Interim CISO Services, Full-Time Until the Seat Is Filled
A full-time security chief within weeks of a breach, a resignation, an audit or a hard insurance renewal.

Interim CISO services place a full-time, temporary chief information security officer in an empty security seat after a breach, a CISO’s exit, an audit or an insurance renewal. The interim stays until your permanent CISO starts.
Last updated: September 29, 2026
- On this page
- What a full-time interim CISO from KORE1 takes over, what they inherit, and the contract engineers who usually arrive with them.
- Covered elsewhere
- Part-time security leadership is in our fractional CISO guide. A permanent hire runs through CISO staffing.
Security seats don’t empty on a convenient date. Ever. The CISO resigns the week the SOC 2 auditors send their request list. Or a ransomware note turns up on a Friday afternoon, and the only person who knew where the incident response retainer lived, and which partner at the outside firm picks up on a weekend, left in June.
An interim CISO takes the seat full-time, with the title and the authority, and runs the program until your permanent hire arrives. It’s one of the leadership roles our cybersecurity staffing desk fills, and it rarely arrives alone. Every fix an interim orders needs somebody to carry it out.

The First Week of an Interim CISO Engagement
No ramp. That’s the whole reason to buy the model.
- AccessEvery admin account, SSO role and cloud console login the last CISO held is closed or moved on day one. Shared vault entries too.
- The incident retainerWho’s the forensics firm? Who’s breach counsel, and does anyone have a current number for either? If nobody knows, the interim finds out before it matters.
- Auditors and the brokerAnyone waiting on a signature from the security chief gets a new name, a date and a straight answer about what’s late. No spin.
- The boardA short written read. What’s exposed, what it will cost to close, and what can wait for the permanent hire.
Then comes the unglamorous part, reading every open ticket, exception and accepted risk the last person left behind, because that pile is where the real state of a security program lives and where most of the surprises turn up. It takes days, not hours.
Give the interim the CISO title for the whole engagement. Not a softer one. Auditors, insurers and regulators look for the person with the title, and an “advisor” who can’t approve a risk exception spends the engagement asking permission.
The Register an Interim CISO Inherits
Every CISO keeps a list of open risks, exceptions and promises with their name in the owner column. They leave. The list stays. Here’s an illustrative one, a week after a mid-market company lost its CISO and then found a ransomware note.
Security risk register Open items, sorted by due
-
R-09Former CISO’s admin, SSO and vendor portal access closed
Came in withCISO exit
Owner
Former CISOInterim CISO DueDay 1 -
R-02Every privileged credential the attacker could have reached, rotated
Came in withBreach
Owner
UnassignedInterim CISO DueDay 2 -
R-05Regulator notice drafted with outside counsel
Came in withBreach
Owner
UnassignedInterim CISO Due72 hours if NYDFS -
R-14Accepted risk, legacy VPN without MFA, acceptance lapsed in March
Came in withCISO exit
Owner
Former CISOInterim CISO DueRenew or close -
R-23Cyber renewal application, MFA and backup answers checked against what’s deployed
Came in withRenewal
Owner
Former CISOInterim CISO DueBefore anyone signs -
R-18SOC 2 exception on quarterly access reviews, auditor retest
Came in withAudit
Owner
Former CISOInterim CISO DueBefore fieldwork -
R-27Annual NYDFS compliance certification, signed by the CISO
Came in withCISO exit
Owner
Former CISOInterim CISO DueApril 15
Look at the owner column, where every line was either the former CISO’s or nobody’s, and on day one each becomes the interim’s. Watch R-23. In 2022 Travelers asked a federal court to rescind a cyber policy after a ransomware attack, saying the CEO-signed application claimed MFA protection the company only had on its firewall, and the two sides agreed to void the policy from inception, as Insurance Journal reported. Void, from day one.
Two lines carry legal weight. New York’s financial regulator wants notice within 72 hours of determining a cybersecurity incident occurred, and its annual certification, due April 15, is signed by the CISO under 23 NYCRR 500.17. Healthcare adds the HIPAA limit, no later than 60 calendar days after a breach is discovered for notice to the people affected, under 45 CFR 164.404.

