Last updated: September 7, 2026
By Mike Carter, Director of Partnership Success, KORE1
Bring in contract cybersecurity talent when the work is a burst your team cannot absorb or has never done before, and hire full time when someone has to own the outcome permanently. That sounds close to the test you already run on every other technical role. It is not, and the gap between the two is where most security staffing decisions quietly go wrong.
The usual test is one question. Does the work end? Ask it about a Workday rollout or a data center exit and it answers cleanly. Ask it about security and it tells you to hire everybody, forever, because almost nothing in security ends. Monitoring does not end. Patching does not end. The audit comes back next year with the same auditor and a longer evidence request.
So a test that works everywhere else stops working here, and teams keep running it anyway.
A medical device manufacturer in Orange County called us from exactly that spot. Enterprise deal contingent on SOC 2 Type II, compliance date fourteen weeks out, and an open req for a full-time GRC manager that had been posted for nine weeks. Two finalists had already taken other offers. Nobody on their security team had been through a Type II before, and what they actually needed was not a manager at all. It was somebody who had assembled that evidence package eleven times and could walk in on a Monday, read the control matrix for an afternoon, and tell them which of their forty controls were going to fail before the auditor ever opened a laptop.
One thing about my seat, so you can discount for it. KORE1 bills on both sides of this call, contract and direct hire, so nothing I recommend here moves my number one way or the other. A fair number of the teams I talk to should hire full time and run the search themselves. I say so more than once below.
If you want the menu of engagement models while you read, our cybersecurity staffing practice lays out how contract, contract-to-hire, and direct placement each work in a security org. This piece is the decision that comes before the menu.

Why the Standard Test Fails in Security
Bounded work is easy to spot in most of IT. There is a go-live date. Something ships, the team exhales, the contractor rolls off.
Security has almost none of that shape. The SOC runs on Christmas. Vulnerability management is a treadmill with no off switch. Identity governance is a permanent argument with your own HR system. Run the honest version of the “does it end” test across a security org and every single function comes back the same way. Hire. Permanently. All of it.
Then you carry that answer into a budget meeting. It does not survive the room.
The 2025 ISC2 Cybersecurity Workforce Study found 36% of organizations absorbed security budget cuts in the previous twelve months, 24% went through security layoffs, and 39% were operating under a hiring freeze. Fifty-nine percent cited critical or significant skills needs, up from 44% a year earlier. The demand did not soften. The ability to answer it with headcount did.
ISACA’s numbers say the same thing from the other side of the desk. Its State of Cybersecurity 2025 research found 65% of organizations carrying unfilled security positions, and 55% describing their own teams as understaffed. When they do get a req approved, 39% say a non-entry-level role takes three to six months to fill.
Six months. Your auditor is not waiting six months.
Here is the part of the ISC2 study nobody quotes. It also asked what teams did about the skills they were missing, and the answers were not headcount. Twenty percent outsourced the work outright. Another 19% brought in a third-party provider, and 17% simply hired temporary contractors to close the gap. Roughly one team in six had already resolved this question before you sat down to think about it.
Two Questions That Hold Up
Retire “does the work end.” Replace it with these two.
Does someone have to own it, or does your team have to survive it?
Ownership means accountability that outlives the project. Somebody answers when the auditor asks who approved the exception, when the board asks who accepted the risk, when a regulator asks for a name. That person belongs on your payroll. Not because a contractor could not do the work, but because accountability has to sit somewhere it cannot roll off in ninety days.
Survival works differently. It is a window. Get through the assessment. Get through the migration. Get through the eight weeks after the incident, or the quarter when two analysts left at once. Buying capacity through a window is the thing contract talent is genuinely excellent at, and it is the least controversial money you will spend all year, because the end date is written into the engagement rather than negotiated later with somebody’s manager.
Has your team done this exact thing before?
Not “could they figure it out.” Have they done it.
First SOC 2 Type II. First migration off Splunk onto Microsoft Sentinel. First FedRAMP package. First real incident with outside counsel on the bridge. First identity consolidation into Okta after three acquisitions left you with four directories and no map. Every one of those carries mistakes that only surface the first time through, and every one of them has people walking around who already made those mistakes on somebody else’s budget. For the first item on that list, Kris Drouet has written up what a first SOC 2 Type II cycle actually asks of the engineering team.
You cannot grow that on your timeline. You can rent it this month.
The Bursts Worth Buying Outside
Audit and certification windows. SOC 2 Type II, PCI DSS, HITRUST, the ISO work that shows up the week a European deal gets serious. Evidence collection is finite, genuinely miserable, and several times faster in the hands of someone who has built the package before, because the hard part was never the control itself but knowing which artifact your particular auditor will accept as proof that the control exists.
Incident surge is the one teams wait too long on. SEC rules now require public companies to disclose a material cybersecurity incident on Item 1.05 of Form 8-K, generally within four business days of determining that it is material. Your responders cannot run the investigation, brief counsel, and produce filing-grade narrative at the same time. Something gives. It is almost always the investigation.
