In many SMEs, security is nobody's job. IT keeps the business running, the management team decides on budgets, and somewhere in between sit the questions nobody answers. Who checks whether our measures actually work? Who talks to the auditor? Who says no when yet another tool is about to be bought? That gap is what a fractional CISO fills.
A fractional CISO is an experienced security leader who takes on a company on a part-time mandate instead of as an employee. The role carries responsibility for the security programme, works embedded in the team, and reports to the management team and the board. For SMEs that cannot justify a full-time position but still need someone who wears the hat.
The market uses several terms for this: fractional CISO, vCISO (virtual CISO), CISO as a Service or external CISO. The emphasis differs, the idea is the same: security leadership on a mandate rather than as a permanent post. We use fractional CISO here because it captures the core best, a fraction of a real leadership role, ongoing and with accountability.
A fractional CISO runs a company's information security on a part-time mandate: security management and operations, governance, risk and compliance, ISMS implementation. The difference from consulting is accountability for delivery. For Swiss SMEs with 50 to 500 employees the model is often the right size, because a full-time CISO (CHF 150'000 to 250'000 per year) is too expensive and a pure adviser too non-committal.
What does a fractional CISO actually do?
A fractional CISO covers the same ground as a permanent security lead, only in the dose that fits the company. The work has three areas:
Security management and operations
Running the day-to-day of security. That means building and steering a roadmap from stocktake through quick wins to full operation, checking the existing security landscape for effectiveness, cutting duplicate licences, chairing a steering group, and building incident readiness for the day it matters. The focus is prioritisation: which topics count first.
Governance, risk and compliance
The overview of risks and obligations. A risk register with the top items, reporting the management team and the board can actually read, answering customer questionnaires and supplier audits, and making sense of regulation such as the Swiss Information Security Act, the revised Data Protection Act, or EU requirements like NIS2 and DORA that reach Swiss SMEs through supply chains.
ISMS and evidence
Building and maintaining a management system for information security, for example along ISO 27001. Scope, policies, asset and risk registers, awareness training, audit preparation. The goal is a lived ISMS that works in daily operations, not an 80-page binder nobody opens.
Fractional CISO, consultant or interim: what is the difference?
The key difference is accountability. A consultant recommends and leaves, an interim CISO steps in full-time to cover a vacancy or a crisis, and a fractional CISO stays on an ongoing part-time mandate and carries the delivery. The choice depends on size, urgency and duration.
| Model | Role | Typical for |
|---|---|---|
| Fractional CISO | Accountable for delivery, 1 to 4 days per week, ongoing | SMEs with 50 to 500 employees |
| Security consulting | Recommends, project-based, no line responsibility | Single questions, expert opinions |
| Interim CISO | Full-time for a period, bridges a gap | Vacancy or acute crisis |
| Permanent hire | Full-time, ongoing | Large companies from roughly 1'000 employees |
When does a fractional CISO pay off for an SME?
A fractional CISO pays off as soon as security needs leadership attention regularly, but not enough to fill a full-time post. That applies to most companies with 50 to 500 employees. The concrete triggers we see are the same ones again and again:
- A major customer or auditor asks for security evidence before they buy or renew.
- The cyber insurer asks about controls nobody can document.
- Regulation such as the ISG applies, and there is no working ISMS.
- IT spend on security keeps rising, but nobody knows whether protection rises with it.
- The board asks who is actually watching information security, and gets no clear answer.
If you are unsure whether your company is at that point, look at the typical course of a mandate: it starts with a stocktake, not with a multi-year contract.
What does a fractional CISO cost in Switzerland?
A fractional CISO costs considerably less than a permanent security lead. A full-time CISO in Switzerland sits at CHF 150'000 to 250'000 per year (source: jobs.ch salary data), plus social contributions and several months of recruiting. A mandate starts where the actual need is.
For orientation, without claiming completeness: a Cyber Assessment as a two-week sprint comes at a fixed price, a CISO retainer starts at around CHF 4'900 per month, roughly CHF 58'800 per year, and anyone who already has an IT or security lead starts with a leaner sparring mandate. The current numbers and what each one includes are on the packages and pricing section.
The most common thinking error: most companies do not have a security problem, they have a sizing problem. Too many tools, too little overview, too much cost for too little real protection. That is why a good mandate starts with the question of what stays and what can go, before anything new is added. More protection often comes without spending more.
Frequently asked questions
Does a fractional CISO also take over operational IT security?
A fractional CISO leads and steers, the role does not replace IT. Measures are implemented by the existing team or the service providers. The role makes sure the right things happen, get prioritised and documented, and that someone can account for them at the end. Hands-on work on the systems stays with IT.
How many days per month does an SME need?
That depends on size, maturity and the current triggers. Pure sparring for a company with its own security lead can work on two days per month, an active ISMS build needs more. The sensible order is to start with a clear stocktake and set the dose from there, not the other way round.
Does knowledge stay in the company when the mandate ends?
Yes, if the mandate is set up properly. Because a fractional CISO works inside the team and does not hand over by PDF, policies, registers and processes stay in the company. The goal is a security programme that keeps running without external support, not a permanent dependency.