Target Search — Retained executive search for family offices, boards and portfolio companies. London.

The UK CISO market in H2 2026 — what boards should know before briefing the search

The UK Chief Information Security Officer market has shifted materially in the last twelve months, and the H2 2026 hiring pattern reflects both regulatory pressure and a reset in what boards now expect the CISO to hold. Below is our reading of the market as we enter Q3.

What CISOs are now expected to hold

The scope has widened beyond the traditional security programme. In regulated financial services in particular, CISOs are now expected to hold or heavily inform:

  • Operational resilience under the FCA/PRA/DORA regime
  • Third-party risk, particularly around critical technology providers
  • AI governance to the extent that AI capabilities are used within the security programme (a growing scope)
  • Board-level cyber risk translation — the CISO increasingly writes the cyber risk paragraph in the Annual Report
  • Regulatory engagement, including SMCR-related conversations where the CISO or their peer holds the operational-resilience SMF

What compensation has done

Base salary for a regulated-financial-services CISO in London has risen roughly 15–20% in the last twenty-four months. Total compensation (base plus cash bonus plus, in listed environments, LTIP) has risen more sharply — 25–35% in the same window — driven by cash bonus and LTIP re-benchmarking.

Non-financial-services CISO compensation has risen more slowly. The pattern is that the risk-of-regulation premium now attaches specifically to regulated environments.

What the strongest candidates now want in the mandate

  • Board access, not just quarterly reporting. Strong CISOs walk away from mandates where the reporting line to the board is via a quarterly slide in the CIO’s pack.
  • Sufficient budget authority. A CISO who cannot approve their own tooling spend up to a reasonable threshold is a CISO who will leave within eighteen months.
  • Clear separation from the CIO. The pattern of “CIO holds security” is now considered by strong candidates as a signal that the organisation has not caught up with market. Independent CISO reporting lines are increasingly non-negotiable.
  • Explicit written authority on regulatory conversations. Particularly in regulated firms, CISOs want the written mandate to represent the firm to the regulator on operational resilience matters.

For Chairs, CEOs and CHROs briefing a CISO search

Three things to build into the brief before starting the mandate: what the reporting line will be, what the budget authority will be, and whether the CISO will sit on the executive committee or attend it. These three, more than the technical scope, determine whether a strong CISO will accept the offer.

Related reading

For our CISO role page, see CISO Executive Search. For the cyber sector practice, see Cyber Security. For the retained-search fee and process, see the fees explainer.