FeaturedRecruitment CRM review ·  Get more from the CRM you already pay for.  Explore the review →
Change service · From £1,350/month · UK & Ireland

Fractional CISO & vCISO.
Cyber risk. Owned.

A fractional or virtual CISO gives your cyber risk a senior owner. They lead the security priorities, risk register and board reporting, working with your team and existing providers. We agree the responsibilities, time and monthly fee upfront. Additional engineering and managed security are scoped separately.

FRACTIONAL CISO · SNAPSHOT
AVAILABLE
from£1,350/month
Priced on scope · No recruiter fees
A standing weekly security slot
In the seat in two weeks
Risk register and board report included
Named CISO for regulators and insurers
UK & Ireland · Remote-firstSee what's included →
The short answer

What is a fractional CISO?

A fractional CISO is an experienced Chief Information Security Officer who works with your business part time while carrying full ownership of cyber strategy, risk and compliance. Some providers call it a vCISO or virtual CISO. Same role. You get a named security leader your board, regulator, insurer and biggest client can point to, for a fraction of the cost of hiring one.

The difference worth paying attention to is not the name. It is whether the CISO only writes the plan, or also has the engineers to carry it out. Ours does both. The rest of this page covers what that looks like, what it costs and how to tell whether you need one.

When to hire one

When should you hire a fractional CISO?

The honest trigger: hire a fractional CISO when security has become a board question and nobody at board level owns the answer. Not the IT manager, not the MSP, not the FD who ended up with it.

For a UK business with 50–1,000 staff that usually looks like:

A regulator, insurer or enterprise client has asked who your CISO is and the honest answer is "nobody"

Security questionnaires land on the FD's desk and take a week of guesswork to answer

Cyber insurance renewal wants MFA everywhere, tested backups and an incident plan you don't have

Your MSP says you're secure. Nobody senior has checked what that actually means

A tender or client contract now requires Cyber Essentials Plus or ISO 27001

You've had the near-miss: the phishing click, the invoice fraud attempt, the laptop left on a train

If two or more of those land, you don't need another security tool. You need someone whose job is to own the risk and be accountable for it.

What's included

What your fractional CISO delivers.

Direct answer first: a security strategy the board understands, a risk register someone owns and a named person your regulator and insurer can hold to account.

Month by month it looks like this:

Cyber strategy and a 12-month roadmap

Where the security money goes and why, ranked by the risks that would actually hurt you, not by what a vendor wants to sell.

A living risk register

Owned, reviewed and reported. The document your insurer, auditor and regulator will ask for first.

Cyber Essentials Plus and ISO 27001 ownership

The CISO holds the programme, we deliver it. Gap assessment, remediation, auditor liaison, certificate.

Named CISO for regulators, insurers and clients

SM&CR cyber lead where you're FCA-regulated. The person who answers the questionnaire and signs the evidence.

Incident response plan, rehearsed

A plan that exists, a tabletop exercise that tests it and a named person who runs containment when it happens.

Board reporting in plain English

A quarterly security report the board can challenge. Risk, spend, progress, no acronyms without translation.

Strategic and tactical

Most vCISO services stop at the plan. Ours doesn't.

A roadmap nobody implements is a liability with a date on it. Your fractional CISO sets the direction and holds the risk. Behind them sits the AssurePath engineering bench that runs cyber operations for clients every day. One firm, both halves, no handover between the person who decided and the people who do.

Already have an MSP you like? Keep them. The CISO sets the standard and holds them to it. Nothing on this page requires you to move your IT to us.

STRATEGIC

The CISO decides

  • Risk appetite agreed with the board
  • 12-month roadmap and security budget
  • Policy set, ownership and review cycle
  • Regulator, insurer and client conversations
  • Cyber Essentials Plus and ISO 27001 programme
TACTICAL

The engineers deliver

  • MFA, conditional access and privileged identity
  • EDR rollout and vulnerability management
  • Backup verification and restore drills
  • Incident containment when something happens
  • Optional 24/7 SOC through our UK partner
What it costs

What a fractional CISO costs in the UK.

Most of the market bills vCISO time by the hour or the day, which quietly punishes you for asking questions. We price the role instead: one monthly figure, agreed with you before anything starts.

from£1,350/month
PRICED ON SCOPE · AGREED BEFORE YOU SIGN

£1,350 is the starting point. Most CISO engagements sit above it, because a regulated firm or an ISO 27001 programme needs more of the month than the floor covers. We work that out with you on the first call. The number we agree is the number on the invoice.