Tool migrations. A CrowdStrike Falcon rollout across four thousand endpoints. A SIEM cutover with eighteen months of retained data behind it. Somebody who has run that migration five times finishes in a third of the time, and does not have to rediscover on your budget that ingest licensing prices what you send rather than what you keep, which is the detail that turns a clean cutover into an unbudgeted quarter.
Then there is the specialist you would use twice a year. Red team. ICS and OT assessment. Cryptography review. Cloud detection engineering deep enough to write real rules against GuardDuty and Defender output instead of shipping the vendor defaults and hoping. Hiring that person full time means paying them to be bored for ten months, and bored specialists leave. Usually right before you need them.
Coverage belongs on this list too. It gets its own section, because the arithmetic surprises people every time.
Coverage Math Before Headcount Math
A week has 168 hours. One chair staffed continuously, at forty hours per person, is 4.2 people before anyone takes a vacation.
Add PTO, training, on-call recovery, and the turnover security operations is famous for, and the honest number to keep a single seat warm around the clock lands at five to six. Five people. One chair.
| Coverage you need | People at 40 hours | What it actually takes |
|---|---|---|
| One seat, business hours | 1 | 1, plus somebody who can cover vacation |
| One seat, 16 hours a day, weekdays | 2 | 2 to 3 |
| One seat, 24/7/365 | 4.2 | 5 to 6 after PTO, training, and turnover |
O*NET, published by the U.S. Department of Labor, puts the 2025 median wage for information security analysts at $129,180, with 182,800 people employed in 2024 and growth projected much faster than average through 2034. Your Tier 1 seat probably sits below that median. It does not matter much. Five bodies is five salaries, five benefit loads, and five people you have to keep engaged in a job that is mostly quiet right up until it is not.
That arithmetic is why most mid-market teams end up buying nights and weekends and hiring the day shift. It is usually the correct answer, and it is almost never the one in the original headcount plan.

Where Contract Security Talent Quietly Costs More
Two of these are obvious. The other two show up in month four, which is why they are expensive.
Privileged access. Every security contractor you bring in gets keys, and not the read-only kind. Domain admin. SIEM administration. EDR console. Sometimes the identity provider itself. The real onboarding cost is not the bill rate, it is the scoping, the access review, and an offboarding that has to actually happen on the last day rather than four months later when someone finally runs the report.
Environment knowledge is the second one and it is larger than people expect. Detection tuning is mostly knowing which alerts are normal here. Which service account hammers a domain controller every night at 2 a.m. because a batch job from 2019 never got retired. A contractor rebuilds that map on every engagement, and on a short engagement they never finish building it.
On-call ownership. Route the pager to a contractor and you have outsourced judgment, not just labor. With a mature provider and a real runbook, that can work fine. More often it is a decision nobody made on purpose, and it surfaces at 3 a.m. when somebody six weeks into your network has to choose between isolating a production host and waking a director who did not know they were the escalation path.
Last one is the rebuild tax. An engagement that ends with no knowledge handoff costs you the entire thing twice, and you pay the second bill in a worse quarter than the first.
Some Security Roles Have a Name on Them, and Regulators Check
This is where security genuinely parts ways with every other staffing decision, and where I watch sharp teams get caught out.
The HIPAA Security Rule does not ask you to have a security function. It says to identify the security official who is responsible for the development and implementation of the policies and procedures required by the rule. Identify. One official. A person with a name.
New York’s financial regulator goes further, in a direction that surprises almost everyone. Under 23 NYCRR 500.4, the CISO may be employed by the covered entity, one of its affiliates, or a third-party service provider. A fractional CISO is explicitly permitted by one of the most demanding cybersecurity regimes in American financial services. There is a condition attached, and it is the whole point. The covered entity retains responsibility for compliance and must designate a senior member of its own personnel responsible for direction and oversight of that third party.
Read the condition twice. The regulator will let you contract the expertise. It will not let you contract the accountability.
Public companies get a version of the same instruction from the SEC, where Regulation S-K Item 106 requires an annual description of the processes for assessing, identifying, and managing material cybersecurity risk, along with management’s role in it. Boards read that section closely. Boards ask who.
Practically, this sorts cleanly. The work can be contract. The officer of record cannot. If you need senior security judgment before you can afford the title, a fractional arrangement is a legitimate bridge rather than a dodge, and we structure them through our CISO staffing practice with an internal name attached from day one.
What to Buy for Which Work
| The work | Usual right answer | Why |
|---|---|---|
| First SOC 2 Type II or PCI DSS readiness | Contract | Finite window, and the value sits entirely in having done it before |
| Control monitoring after certification | Hire | It repeats forever and somebody owns the evidence trail |
| SIEM or EDR migration | Contract | Bounded, painful, and dramatically faster with repetition behind it |
| Day-to-day detection tuning | Hire | Most of the skill is knowing your environment, not the tool |
| Incident response surge | Contract | Demand spikes far past what a sane headcount plan would carry |
| Security architecture for a platform you own | Hire | The decisions outlive the engagement by years |
| Red team, OT assessment, cryptography review | Contract | Used twice a year, and specialists leave when they get bored |
| Compliance officer of record | Hire | Regulators want a name, and usually one on your own payroll |
| Night and weekend SOC coverage | Contract or managed | The coverage arithmetic above rarely survives a budget review |
| Cloud security program, build then run | Contract to build, hire to run | The build ends. The run does not. |
Scope the Access Before You Scope the Hours
The engagements that work share four things, and the ones that fall apart are usually missing the same four.
