For CEOs, CFOs and boards with an open security seat

Interim CISO Services, Full-Time Until the Seat Is Filled

A full-time security chief within weeks of a breach, a resignation, an audit or a hard insurance renewal.

Empty leather desk chair pushed back from a desk holding a stack of binders, a ring of keys and an orange mug, the open security seat an interim CISO fills

Interim CISO services place a full-time, temporary chief information security officer in an empty security seat after a breach, a CISO’s exit, an audit or an insurance renewal. The interim stays until your permanent CISO starts.

Last updated: September 29, 2026

On this page
What a full-time interim CISO from KORE1 takes over, what they inherit, and the contract engineers who usually arrive with them.
Covered elsewhere
Part-time security leadership is in our fractional CISO guide. A permanent hire runs through CISO staffing.

Security seats don’t empty on a convenient date. Ever. The CISO resigns the week the SOC 2 auditors send their request list. Or a ransomware note turns up on a Friday afternoon, and the only person who knew where the incident response retainer lived, and which partner at the outside firm picks up on a weekend, left in June.

An interim CISO takes the seat full-time, with the title and the authority, and runs the program until your permanent hire arrives. It’s one of the leadership roles our cybersecurity staffing desk fills, and it rarely arrives alone. Every fix an interim orders needs somebody to carry it out.

Interim CISO in a grey cardigan reading through a thick printed binder with blank colored tabs at a desk, marking pages with a pen on her first week in the security seat
Week one

The First Week of an Interim CISO Engagement

No ramp. That’s the whole reason to buy the model.

  • AccessEvery admin account, SSO role and cloud console login the last CISO held is closed or moved on day one. Shared vault entries too.
  • The incident retainerWho’s the forensics firm? Who’s breach counsel, and does anyone have a current number for either? If nobody knows, the interim finds out before it matters.
  • Auditors and the brokerAnyone waiting on a signature from the security chief gets a new name, a date and a straight answer about what’s late. No spin.
  • The boardA short written read. What’s exposed, what it will cost to close, and what can wait for the permanent hire.

Then comes the unglamorous part, reading every open ticket, exception and accepted risk the last person left behind, because that pile is where the real state of a security program lives and where most of the surprises turn up. It takes days, not hours.

Give the interim the CISO title for the whole engagement. Not a softer one. Auditors, insurers and regulators look for the person with the title, and an “advisor” who can’t approve a risk exception spends the engagement asking permission.

The inheritance

The Register an Interim CISO Inherits

Every CISO keeps a list of open risks, exceptions and promises with their name in the owner column. They leave. The list stays. Here’s an illustrative one, a week after a mid-market company lost its CISO and then found a ransomware note.

Security risk register Open items, sorted by due

  1. R-09Former CISO’s admin, SSO and vendor portal access closed Came in withCISO exit OwnerFormer CISOInterim CISO DueDay 1
  2. R-02Every privileged credential the attacker could have reached, rotated Came in withBreach OwnerUnassignedInterim CISO DueDay 2
  3. R-05Regulator notice drafted with outside counsel Came in withBreach OwnerUnassignedInterim CISO Due72 hours if NYDFS
  4. R-14Accepted risk, legacy VPN without MFA, acceptance lapsed in March Came in withCISO exit OwnerFormer CISOInterim CISO DueRenew or close
  5. R-23Cyber renewal application, MFA and backup answers checked against what’s deployed Came in withRenewal OwnerFormer CISOInterim CISO DueBefore anyone signs
  6. R-18SOC 2 exception on quarterly access reviews, auditor retest Came in withAudit OwnerFormer CISOInterim CISO DueBefore fieldwork
  7. R-27Annual NYDFS compliance certification, signed by the CISO Came in withCISO exit OwnerFormer CISOInterim CISO DueApril 15
Illustrative register, not a client’s. Item wording, IDs and due dates vary by company and regulator.

Look at the owner column, where every line was either the former CISO’s or nobody’s, and on day one each becomes the interim’s. Watch R-23. In 2022 Travelers asked a federal court to rescind a cyber policy after a ransomware attack, saying the CEO-signed application claimed MFA protection the company only had on its firewall, and the two sides agreed to void the policy from inception, as Insurance Journal reported. Void, from day one.

Two lines carry legal weight. New York’s financial regulator wants notice within 72 hours of determining a cybersecurity incident occurred, and its annual certification, due April 15, is signed by the CISO under 23 NYCRR 500.17. Healthcare adds the HIPAA limit, no later than 60 calendar days after a breach is discovered for notice to the people affected, under 45 CFR 164.404.

