Some organisations need a security function long before they need a permanent CISO and a team around them. Customer requirements have grown, a new programme is changing the risk, or the board wants a clearer answer to a simple question. Who is making sure the work gets done?
Hiring a senior security leader may be right eventually. It is a significant commitment if the organisation has not yet worked out what that person would own, who can act on their advice and how much specialist work is required each month. The first task is to build a way of working that survives beyond the next assessment or urgent request.
That means someone has a clear view of the risks, the people with budgets make the decisions, and delivery teams know when to involve security. Some of the expertise can come from outside. The authority to accept risk and fund change stays with the organisation.
I think every organisation needs somebody paying attention to cyber security. In a very small consultancy that may be the chief executive, who needs to understand the firm's digital services and the risks that come with them. As the organisation grows, the work may call for a security leader. The size of the budget matters, but giving the CISO title to somebody alongside an unrelated day job does not give them the experience or time the role requires.
Start with the work that needs to happen
The phrase security function can make a small organisation imagine a large corporate department. It does not have to start there. Look at the work already arriving. A customer is asking for assurance. A supplier needs review. A product team is changing how data is handled. An incident plan exists, but nobody has tested who would make the decisions under pressure.
If each request is handled by whoever happens to have time, the organisation may get through the week without seeing where the same problems recur. There is no regular place to decide which risks need money, which ones can be accepted and which ones need more evidence.
A useful starting point is a short list of the services, information and commitments that matter most. From there, agree who can decide about risk, who will organise the security work and which teams will make changes. That gives an external adviser something practical to support and gives the board a way to judge whether the arrangement is working.
Take a customer assurance request as an example. Someone needs to understand what the customer is asking, find the evidence, check whether it reflects what happens in practice and agree who will fix any gap. Answering the questionnaire is only one part of that job. If the same gap appears again in the next request, the function should know whether the promised change was funded and completed.
Keep ownership with people who can act
The NCSC describes good cyber governance as a way to get information and decisions moving through the organisation. It also says there is no single structure that fits everyone. An organisation can choose a proportionate structure. It still needs to be clear about who owns the decisions.
I would start with the reporting line. There is no single correct place for a CISO in every organisation, but there are arrangements that make the job almost impossible. The chief executive needs to understand their part in governing cyber risk. Below that, the CISO needs a route to the people who can approve spending, change priorities and act quickly when an urgent issue arises. A reporting line that only produces another meeting or another request for permission will not do that.
A part time security lead can assess a risk, explain the options, organise a test and report what the evidence shows. They cannot approve a programme budget they do not control. They cannot make a supplier change its contract or decide on the board's behalf that a risk is acceptable. Those decisions need named leaders inside the organisation.
This is where many arrangements struggle. The external person is introduced as the owner of everything cyber, then spends their time chasing decisions they have no power to make. A better brief gives them access to the leadership team, a regular decision meeting and an agreed route for urgent issues. It also names the business owner for each significant risk.
The authority needs to be practical. Agree who can sign off ordinary work, which decisions must reach the executive team and what action is already authorised in an emergency. Otherwise the security lead may identify a problem quickly and still spend weeks trying to get permission to address it. The structure is only useful if people can act through it.
An existing IT lead may already do much of the security work. They should be part of the arrangement from the start. Give them a way to raise problems without being expected to judge their own work in isolation, and make sure the security lead understands the systems and delivery pressures the IT team lives with. The aim is to give people support and clear decisions, not to hand them another list of unfunded actions.
Build a rhythm people can actually use
The function needs more than a monthly slide deck. At a sensible interval for the organisation, the security lead should be able to show what has changed, which controls have been checked, what needs a decision and what happened after the last one. Reporting should be short enough to use and specific enough to challenge.
The same approach should reach delivery work. Security should be present while a service or supplier can still be changed without expensive rework. Teams need to know when to ask for help and what they will get back. If every request starts with a new form and a long wait, the function will be avoided until late in the project.
An incident plan deserves the same attention. People need to know who will lead the response, who can authorise a service decision and how the organisation will contact its technical and legal support. A plan that has never been discussed with those people offers little comfort.