Interim CISO, Fractional CISO or a Permanent Search
Is anyone in the seat? That settles most of it.
- Interim CISOThe seat is empty, or the person in it can’t stay. Full-time, with the title, billed hourly through our contract staffing desk. Gone when the permanent CISO starts.
- Fractional CISOThere was never a full-time seat, and a few days a month of senior judgment will do. Fine for a first framework. Thin cover in an incident.
- Permanent searchRuns beside the interim. Never after it. Our CISO searches usually take 60 to 90 days.
Budget the interim for the permanent search plus the new CISO’s notice period, which for a sitting security chief at another company is rarely short, and that puts most engagements somewhere between four and six months. Sometimes the interim is the permanent answer. It happens. So agree at the start whether they can be considered, and write the terms down the way a contract-to-hire conversion is written.
The grey areas between interim, fractional and plain contract work are laid out in our comparison of the three engagement models. Read it before you sign anything longer than six months. If it is the CTO who left rather than the CISO, the same bridge applies to the chief technology officer seat.
3 of 4
recent post-breach CISO hires in the seat inside 21 days
92%
of KORE1 hires still in place after a year
17 days
to fill the average KORE1 IT search
2005
KORE1 founded in Irvine, California
Source: KORE1 placement data and our CISO search desk.
The Contract Engineers Behind an Interim CISO
An interim CISO decides what gets fixed. Somebody has to fix it. We staff those hands through cybersecurity staff augmentation, often from the same first call, so the interim can hand a containment list to people who start that week instead of waiting on a second search.
Respond
Incident response and SOC
Analysts and responders who work the containment list while the interim briefs counsel and the board.
Security operations staffingCloud
Cloud security engineers
Engineers who close the misconfigurations and identity gaps a breach or an assessment exposes in AWS, Azure or GCP.
Cloud security staffingIdentity
IAM and access engineers
People who rebuild privileged access, SSO and offboarding, so the next departure closes cleanly.
IAM engineer staffingEvidence
Audit and GRC analysts
Analysts who gather SOC 2 and ISO 27001 evidence and chase control owners before the auditor does.
Security analyst staffing
Common Questions
What does an interim CISO do?
Runs the security program full-time, with the CISO title, until a permanent CISO starts. That covers open risks, incidents, auditors, the insurance broker and the board report, plus directing the contract engineers the fixes need, which is most of the job in the first month after a breach. It isn’t an advisory seat.
How much does an interim CISO cost?
$150 to $300 an hour, billed for full-time weeks, covers most interim executives we place. A 20-week engagement at $250 an hour comes to about $200,000. Five months of leadership. Not a salary.
How fast can an interim CISO start?
Within about three weeks when it’s urgent. Of our last four post-breach CISO hires, three were in the seat inside 21 days, because urgent searches go to people who can leave their current work quickly. A planned exit with notice leaves more room. Sometimes it’s faster.
Is an interim CISO the same as a fractional CISO?
No, an interim CISO works full-time in an empty seat and leaves when the permanent hire arrives. A fractional CISO gives a few days a month, often to a company that has never had a full-time security chief.
Can an interim CISO sign the NYDFS annual certification?
Yes, if they hold the CISO role. Part 500 lets a covered entity use a CISO who works for a third party, provided it keeps responsibility for compliance and names a senior person to oversee them. The April 15 certification is signed by that CISO and the highest-ranking executive.
How long does an interim CISO engagement last?
Four to six months covers most of them. That’s the permanent search, which usually runs 60 to 90 days with us, plus the new CISO’s notice period. Engagements stretch when the search starts late. Start both at once.
Can we hire the interim CISO permanently?
Sometimes the best candidate is already in the chair. Settle on day one whether the interim is a candidate for the permanent role, and write the conversion fee and timing into the contract. Then run the permanent search anyway, so the comparison is real.
Fill the Seat, Then Staff the Fixes
Tell us what happened, and when. A KORE1 recruiter will come back with interim CISO candidates and, if the register needs hands, contract security engineers who can start alongside them.
Talk to Our Security Desk →Or call 949-706-6990
