. In the third conversation a counter-question came instead: which systems already exist twice today. After that the management team stopped discussing the price and started discussing the start date. The customer's questionnaire was answered a few weeks later, with evidence instead of statements of intent. And two of the duplicated systems are no longer running today.
What does an external CISO cost in Switzerland?
A full-time CISO in Switzerland costs between CHF 150'000 and 250'000 per year, plus social contributions and several months of recruiting (salary data from jobs.ch). A fractional mandate sits considerably below that: our CISO retainer starts from CHF 4'900 per month, the sparring model with two days per month from CHF 2'400. Interim managers bill full-time day rates, platforms look cheap but price templates rather than leadership. The details are in the overview of fixed-price packages, the full cost calculation in the article on what a CISO costs in Switzerland.
More important than the absolute number is the other side of the calculation. A good external CISO starts with a stocktake of what is already there. When duplicate licences and unused modules fall away in the first six months, that finances part of the mandate. In our experience that is the normal case, because in grown environments many hands have bought over the years and nobody had the whole picture.
Frequently asked questions
Can we outsource responsibility for information security entirely?
No. Overall responsibility stays with the management team and the board, and no mandate changes that. An external CISO takes over the operational leadership: making sure risks are known, decisions are properly prepared and delivery happens. In doing so they also document the due care expected from management. In the end you have to decide.
Is it not enough to appoint our IT lead as CISO?
On paper that is quick, in practice a conflict of interest appears: whoever is accountable for operations should not also be checking themselves. Capacity comes on top. An IT lead with a full day job prioritises availability, not security work, and from their point of view that is rational. The combination of an internal IT lead and an external CISO as their counterpart therefore works better in many SMEs than any dual role.
How quickly do you notice whether the choice was right?
Early. After around 90 days you should see three things: a risk register phrased in the language of the business, first measures implemented rather than only planned, and reporting that management and the board understand without translation. If after a quarter it is still documents and statements of intent, you bought a consultancy, not a CISO.
If quotes are on your table right now and you are unsure which model fits your situation: the switch-it-off question can be put to every provider. Including us.