Name the internal owner before day one. Not the executive sponsor. Not a committee. The owner, meaning the person who reviews output weekly and holds the decisions when the contractor is gone.
Time-box privileged access to the engagement, and review it on a cadence you will actually keep. Standing access granted for a ninety-day project is still live at month eight far more often than anybody wants to say out loud.
Make the runbook a priced, dated deliverable in the statement of work rather than a courtesy you hope for in the final week. Detection logic, tuning rationale, false-positive history, the reasoning behind every suppression. If all of that lives in one contractor’s head, you bought a rental and filed it as a build.
Write down the exit criteria. “The Type II report is issued” is exit criteria. “Until we feel better about our posture” is a subscription.
And decide early whether this is a trial. If the honest answer is that you want to hire this person and cannot get the headcount until January, say that at the start. It is contract-to-hire, it is completely normal in security, and structuring it that way in week one beats an awkward conversation in month five. The mechanics of how contract staffing engagements get priced and governed apply here the same as anywhere else in IT. Security just raises the stakes on the access paragraph.

Before You Open a Req or Sign a SOW
Is a fractional CISO actually allowed under our regulators?
In the strictest US financial regime, yes. NYDFS Part 500.4 permits a CISO employed by a third-party service provider, as long as you retain compliance responsibility and name a senior internal person to direct and oversee them.
Healthcare reads tighter in practice, because HIPAA’s language points at an identified official inside the covered entity rather than at a service. Check with counsel before assuming your framework works like New York’s. Most of them do not.
We got breached Tuesday. Can staffing even move that fast?
Submittals in days rather than weeks, for surge work specifically. Incident and remediation contractors come off a bench that exists precisely because engagements end, which is not true of the direct hire market at all.
What slows a surge down is never sourcing. It is access provisioning and background checks. The teams that move fastest are the ones that settled their contractor onboarding path back when nothing was on fire, which means the access request template, the background check vendor, and the approver’s backup all got decided in a quarter when nobody needed them. For reference on the other side of the comparison, our average time to hire across IT roles runs 17 days, against the three to six months ISACA’s respondents report for a non-entry-level security req. Those are two different conversations and they should be budgeted as two different conversations.
Contractors in the SOC. How do we handle privileged access?
Scope it to the engagement, review it weekly, and set the revocation date on the same day you set the start date. Treat the access review as a deliverable with a name against it, not an afterthought.
The practical version. Separate named accounts, never shared credentials. Session recording on administrative consoles. One internal person who can list every contractor holding elevated rights without looking it up. If nobody can produce that list from memory, the number is higher than you think it is.
Our board wants headcount, not vendors. How do I frame it?
One seat staffed around the clock costs 4.2 people at forty hours each, before anybody takes PTO. Boards follow a number they can multiply far better than they follow a staffing philosophy, so lead with the arithmetic.
Then show what the headcount is being protected for. Boards rarely fight contract capacity once the permanent roles on the request are visibly the ones carrying accountability, and the argument you were bracing for usually collapses into a much shorter conversation about which line item pays for nights and weekends.
Does contract security talent cost more per hour than an employee?
Per hour, yes, and usually by a meaningful margin. Per outcome it depends entirely on whether the work is continuous, because a salary costs you fifty-two weeks whether the audit window is open or shut.
Run it against real utilization instead of the rate card. Nine weeks of specialist work at a contract rate beats a salary you carry all year for a skill you use twice. If you need a starting point for the salary side of that math, our salary benchmark tool and the cybersecurity engineer salary guide both carry current bands.
When is contract-to-hire the wrong answer?
When the role needs a clearance you do not sponsor, or when accountability starts on day one. A compliance officer of record cannot spend six months on trial while a regulator waits for a name.
It is also wrong when you are using it to avoid a decision. Contract-to-hire earns its keep when you genuinely cannot assess fit from an interview loop. It works badly as a way to postpone an approval you already suspect you will not get.
The Call I Would Make
Write down the security work sitting in front of you for the next two quarters. Beside each line, answer one question. Does somebody need to own this after it is finished?
Every yes is a hire. Every no is a candidate for contract, and the ones your team has never done before are the strongest candidates on the page.
Most mid-market security orgs I talk to land near the same shape once they run it. A small permanent core that owns the program and answers for it, wrapped in contract capacity that flexes around audits, migrations, incidents, and coverage. Not because the shape is clever. Because the alternative is a hiring plan finance will not approve against a calendar that does not care.
If you want a second read on where a specific role belongs, bring the list to our recruiting team. The people who would run these searches have averaged fifteen years on the desk, 92% of our placements are still in the seat at twelve months, and the first conversation is about which of your lines are genuinely hires.

