Cyber Security · CISO

Chief Information Security Officer search.

Retained CISO and Head of Information Security search for regulated and enterprise organisations.

What the role is

A short definition.

A Chief Information Security Officer leads the organisation’s security programme end-to-end: strategy, governance, risk, engineering, operations and reporting. In regulated environments, the CISO increasingly holds explicit accountability under SMCR, DORA and comparable frameworks. In enterprise organisations, the CISO is typically the board-facing voice on cyber risk, translating between technical detail and executive decision-making.

Core responsibilities

What we assess candidates against.

  • Security strategy aligned to the organisation’s risk appetite and regulatory obligations
  • Governance across information security, cyber risk, resilience, business continuity and where relevant, physical security
  • Operational leadership across SOC, incident response, engineering, GRC and awareness
  • Board and audit committee reporting; regulatory engagement in regulated firms
  • Programme leadership on cloud security, identity, DORA operational resilience, third-party risk
  • Building and retaining the security leadership team

When to run this search

Typical triggers.

When an organisation crosses the threshold where cyber risk becomes a board-level concern; following a serious incident or regulatory finding; when moving into a new regulatory perimeter (financial services, critical national infrastructure, defence-adjacent); on a change of CIO or CEO where security posture is being reset; when an existing CISO moves on.

How we search for this role

The specific approach we take.

CISO search requires distinguishing the profiles a client actually needs: board-level risk translation (the “governance CISO”), technical security leadership (the “engineering CISO”), or a hybrid. We calibrate the brief before starting. Candidate pools include sitting CISOs at comparable organisations, Deputy CISOs ready for the top seat, senior regulator alumni for regulated searches, and, for engineering-heavy roles, Heads of Security Engineering from technology companies. Every search is retained.

FAQ

Frequently asked questions

What is the difference between a CISO and a Head of Information Security?

Titles vary widely. In smaller organisations they are often the same role. In larger organisations “CISO” tends to indicate the board-facing accountable executive, while “Head of Information Security” indicates the operational security leader reporting to the CISO. We calibrate against how the client uses the titles.

Can you support regulated financial services CISO appointments?

Yes. Regulated financial services CISO searches are a specialism. We understand PRA/FCA operational resilience expectations, DORA implications for UK entities and the SMCR reporting responsibilities that increasingly attach to security leadership. We advise on pre-approval-friendly candidate profiles where relevant.

Do you understand technical stacks?

Our consultants assess technical breadth and depth directly — cloud (AWS/Azure/GCP), identity, application security, network, data protection, SOC operations, threat intelligence — sufficient to defend every shortlist against the technical scrutiny CISO clients apply.

How long does a CISO search take?

Twelve to sixteen weeks is typical, brief to accepted offer. Board-facing CISO searches tend to run longer because Board and Audit Committee interviews are involved.

How is compensation typically structured?

Base, cash bonus and, in listed environments, LTIP or restricted stock. CISO compensation has risen sharply over the last five years, particularly in regulated financial services, and we benchmark every mandate against current market data.

Related practice

This role is part of the Cyber Security practice.