This rhythm need not mean more meetings. Security can use existing programme reviews, supplier conversations and leadership decisions, provided there is room to discuss the evidence and record what was agreed. If the same red risk appears in every report with no change to its owner, funding or treatment, the reporting cycle is recording the problem rather than helping to solve it.
Use outside support for the gaps you can name
There are several ways to buy security help. A retained senior adviser might lead the risk discussion, shape the work plan and make sure decisions reach the right people. A specialist might then do a defined piece of technical or assurance work. Existing IT and delivery teams still operate the systems and make the agreed changes.
A fractional CISO can make sense when the organisation cannot fund the right person full time. They work across several clients and see how different organisations deal with similar problems. That breadth can help them notice an emerging issue and know which approaches have worked elsewhere. The client should still agree how the arrangement works between scheduled days, including how a material threat or incident will be raised and who will respond. I would not assume a title or a retainer answers that question.
The NCSC's board guidance asks organisations to examine the skills they have and consider consultants or third party services for specific gaps. That is a useful test of a proposed arrangement. If the external support cannot explain what it will own, how it will work with the people already there and what will be left in the client's hands, the scope is too loose.
The balance may change. A period of transformation may need more security capacity for design and supplier reviews. During steadier operation, a smaller retained role may be enough to keep decisions, assurance and incident preparation moving. The point is to size the support around the work, then revisit it as the organisation changes.
A retained contract should be explicit about access and cover. Who attends the leadership meeting? Who responds when a supplier issue appears between scheduled days? Who brings in a technical specialist and who approves that extra work? A title and a monthly allowance of days do not answer those questions. The details matter when the first urgent decision arrives.
Good security leadership also has to balance the books. I want a CISO to tell a client where money is needed and where a proposed control is more expensive or complicated than the risk warrants. Avoiding late rework, poorly judged purchases and a growing backlog can be worth more than the cost of the leadership itself. That is part of the financial case for the role, though no adviser can promise a saving or an absence of incidents.
Know when the arrangement has outgrown itself
If the organisation can afford an experienced permanent security leader and has enough work for them to do, I would encourage that hire. A part time model has limits. If significant decisions are waiting every day, programmes repeatedly need an embedded leader, or the adviser has become the only person who understands the risks, it may be time to build the internal team.
Quality matters more to me than the number of days in a contract. I would rather have an excellent CISO two days a week than an ineffective one five days a week. A weak appointment can allow technical debt to grow quietly or lead to expensive decisions that a stronger leader would have challenged. The right long term answer depends on the work, the budget and the quality of person the organisation can bring in.
Equally, a permanent hire will struggle if the business has never agreed who owns its risks or how security work is funded. The operating model should be clear enough for either an internal leader or an external one to use. That also makes a future handover less painful.
Before deciding, look at the last few months. How often did security need a leadership decision? How much work required specialist skills? What work waited because nobody had the capacity to do it? Those answers are more useful than a generic rule based on company size.
There are also times when a short, defined project is enough. If the organisation needs a single assessment or a specific test, it may not need retained leadership. If it needs someone to keep risk decisions, supplier work and delivery conversations moving over time, a one off report will leave the same gap when the consultant goes home.
What a sensible first engagement should establish
An initial engagement should leave the organisation with a clear picture of its important services and risks, agreed decision owners, a short work plan and a way to report progress. It should say which work the provider will do, which work stays with internal teams and when the arrangement will be reviewed. These are practical outputs, not a large policy library for its own sake.
For Wuluf, the useful conversation starts with the decisions the organisation needs help making and the authority its security lead will have. We can discuss a retained leadership role, specialist support and the point at which an internal hire makes sense. The arrangement should leave your teams knowing whom to call and your leaders knowing what they need to decide.
Security needs clear ownership, regular decisions and specialist support attached to named people, long before it needs a permanent CISO and a team around them.
Working out what a right sized security function looks like for your organisation? Talk to Wuluf about retained leadership, specialist support and where internal capacity would make more sense.

