Your First Security Hire Won’t Save You
In Part 1, we looked at the compliance gap that quietly disqualifies startups and SMEs from enterprise contracts. Certification opens procurement gates. That much is clear. But here’s the problem most founders hit next: they decide to “do security properly,” post a job advert for a security lead, and discover that the talent market has other plans.
The ISC2 2024 Cybersecurity Workforce Study puts the global shortage at 4.8 million professionals. In the UK alone, the Department for Science, Innovation and Technology estimates that 44% of businesses lack the basic technical skills needed to manage their own cybersecurity. For a company turning over £2m to £15m with between twenty and a hundred employees, the maths doesn’t work. A capable head of security commands £90,000 to £140,000 in the current UK market. A CISO with genuine enterprise experience will cost north of £150,000 before benefits. And even if the budget is there, the candidate probably isn’t. They’re embedded at a bank, a defence prime, or a well-funded scale-up that can offer equity, a team to manage, and problems worth solving.
So the founder does what most founders do. They hand security to the CTO, the head of IT, or whoever volunteered least reluctantly. The result is predictable. Security becomes a side project for someone already running at full capacity. Compliance certificates get achieved but not maintained. Incident response exists as a document nobody has tested. The firewall was configured eighteen months ago and hasn’t been reviewed since.
This isn’t negligence. It’s a structural problem. And solving it requires a fundamentally different approach to how growing businesses think about building security capability.
The three models that actually work
There is no single answer. But there are three models that work at different stages of growth, and the smartest companies layer them rather than choosing one.
Model one: managed security. For companies under fifty employees, outsourcing the technical security function to a managed security provider is almost always the right starting point. A competent managed service delivers 24/7 monitoring, endpoint detection and response, vulnerability management, and incident handling for a fraction of what a single hire would cost. Hiscox’s 2024 Cyber Readiness Report found that UK SMBs spend a median of £22,000 per year on cybersecurity. A well-scoped managed security engagement sits comfortably within that budget and covers more ground than any one employee could.
The trap here is treating managed services as a replacement for internal ownership. Someone inside the business still needs to own the relationship, interpret the outputs, and make decisions when the provider flags a risk. Managed security handles the technical execution. Strategic direction still needs to live in house.
Model two: the fractional CISO. Between fifty and two hundred employees, the complexity increases. Regulatory obligations multiply. Customers start asking for evidence of board-level security oversight. ISO 27001 auditors want to see named accountability. This is where a fractional or virtual CISO earns their fee.
A fractional CISO typically costs between £2,000 and £6,000 per month, depending on scope and seniority, compared to £150,000 plus for a full-time equivalent. They provide strategic oversight, board reporting, policy development, and audit readiness without the overhead of a permanent C-suite hire. The UK National Cyber Security Centre has been encouraging this model for mid-market organisations since 2023, recognising that most companies at this stage need strategic direction more than they need another pair of hands on the firewall.
The value isn’t just cost. It’s speed. A fractional CISO with twenty years of enterprise experience can stand up a governance framework in weeks that would take a first-time security hire months to design from scratch. They’ve seen the patterns, they know which controls actually matter for your industry, and they can prioritise ruthlessly.
Model three: the first dedicated hire. Beyond two hundred employees, or once the business is handling regulated data at scale, a full-time security leader becomes necessary. But even here, the approach matters. The most effective first hires are not the most senior candidates. They are mid-level security professionals, typically with five to eight years of experience, who can operate across both technical implementation and governance. Someone who can configure a SIEM and write a board paper. Someone comfortable running a penetration test and presenting findings to a non-technical audience.
The DSIT 2024 Cyber Security Skills report highlights that the hardest roles to fill are exactly these hybrid profiles. Pure technical specialists exist. Pure governance professionals exist. The person who bridges both is genuinely scarce, and finding them requires a recruitment partner who understands where those candidates sit and how to engage them.
The tooling question: what actually matters
Every vendor in the cybersecurity market will tell you their product is essential. Most of them are wrong, at least for a company at your stage. The practical baseline for a business moving from startup to scale-up is simpler than the industry would have you believe.
Endpoint detection and response is non-negotiable. Not antivirus. EDR. The difference is the gap between a smoke alarm and a monitored fire suppression system. CrowdStrike, SentinelOne, and Microsoft Defender for Business all offer credible options at different price points. NCSC’s own guidance recommends EDR as a minimum for any organisation handling sensitive data.