OptionTypical costWhat you actually get
Full-time CISOSix-figure salary plus NI, pension and bonusA full-time seat for a part-time need, and a scarce hire that takes months to land
Metered vCISOBilled by the hour or day, invoice variesAdvice when you ask for it, the meter running every time you do
Big-consultancy security programme£50k+ engagementsA maturity assessment, a deck and a junior team to implement it
AssurePath fractional CISO★ AGREED UP FRONTFrom £1,350/month, agreed up frontNamed senior CISO, risk register and board report included, engineers behind them

Delivery work is separate and quoted separately. Tabletop exercises start at £550 + VAT, Cyber Essentials Plus and ISO 27001 programmes are priced on our compliance page, and managed security runs per user per month on the cyber operations page. The CISO fee never hides a delivery bill inside it.

Which model do you need

Fractional CISO vs vCISO vs full-time.

Fractional CISO

Part time · Ongoing · Accountable

Part time and ongoing. Owns the risk register, the roadmap and the regulator conversation, and has engineers to carry out the plan. Our model.

vCISO (advisory only)

Metered · Remote · Advises

Same title, narrower job. Most vCISO services advise by the hour and hand you a list. Fine if you have a team to execute it. Most 50–1,000 person firms don't.

Full-time CISO

Permanent · Scarce · Six figures

Right when security is a full-time job. Below about 1,000 staff it rarely is, and a good one takes months and a recruiter fee to find.

Not sure you need a CISO at all? That's what the free call is for. If the honest answer is "a Cyber Essentials Plus programme and a DPO from £950/month", we'll say so and quote that instead.

Book a free strategy call
The first three months

Your first 90 days.

01
Week 1–2
In the seat. Access, first leadership meeting, current-state snapshot of identity, endpoints, backups and the last twelve months of incidents.
02
Day 30
Risk register live and gap assessment done against Cyber Essentials Plus, ISO 27001 or your regulator's expectations. Quick wins like MFA gaps closed by the engineers.
03
Day 60
12-month security roadmap and budget on the table. Incident response plan written. Insurer and client questionnaires answered from evidence, not memory.
04
Day 90
First board security report walked through. First tabletop exercise run. The board can finally answer "are we secure?" with something better than "we think so".
Sector fluency

Built for your sector.

Our CISOs have held the named role for FCA-regulated firms and led ISO 27001 programmes from zero to certificate. We specialise in UK professional services with 50–1,000 users:

FCA-regulated? The CISO acts as your named cyber lead under SM&CR, supports Consumer Duty submissions and is the audit point of contact. That is the job, not an add-on.

Where we work

UK-wide and the Republic of Ireland, remote-first with on-site days for board meetings, audits and incidents, where they earn their travel.

CORE CITIES
ManchesterLondonBirminghamBristolDublin
Why AssurePath

Why AssurePath.

Engineers, not account managers.

Your CISO has built and run security programmes, not just audited them. CISSP and CISM on the bench, ISO 27001 lead auditor experience, named CISO on FCA permissions.

Published starting price.

Most UK vCISO providers won't put a number on the page. Ours starts at £1,350 a month, and we'll tell you on the first call where your scope actually lands.

In the seat in two weeks.

Security hires are scarce and slow. Executive search takes months and a fat fee. We don't.

We'll tell you not to buy things.

Including security tools. Often the first finding is a licence you already pay for that nobody switched on. Sometimes the answer is a DPO or a compliance programme, not a CISO, and we'll say so.

No lock-in.

Term is agreed with you, not imposed on you. The risk register, policies and evidence pack are yours and stay with you either way.

FAQ

Questions before the call.

The questions we get asked most about the fractional CISO role. We answer them again, properly, on the call.

Last reviewed: August 2026.

A fractional CISO is a senior Chief Information Security Officer who works with your business part time while owning cyber strategy, the risk register, compliance and the conversation with your regulator, insurer and clients. You get a named, accountable security leader without the six-figure salary a permanent CISO costs.

Let's talk

Thirty minutes with a security engineer,
not a pitch.

Book a free strategy call. If a fractional CISO isn't the right answer, we'll tell you what is – even when it's cheaper.