Home · Blog
Basics

What does a CISO cost in Switzerland? The honest calculation

August 19, 2026 · 8 min read · ODCUS
A leader compares a tall stack of salary coins for a full-time position with a compact block of a few mandate days on a balance scale, as an image for the honest CISO cost calculation

A customer sends a security questionnaire, the insurer wants to see an accountable person, the board asks for a report. At some point the question is on the table: what does a CISO cost? The quick answer: as a permanent hire in Switzerland, CHF 150'000 to 250'000 per year, plus on-costs. The more honest answer: the salary band is the smallest part of the calculation. An SME with 50 to 500 employees rarely needs a full-time position, and a badly sized solution costs more than any salary.

TLDR

A full-time CISO in Switzerland costs CHF 150'000 to 250'000 per year, plus social contributions and recruiting. But an SME with 50 to 500 employees rarely has five days of security leadership per week to fill. A fractional CISO carries the same accountability with 1 to 4 days per week, from CHF 4'900 per month. The most expensive option is the badly sized one.

What does a full-time CISO cost in Switzerland?

The salary band for a Chief Information Security Officer in Switzerland sits between CHF 150'000 and 250'000 per year, depending on sector, region and experience (salary data from jobs.ch). On top come social contributions, recruiting cost and, in our experience, several months of searching until the right person is found.

But the salary band is only half the calculation. The other half is a question asked in almost no budget discussion: what does this person do all week?

Security leadership in an SME comes in waves. A customer audit, an incident, building an ISMS: then there is plenty to do. In between, the work consists of steering, reporting and maintenance, and with 100 or 200 employees that does not fill five days a week. An experienced CISO notices this within a few months. Either they leave again, and recruiting starts over. Or they keep themselves busy, and that gets genuinely expensive: new tools and new projects nobody ordered. The alternative of hiring someone cheaper does not solve it either. Then the company has a security administrator with a CISO title, but nobody who talks to the management team and the board about risk as an equal.

When does a fractional CISO beat a permanent hire?

As soon as security leadership fills less than a full-time position. In SMEs with 50 to 500 employees that is the normal case. A fractional CISO takes on the same accountability on a mandate, with 1 to 4 days per week. The CISO retainer starts at CHF 4'900 per month, so CHF 58'800 per year, and is ready to go within two weeks instead of after months of recruiting.

The four usual models differ less in the day rate than in what you are paying for:

ModelCost per yearWhat you pay for
Permanent hireCHF 150'000 to 250'000 plus on-costsFull presence, including the quiet weeks
Interim CISODay rates on a full-time basisBridging a vacancy or a crisis
Security consultingTime and materialsRecommendations, delivery stays with you
Fractional CISOFrom CHF 58'800, fixed priceAccountability and delivery, sized to the need

The difference from consulting is the most important one: a consultant recommends and leaves, the accountability stays with you. A fractional CISO carries it on the mandate itself, towards the management team, the board and auditors. What the role covers in detail is described in our article on what a fractional CISO is.

In fairness: above a certain size the calculation flips. A company heading towards a thousand employees, running several sites and under dense regulation, fills a full-time position and is better served by a permanent hire. A mandate does not replace a security department, it replaces the full-time position an SME never needed.

For companies that already have an IT or security lead there is the smaller variant: CISO sparring, two days per month from CHF 2'400, as a second opinion and to prepare management and board sessions. Not an embedded mandate, but a senior alongside the person who is internally accountable.

What the need depends on

Whether a company needs one day of security leadership per week or four is decided by four factors, and none of them is headcount alone.

Regulation. Anyone supervised by FINMA, subject to the ISG, or contractually pulled in as a supplier to critical infrastructure needs a regular rhythm of reporting, evidence and risk management. Without such requirements a far leaner programme is often enough.

Customer landscape. An SME with three major customers who all audit annually has more ongoing security work than one with a hundred small customers who barely ever ask. Questionnaires, audits and contract clauses are in practice the most common driver, not the threat landscape.

Maturity. An ISMS under construction eats more capacity than one in maintenance. That is why many mandates start with more days and get leaner after the first year.