Identity and access management matters more than most founders realise. Gartner’s 2024 analysis found that 74% of breaches involving a human element start with compromised credentials or social engineering. Multi-factor authentication across all business-critical applications, a single sign-on provider, and a clear joiner-mover-leaver process will prevent more incidents than any other single investment.
Email security, specifically anti-phishing and domain authentication (DMARC, SPF, DKIM), is the third priority. Proofpoint’s 2024 State of the Phish report found that 71% of UK organisations experienced a successful phishing attack in the preceding year. For a growing business, one compromised email account can lead to invoice fraud, data exfiltration, or a ransomware deployment that takes the entire company offline.
Backup and recovery is the safety net. Not a product. A tested process. IBM’s 2025 Cost of a Data Breach Report found that organisations with incident response plans and tested backups reduced breach costs by an average of £1.49 million. The key word is tested. An untested backup is not a backup; it’s a hope.
Everything else (the SIEM platforms, the SOAR tools, the zero-trust architectures, the AI-powered threat intelligence feeds) can come later. They matter at scale. They don’t matter when you have thirty employees and a compliance audit next quarter.
Matching capability to stage
The mistake most companies make is trying to build the security function they’ll need in three years rather than the one they need now. Security capability should scale with the business, not ahead of it.
At the startup stage, under fifty employees, the priority is foundational hygiene: managed EDR, MFA everywhere, email security, tested backups, and Cyber Essentials certification. Total annual spend: £15,000 to £30,000 including the managed service provider. This covers more than 80% of the attack surface that matters at this stage.
At the scale-up stage, fifty to two hundred employees, add a fractional CISO, formalise policies, begin the ISO 27001 journey, introduce security awareness training, and implement proper access management. Total annual spend: £40,000 to £90,000. This positions the business to win enterprise contracts, satisfy investor due diligence, and demonstrate regulatory readiness.
At the growth stage, beyond two hundred employees, bring in a dedicated security leader, build a small internal team (security engineer plus GRC analyst), deploy a SIEM, and move towards continuous compliance monitoring. Total annual spend: £200,000 to £400,000. At this point, the security function is no longer a cost centre. It’s a competitive asset that directly enables revenue.
Where recruitment fits
There is a pattern we see repeatedly across the market. A company reaches the point where it needs its first full-time security hire, posts the role, and receives either no credible applications or a flood of candidates who look right on paper but lack the hybrid skills the business actually needs.
The cybersecurity talent market is unlike almost any other function. The ISC2 study estimates a UK workforce gap of approximately 73,000 professionals. The best candidates are not on job boards. They’re not actively looking. They’re embedded in organisations where they’re valued and well compensated, and reaching them requires a specialist approach that goes beyond posting on LinkedIn and hoping.
This is where the combination of managed services, advisory, and specialist recruitment creates the most value. A managed service provider handles the technical execution while a fractional CISO sets the strategic direction. When the business reaches the point where a permanent hire is justified, a specialist recruiter who understands the security market, who knows where the hybrid profiles sit and what it takes to move them, can compress what would otherwise be a six-month search into weeks.
The commercial case
Part 1 of this series made the argument that cybersecurity is a growth enabler, not a cost. Part 2 makes the practical case. Building a security function doesn’t require a six-figure hire on day one. It doesn’t require a twenty-person SOC or a seven-figure technology stack. It requires a phased, commercially pragmatic approach that matches capability to the stage of the business.
The companies that get this right don’t just protect themselves from breaches. They build a security posture that actively opens doors: procurement gates, investor confidence, insurance savings, and the credibility to compete for contracts they would otherwise lose.
The deals are there. Part 1 showed how to clear the compliance gate. This is how you build the capability to stay on the other side of it.
Ready to build your security capability?
A focused conversation about where you sit on the capability curve, which model fits your stage, and how to get there without overspending.
Discuss More →Sources: ISC2 Cybersecurity Workforce Study 2024 · DSIT Cyber Security Skills in the UK Labour Market 2024 · Hiscox Cyber Readiness Report 2024 · IBM Cost of a Data Breach Report 2025 · Gartner Identity and Access Management Analysis 2024 · Proofpoint State of the Phish Report 2024 · NCSC Guidance for Small and Medium Organisations 2024 · UK Government Cyber Security Breaches Survey 2025
Garzon Cyber Solutions specialises in cybersecurity, compliance, and specialist technology recruitment for startups and SMEs scaling into enterprise markets.
Part 3 of this series will examine what boards and investors actually want to see when they assess cyber risk, and how to present security as a board-level asset rather than a technical footnote.