You have reached the point where security in your company needs an owner with a name attached to it. Until now the decisions have been split between your IT provider, whoever keeps the systems running and you, and every time a client sends a security questionnaire it becomes obvious that nobody holds the whole picture. The question that follows is always the same: do you hire a CISO in house or work with an external CISO? This guide gives you the criteria to decide it under the real conditions of an SME with 10 to 50 employees.

What you are actually buying in each option

Hiring in house buys you one person's full working day: their daily availability, their inside knowledge of the business and their attention focused on a single company. Working with an external CISO buys you a fraction of a senior professional's time, backed by the team behind them and by the experience of having solved the same problem in companies much like yours.

The comparison goes wrong when it collapses into "a whole person versus half a person". What you are really comparing is how many correct security decisions each euro buys you over the next year, and how long each option takes to produce the first one.

The real cost of an in-house hire

Gross salary is the visible line and the one that generates least discussion in a board meeting. The lines that usually get left out of the budget are the others:

  • Employer social security contributions, which sit on top of the agreed gross figure.
  • The hiring process itself: management time, recruiter fees if the profile proves hard to find, and the weeks the role stays empty while you search.
  • Training and certifications to keep the profile current, because security knowledge expires and refreshing it costs money and hours.
  • Tooling: asset inventory, vulnerability scanning, credential management. Someone has to license it and maintain it.
  • External providers anyway: penetration testing, incident response and audits still get subcontracted, because one person does not execute all of that.

That last point is what breaks most budgets. Hiring a CISO in house reduces the consulting bill, it does not remove it. Do the full exercise and the annual cost of the internal option includes salary, contributions, tooling, training and a budget line for specialist services that your hire will coordinate rather than deliver personally.

Availability and time to first result

A security professional with genuine experience is rarely available immediately. Between defining the role, finding candidates, negotiating and waiting out their notice period, the clock runs in months. Then comes onboarding: learning your systems, your suppliers, your contracts and your priorities. Nobody produces useful decisions in week one.

An external CISO arrives with a proven method and starts from the same discovery phase, with one practical difference: they have run it many times and know what to ask first. The concrete functions of an external CISO set out in detail what gets delivered in the first ninety days.

There is another availability issue that planning tends to skip: one person takes holidays, gets ill and gets pulled into other internal projects. During those weeks your company's security has no owner unless somebody covers it. A contracted service covers absence by design.

Coverage: what one person cannot span

Company cybersecurity plays out across fronts that demand different profiles: governance and regulatory compliance, systems architecture, vulnerability management, offensive testing, incident response, staff awareness, and handling clients who audit their suppliers. Nobody masters all seven at the same level.

When you hire one person, what you are really choosing is their specialism. If they come from the technical side, your systems will be better configured and your board presentations weaker. If they come from the compliance side, your documentation will be immaculate and your network configuration will go unreviewed. That asymmetry is normal, and it is exactly why large companies surround their CISO with a team.

An external service distributes those fronts across several people and gives you the profile you need at each moment, without expanding headcount every time the priority shifts.

What breaks the day that person leaves

This is the scenario almost nobody evaluates before signing the employment contract. Your internal CISO has been there eighteen months, knows every exception in every system, has built the relationships with suppliers, and carries a good share of the judgement in their head. One day they accept another offer.

What stays behind is the licensed tooling and whatever documents they had time to write. What walks out is the context: why that risk was accepted, what was promised to the client who sent the questionnaire, what was still outstanding on the plan. And you are back at the start of a hiring process, this time with less room to manoeuvre because the work was already under way.

With an external service, continuity is a contract clause. Documentation is the deliverable rather than an extra that happens if there is spare time, and the knowledge lives with the provider. Changing provider also has a cost, with the difference that you can specify in writing what you take with you when the relationship ends.

When hiring in house is the right call

The internal option wins clearly in several situations, and they deserve recognition:

  • Security is part of what you sell: you build software, you handle sensitive third-party data, or your product gets audited as part of the sales process.
  • You already have your own IT team to direct. A CISO with nobody to execute their decisions turns into a report generator.
  • The workload fills a full day consistently, rather than in two-week bursts once a quarter.
  • A significant contract or your sector requires a named internal owner, present in client meetings on a continuous basis.

If you sell to the public sector or sit in the supply chain of a public-sector contractor, Spain's Esquema Nacional de Seguridad (Real Decreto 311/2022) adds continuous governance obligations worth factoring into the decision. The same logic applies to companies receiving requirements derived from the NIS2 directive through their larger clients.

How to decide, in six questions

Answer these six questions in writing before the meeting where the decision gets made. The result is usually clear without needing a debate:

  1. How many hours of security work does your company realistically generate per week?
  2. Do you have someone to execute what gets decided, or would you need to hire that part too?
  3. What is your full annual cost for the internal option, contributions, tooling and training included?
  4. How long can you wait before the first improvement is actually applied?
  5. What happens to your security programme if that person leaves within a year?
  6. Which fronts do you need covered next quarter, and which profile covers them best?

Most SMEs with 10 to 50 employees discover, once they run this calculation, that the workload does not fill a full day while the range of profiles needed exceeds what a single hire can offer. That exact point is what the external CISO service exists for: security leadership sized to your company, without the risk of everything depending on one individual. If the work later grows enough to justify an internal hire, you will reach that decision with the ground already documented and with clear criteria for choosing the right person.

Want to know how exposed your website is?

Ciphraverse's Security Assessment checks websites, portals and e-commerce with a professional external audit designed for SMEs.

Discover Security Assessment