Hiring a CISO: Profile, Responsibilities and Process
Hiring a CISO: responsibilities by company size, profiles, reporting line, part-time CISO, assessment, offer and the first 90 days in the role.
The CISO (RSSI in France) is often a company's first security hire, and the hardest one to get right. The role mixes strategy, technology, compliance and crisis management, and a wrong choice costs years. This guide helps you define the right profile, build a serious assessment process and prepare an arrival that delivers.
CISO responsibilities by company size
The title stays the same; the job changes a lot from one organisation to another.
| Context | Main responsibilities | Watch out for |
|---|---|---|
| SME or mid-size company with no security team | First assessment, priorities, basic hygiene, managing providers, awareness | The CISO does a lot hands-on and must be willing to |
| Mid-size company with a small team | Multi-year roadmap, risk management, compliance (NIS2, ISO 27001), people management | Balancing building and running |
| Large group | Governance, security policy, coordinating subsidiary CISOs, budget, audit committee | Political influence, getting teams they do not manage to deliver |
| Scale-up or SaaS vendor | Product security, cloud, customer security questionnaires, certifications | Speed: security must support growth, not slow it |
If NIS2 applies to you, the directive shapes the role directly: management body accountability, risk management, incident notification. Our article on the profiles to hire for NIS2 covers these effects.
Three broad CISO profiles
The technical profile
Comes from architecture, infrastructure or technical audit. Grasps an information system quickly, talks to IT as a peer and spots concrete weaknesses. The risk: staying operational and struggling in front of the executive committee.
The governance profile
Comes from audit, consulting or compliance. Structures, documents, masters frameworks (ISO 27001, ANSSI's EBIOS Risk Manager) and reassures auditors. The risk: well-written policies that change nothing on the ground.
The business profile
Often has worked across several functions and thinks in business risk, budget and priorities. Secures resources and decisions. The risk: not enough technical depth to challenge teams and vendors.
The right choice depends on what is missing today. A company with no technical foundation needs a CISO who can get hands-on; an already well-equipped group needs someone who steers and arbitrates.
Who should the CISO report to?
The reporting line determines the real authority of the role.
- To the CEO: the best position to arbitrate and escalate, especially when security also concerns business units and compliance.
- To the CIO: common and effective for execution, but a conflict of interest when the CISO must flag risks created by IT itself.
- To risk or legal: consistent in regulated sectors, at the cost of distance from technology.
Whatever you choose, guarantee direct access to the executive committee for serious matters, and write it into the job description.
The part-time or shared CISO option
Not every company needs a full-time CISO from day one. A part-time (or fractional) CISO works a few days a month to set the roadmap, lead a compliance project or prepare an audit.
This fits when the workload does not justify a full role, or as a step before an internal hire. The limits: reduced availability during a crisis and a slower grasp of internal culture. Either way, name an internal counterpart.
What to assess
A CISO is judged on the ability to move an organisation forward, not on a list of certifications. Our article on cybersecurity certifications explains why a CISSP or CISM alone does not settle it.
- Vision and strategy: can they build a prioritised roadmap from an assessment, with realistic milestones?
- Risk management: do they tie every measure to an understandable business risk?
- Executive communication: can they explain a risk in five minutes, jargon-free, with a clear decision to make?
- Crisis management: have they lived through a major incident? What did they decide, and what did they learn?
- Leadership: can they hire, grow a team and work with providers?
- Technical depth: enough to challenge an architect, a pentester or a vendor.
Interview panel and case study
Who sits at the table
- The CEO or a delegate: alignment, presence, trust.
- The CIO: ability to work together, technical understanding.
- A business leader (finance, operations, legal): clarity and business sense.
- An independent security expert: technical depth and consistency of answers.
A realistic case study
Send the candidate a short pack a few days before the interview: company context, an extract of the IT map, one or two anonymised past incidents, budget and timeline constraints. Ask them to present:
- Their three priorities for the first six months, and what they choose not to do.
- How they would present those priorities to the executive committee.
- Their reaction to a simulated incident during the presentation (a data leak reported by a customer, for example).
The case study reveals the ability to prioritise under constraint far better than general questions. To structure the whole process, see our method for assessing cybersecurity skills.
The offer and positioning
Good CISOs are in demand and choose as much as they are chosen. What weighs in their decision goes beyond pay.
- The mandate: clear scope, reporting line, real authority over trade-offs.
- The resources: budget, ability to hire, support from providers.
- Leadership backing: visible commitment, especially as NIS2 makes management accountable.
- Liability: how does the company protect its CISO (written delegations, insurance, role towards authorities)?
Pay varies widely with company size, sector, regulation and the breadth of the mandate. Set a realistic range in the brief so you do not lose a finalist at the last moment.
The first 90 days
A good hire can still fail through poor onboarding. Plan the arrival with the chosen candidate.
| Period | Goals |
|---|---|
| Days 1 to 30 | Meet leadership, IT and business units, understand critical activities, review past incidents and existing audits |
| Days 31 to 60 | Deliver an assessment and a risk map, identify high-impact quick wins |
| Days 61 to 90 | Present a prioritised, budgeted roadmap to the executive committee, secure the first decisions |
Common mistakes
- Looking for a unicorn: technical expert, lawyer, manager and speaker at once. Pick what really matters.
- Hiring a CISO without authority: a role with no mandate produces reports, not security.
- Judging on certifications rather than on the ability to decide.
- Leaving crisis management out of the assessment, though it is when the role shows its worth.
- Forgetting the team: a CISO alone cannot do everything. Think about the profiles around them, such as a SOC analyst or a pentester.
In short
Hiring a CISO starts with deciding what your organisation needs now: a technical builder, a governance structurer or a business-minded leader. A reporting line that grants authority, a realistic case study, a varied panel and a 90-day onboarding plan make the difference between a successful hire and an early departure.
Preparing to hire a CISO? At Cyber Recrut, a recruiter and a security practitioner run every search together, from framing the mandate to the case study, and our shortlisted candidates prove their skills on hands-on labs when the role calls for it. See how we work or tell us about your need.