Chief executive and an interim CISO talking in two armchairs by an office window, one holding a few sheets of paper, deciding how long the interim security engagement should run
Choosing the model

Interim CISO, Fractional CISO or a Permanent Search

Is anyone in the seat? That settles most of it.

  • Interim CISOThe seat is empty, or the person in it can’t stay. Full-time, with the title, billed hourly through our contract staffing desk. Gone when the permanent CISO starts.
  • Fractional CISOThere was never a full-time seat, and a few days a month of senior judgment will do. Fine for a first framework. Thin cover in an incident.
  • Permanent searchRuns beside the interim. Never after it. Our CISO searches usually take 60 to 90 days.

Budget the interim for the permanent search plus the new CISO’s notice period, which for a sitting security chief at another company is rarely short, and that puts most engagements somewhere between four and six months. Sometimes the interim is the permanent answer. It happens. So agree at the start whether they can be considered, and write the terms down the way a contract-to-hire conversion is written.

The grey areas between interim, fractional and plain contract work are laid out in our comparison of the three engagement models. Read it before you sign anything longer than six months. If it is the CTO who left rather than the CISO, the same bridge applies to the chief technology officer seat.

3 of 4

recent post-breach CISO hires in the seat inside 21 days

92%

of KORE1 hires still in place after a year

17 days

to fill the average KORE1 IT search

2005

KORE1 founded in Irvine, California

Source: KORE1 placement data and our CISO search desk.

The bench behind the seat

The Contract Engineers Behind an Interim CISO

An interim CISO decides what gets fixed. Somebody has to fix it. We staff those hands through cybersecurity staff augmentation, often from the same first call, so the interim can hand a containment list to people who start that week instead of waiting on a second search.

  • Respond

    Incident response and SOC

    Analysts and responders who work the containment list while the interim briefs counsel and the board.

    Security operations staffing
  • Cloud

    Cloud security engineers

    Engineers who close the misconfigurations and identity gaps a breach or an assessment exposes in AWS, Azure or GCP.

    Cloud security staffing
  • Identity

    IAM and access engineers

    People who rebuild privileged access, SSO and offboarding, so the next departure closes cleanly.

    IAM engineer staffing
  • Evidence

    Audit and GRC analysts

    Analysts who gather SOC 2 and ISO 27001 evidence and chase control owners before the auditor does.

    Security analyst staffing
Asked by CEOs, CFOs and general counsel

Common Questions

What does an interim CISO do?

Runs the security program full-time, with the CISO title, until a permanent CISO starts. That covers open risks, incidents, auditors, the insurance broker and the board report, plus directing the contract engineers the fixes need, which is most of the job in the first month after a breach. It isn’t an advisory seat.

How much does an interim CISO cost?

$150 to $300 an hour, billed for full-time weeks, covers most interim executives we place. A 20-week engagement at $250 an hour comes to about $200,000. Five months of leadership. Not a salary.

How fast can an interim CISO start?

Within about three weeks when it’s urgent. Of our last four post-breach CISO hires, three were in the seat inside 21 days, because urgent searches go to people who can leave their current work quickly. A planned exit with notice leaves more room. Sometimes it’s faster.

Is an interim CISO the same as a fractional CISO?

No, an interim CISO works full-time in an empty seat and leaves when the permanent hire arrives. A fractional CISO gives a few days a month, often to a company that has never had a full-time security chief.

Can an interim CISO sign the NYDFS annual certification?

Yes, if they hold the CISO role. Part 500 lets a covered entity use a CISO who works for a third party, provided it keeps responsibility for compliance and names a senior person to oversee them. The April 15 certification is signed by that CISO and the highest-ranking executive.

How long does an interim CISO engagement last?

Four to six months covers most of them. That’s the permanent search, which usually runs 60 to 90 days with us, plus the new CISO’s notice period. Engagements stretch when the search starts late. Start both at once.

Can we hire the interim CISO permanently?

Sometimes the best candidate is already in the chair. Settle on day one whether the interim is a candidate for the permanent role, and write the conversion fee and timing into the contract. Then run the permanent search anyway, so the comparison is real.

Next step

Fill the Seat, Then Staff the Fixes

Tell us what happened, and when. A KORE1 recruiter will come back with interim CISO candidates and, if the register needs hands, contract security engineers who can start alongside them.

Talk to Our Security Desk →

Or call 949-706-6990