Internal IT. A strong IT lead needs method and backing, not a second pair of operational hands. A stretched two-person IT team needs someone who also rolls up their sleeves.

And this need is not static. A mandate can be scaled from one day to three when the audit is due, and back down afterwards. A permanent hire cannot do that, it costs the same in the quiet phase as in audit season.

The costs that appear in no salary band

In the budget discussions we see, people argue about the salary band and stay silent about three items that are usually larger.

The vacancy. Months pass between the decision to look for a CISO and the first day at work. During that time customer questionnaires stay unanswered, tenders run without solid answers about the security organisation, and the board still gets no report. In many tenders the security organisation helps decide whether the order arrives. So the vacancy costs revenue long before the first salary is paid.

Paying twice. Companies that commission classic consulting instead of hiring get a clean analysis with a list of measures. Little of it gets implemented, because nobody in the house has the time and the standing for it. Two years later the next consultancy arrives and analyses the same thing again. You pay twice, little has changed.

Tool sprawl. Without security leadership every new problem is answered by a new tool, each with its own licence and its own portal. In our experience licence costs fall in most mandates while coverage rises, because we tidy up first and invest after. How that works in practice is in the article on consolidating security tools.

Most companies do not have a security problem, they have a sizing problem: too many tools, too little overview, too much cost for too little real protection. So before the salary band comes a different question: how much security leadership does your company need? More protection. Fewer tools. Lower cost.

What this looks like in practice

An example, condensed from situations we meet again and again in mandates, details altered: a Swiss industrial company with around 150 employees. The trigger was a major customer announcing a supplier audit and sending a security questionnaire beforehand. The IT lead could answer the technical questions, but nobody could say who is accountable for information security, which risks are consciously accepted, and what the plan for the next twelve months is.

The management team's first reflex was a job advert. After several months without suitable candidates it became a mandate. In the first quarter nothing spectacular happened: stocktake, risk register, the questionnaire was answered, the audit supported. Along the way it turned out that two security tools had been double-licensed since the last M365 extension and that nobody had looked at a third one for a year. The major customer's contract stayed in the house, because for the first time there was someone who could explain and represent the security organisation.

That is the part of the calculation a pure salary discussion does not capture: a CISO does not only cost, the role prevents cost and secures revenue. But only when the capacity fits the size of the company.

Which costs come at you on a mandate?

The packages are fixed prices, so the budget discussion happens once and not every month: the Cyber Assessment costs CHF 1'900 once and is fully credited against a follow-on mandate. The CISO retainer starts at CHF 4'900 per month with a six-month minimum term, cancellable monthly after that. CISO sparring is available from CHF 2'400 per month for two days, the ISMS build as a 90-day programme at a fixed price after scoping. All details are on the overview of packages and pricing.

This belongs in the calculation too: a mandate does not replace your team's implementation time. When measures are due, hours from internal IT are needed, and individual purchases can still be necessary despite consolidation. A serious mandate makes those efforts visible before they occur, instead of hiding them in on-costs.

Whether this calculation pays off for your company depends on the starting point: compliance pressure, customer requirements, the state of today's security landscape. So the question of what a CISO costs can only be answered seriously once it is clear how much CISO is needed at all. That is exactly what the intro call is for.

Frequently asked questions

What does it cost to have no CISO?

Usually nothing visible, until it becomes visible: a customer questionnaire that delays a tender, an audit with no counterpart, an incident where nobody decides. These costs appear in no budget, they show up as lost orders and hectic weeks. If you want to put a number on them, look at your own open customer requests about security.

Why a fixed price instead of an hourly rate?

Because an hourly rate sets the wrong incentive: the longer the problem lives, the more gets billed. A fixed price forces us to estimate the effort realistically up front, and gives you a predictable annual budget you can defend to the management team and the board.

Is sparring enough instead of a full retainer?

If somebody internally carries the security work, yes. Sparring delivers a second opinion, method and preparation for management and board sessions, delivery stays with your IT lead. As soon as nobody internally can or wants to carry the accountability, the retainer is the better fit.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call