Skip to content
Cyber Recrut

Hiring a CISO: Profile, Responsibilities and Process

Hiring a CISO: responsibilities by company size, profiles, reporting line, part-time CISO, assessment, offer and the first 90 days in the role.

Published on 6 min read

The CISO (RSSI in France) is often a company's first security hire, and the hardest one to get right. The role mixes strategy, technology, compliance and crisis management, and a wrong choice costs years. This guide helps you define the right profile, build a serious assessment process and prepare an arrival that delivers.

CISO responsibilities by company size

The title stays the same; the job changes a lot from one organisation to another.

ContextMain responsibilitiesWatch out for
SME or mid-size company with no security teamFirst assessment, priorities, basic hygiene, managing providers, awarenessThe CISO does a lot hands-on and must be willing to
Mid-size company with a small teamMulti-year roadmap, risk management, compliance (NIS2, ISO 27001), people managementBalancing building and running
Large groupGovernance, security policy, coordinating subsidiary CISOs, budget, audit committeePolitical influence, getting teams they do not manage to deliver
Scale-up or SaaS vendorProduct security, cloud, customer security questionnaires, certificationsSpeed: security must support growth, not slow it

If NIS2 applies to you, the directive shapes the role directly: management body accountability, risk management, incident notification. Our article on the profiles to hire for NIS2 covers these effects.

Three broad CISO profiles

The technical profile

Comes from architecture, infrastructure or technical audit. Grasps an information system quickly, talks to IT as a peer and spots concrete weaknesses. The risk: staying operational and struggling in front of the executive committee.

The governance profile

Comes from audit, consulting or compliance. Structures, documents, masters frameworks (ISO 27001, ANSSI's EBIOS Risk Manager) and reassures auditors. The risk: well-written policies that change nothing on the ground.

The business profile

Often has worked across several functions and thinks in business risk, budget and priorities. Secures resources and decisions. The risk: not enough technical depth to challenge teams and vendors.

The right choice depends on what is missing today. A company with no technical foundation needs a CISO who can get hands-on; an already well-equipped group needs someone who steers and arbitrates.

Who should the CISO report to?

The reporting line determines the real authority of the role.

  • To the CEO: the best position to arbitrate and escalate, especially when security also concerns business units and compliance.
  • To the CIO: common and effective for execution, but a conflict of interest when the CISO must flag risks created by IT itself.
  • To risk or legal: consistent in regulated sectors, at the cost of distance from technology.

Whatever you choose, guarantee direct access to the executive committee for serious matters, and write it into the job description.

The part-time or shared CISO option

Not every company needs a full-time CISO from day one. A part-time (or fractional) CISO works a few days a month to set the roadmap, lead a compliance project or prepare an audit.

This fits when the workload does not justify a full role, or as a step before an internal hire. The limits: reduced availability during a crisis and a slower grasp of internal culture. Either way, name an internal counterpart.

What to assess

A CISO is judged on the ability to move an organisation forward, not on a list of certifications. Our article on cybersecurity certifications explains why a CISSP or CISM alone does not settle it.

  • Vision and strategy: can they build a prioritised roadmap from an assessment, with realistic milestones?
  • Risk management: do they tie every measure to an understandable business risk?
  • Executive communication: can they explain a risk in five minutes, jargon-free, with a clear decision to make?
  • Crisis management: have they lived through a major incident? What did they decide, and what did they learn?
  • Leadership: can they hire, grow a team and work with providers?
  • Technical depth: enough to challenge an architect, a pentester or a vendor.

Interview panel and case study

Who sits at the table

  • The CEO or a delegate: alignment, presence, trust.
  • The CIO: ability to work together, technical understanding.
  • A business leader (finance, operations, legal): clarity and business sense.
  • An independent security expert: technical depth and consistency of answers.

A realistic case study

Send the candidate a short pack a few days before the interview: company context, an extract of the IT map, one or two anonymised past incidents, budget and timeline constraints. Ask them to present:

  1. Their three priorities for the first six months, and what they choose not to do.
  2. How they would present those priorities to the executive committee.
  3. Their reaction to a simulated incident during the presentation (a data leak reported by a customer, for example).

The case study reveals the ability to prioritise under constraint far better than general questions. To structure the whole process, see our method for assessing cybersecurity skills.

The offer and positioning

Good CISOs are in demand and choose as much as they are chosen. What weighs in their decision goes beyond pay.

  • The mandate: clear scope, reporting line, real authority over trade-offs.
  • The resources: budget, ability to hire, support from providers.
  • Leadership backing: visible commitment, especially as NIS2 makes management accountable.
  • Liability: how does the company protect its CISO (written delegations, insurance, role towards authorities)?

Pay varies widely with company size, sector, regulation and the breadth of the mandate. Set a realistic range in the brief so you do not lose a finalist at the last moment.

The first 90 days

A good hire can still fail through poor onboarding. Plan the arrival with the chosen candidate.

PeriodGoals
Days 1 to 30Meet leadership, IT and business units, understand critical activities, review past incidents and existing audits
Days 31 to 60Deliver an assessment and a risk map, identify high-impact quick wins
Days 61 to 90Present a prioritised, budgeted roadmap to the executive committee, secure the first decisions

Common mistakes

  • Looking for a unicorn: technical expert, lawyer, manager and speaker at once. Pick what really matters.
  • Hiring a CISO without authority: a role with no mandate produces reports, not security.
  • Judging on certifications rather than on the ability to decide.
  • Leaving crisis management out of the assessment, though it is when the role shows its worth.
  • Forgetting the team: a CISO alone cannot do everything. Think about the profiles around them, such as a SOC analyst or a pentester.

In short

Hiring a CISO starts with deciding what your organisation needs now: a technical builder, a governance structurer or a business-minded leader. A reporting line that grants authority, a realistic case study, a varied panel and a 90-day onboarding plan make the difference between a successful hire and an early departure.

Preparing to hire a CISO? At Cyber Recrut, a recruiter and a security practitioner run every search together, from framing the mandate to the case study, and our shortlisted candidates prove their skills on hands-on labs when the role calls for it. See how we work or tell us about your need.

Related articles