The First Security Hire Should Be The Third Decision.
Most growing companies make their first security appointment at the moment they feel the absence of one: a questionnaire they cannot answer, a buyer who asks who is accountable, an insurer who wants a name. The instinct is to hire a senior security leader and hand them the problem. Our view is that the hire should be the third decision rather than the first. A company that builds the operating foundations and obtains its certification before recruiting will hire a better person, at a lower cost, into a role that produces value in weeks rather than a year. The labour market this autumn makes that sequence unusually rewarding.
a basic cyber skills gap
an outsourced provider
Head of Information Security
on a year earlier
Situation
The pressure to appoint someone accountable for security now reaches smaller companies earlier than it used to. It arrives through enterprise questionnaires, through contract schedules and through insurance renewals, and in each case the counterparty wants to know who owns the answer. The government's Cyber Security Breaches Survey 2025/2026, published on 30 April 2026, found that 37% of small businesses and 52% of medium businesses have a board member or trustee with responsibility for cyber security, against 68% of large businesses. The buyers asking the question are, in other words, considerably more likely to have answered it for themselves.
The capability to respond is thin. The Department for Science, Innovation and Technology's report on cyber security skills in the UK labour market, published in September 2025, found that 49% of UK businesses have a basic technical cyber skills gap, meaning they lack confidence in tasks such as configuring firewalls, detecting malware or controlling user access, and that 30% have gaps in more advanced areas. The same survey of breaches found that 39% of small businesses and 51% of medium businesses use an external provider for some part of their cyber security. The remainder are managing it, to the extent they manage it at all, with people whose principal job is something else.
The labour market, meanwhile, has moved. DSIT recorded 32,370 core cyber security job postings in the UK in its most recent reporting year, a fall of 33% on the year before. Advertised salaries have followed. According to IT Jobs Watch, the median advertised salary for a permanent Head of Information Security in the six months to 21 September 2026 was £90,000, compared with £112,500 in the same period a year earlier. For the first time in several years, a growing company recruiting a security leader is not negotiating from a position of weakness.
Insight
The conventional reading of those figures is that now is the moment to hire. We think that reading is half right. The market is favourable, but a favourable market rewards the company that is ready to use the hire, and most smaller companies are not.
A senior security appointment made into a business with no managed controls, no documented policies and no certification spends its first year doing work that should have preceded it. It selects tooling, negotiates with providers, writes policies from a blank page and prepares for an audit. Each of those tasks is necessary. None of them requires a permanent executive at £90,000 or more, and several are performed faster and more cheaply by specialists who do them repeatedly. The ISC2 2025 Cybersecurity Workforce Study, published in December 2025 from a sample of 16,029 practitioners, found that 59% of organisations report critical or significant skills needs and that 88% had experienced at least one significant security consequence attributable to skills shortfalls. The shortage that matters is not headcount. It is the right skills applied at the right stage.
The analysis therefore points to sequence rather than timing. The question a founder should ask is not whether to hire a security leader, but what needs to be true before that hire can succeed.
Options
Three paths are realistically available to a company of between twenty and two hundred people.
The first is to hire a senior security leader now and ask them to build the function. This is the most familiar route and the one most often chosen under buyer pressure.
The second is to outsource the function entirely and indefinitely, relying on a managed security provider for technical operations and a fractional or virtual CISO for governance, with no internal owner.
The third is to sequence the build. Managed security and fractional leadership put the foundations in place first. Certification follows, typically Cyber Essentials and then ISO 27001 where the customer base requires it. The permanent hire comes last, recruited into a working system as its owner rather than its architect.
Trade-offs
Hiring first gives the company a name to put on a questionnaire immediately, which has real commercial value in a live procurement. It also commits a six figure fixed cost to a person whose first year is largely spent on procurement and documentation, concentrates the entire capability in one individual, and exposes the company to a difficult conversation if that individual leaves before the foundations are complete. In a smaller business, where one departure can reset a programme, that concentration is the principal risk.
Outsourcing indefinitely is the lowest fixed cost and provides coverage from the first week. Its weakness is accountability. Enterprise buyers, insurers and auditors increasingly expect to see a named internal owner, and a company that can only point to a provider will find that the question keeps returning. Knowledge of the company's own environment also accumulates outside the business, which makes any later change of provider more expensive than it needs to be.
Sequencing is slower to announce. There is no senior appointment to publicise in the first quarter, and the founder must tolerate a period in which accountability is shared between an internal sponsor and external specialists. In exchange, fixed cost is matched to the company's stage, the certification that unlocks procurement arrives sooner because specialists are doing the work, and the eventual hire is recruited against a defined role with running controls, rather than a blank page.
Recommendation
For most companies of this size, we recommend the third path, with a specific order. First, appoint an internal executive sponsor, normally the chief technology officer or chief operating officer, and put the technical foundations under a managed service: endpoint protection, identity and access, email security and tested backups. Second, bring in fractional security leadership to set policy, own the risk register and prepare for certification, and obtain Cyber Essentials within the first quarter. Third, once certification is in hand and the controls are running, recruit a permanent security owner, typically at manager rather than executive level, whose remit is to run and extend what exists. The executive appointment follows later, when the scale of the company or its regulatory exposure requires it.
Why
The commercial case rests on three points. The first is revenue. Certification and a documented control set are what enterprise procurement filters on, and a sequenced build reaches them faster than a single new hire working alone, which shortens the path to contracts that are otherwise closed. The second is cost. A permanent owner recruited into a working system is productive within weeks, and the role can usually be pitched below executive level, which matters when the market median for the executive role alone is £90,000. The third is timing. With core cyber postings down by a third and advertised salaries for senior roles falling, the next six to twelve months are an unusually good window to recruit, provided the company has something ready for that person to own. A company that spends that window building foundations will be ready to hire while the market still favours the employer.
Risks
Four things could undermine the approach. The labour market may tighten again before the company is ready to recruit, which would erode the cost advantage; the mitigation is to begin the search while certification is under way rather than after it. Fractional leadership can become a permanent dependency if the internal sponsor does not take genuine ownership; the mitigation is a fixed term and a defined handover. A certificate obtained without an owner decays, and the next renewal or questionnaire exposes it; the mitigation is to make the permanent hire's first objective the maintenance of what has been certified. Finally, the permanent hire can be the wrong profile. A company at this stage needs someone who can run controls and speak to buyers, not a specialist in a single discipline, and recruiting against a vague brief is the most common way that goes wrong.
Next Move
The practical starting point is a short assessment of where the company stands on each of the three stages: which controls are running and who runs them, what certification the next twelve months of pipeline will require, and what the eventual security role should look like. That assessment determines how much of the build can be handed to specialists now and when the hire should begin.
This is the work Garzon Cyber Solutions was built to do, in the order set out above. Security foundations are delivered with specialist technology partners. Compliance is mapped to what buyers, insurers and regulators actually ask for, with certification readiness from Cyber Essentials through to ISO 27001. The permanent security hire is recruited by us on contingency, so nothing is payable until the candidate accepts and starts, and the brief is written against a role that already exists in practice. We are a young firm, and we built it around the conviction that these three capabilities are worth more delivered as one sequence than bought separately.
Confidence note
Confirmed. That the Cyber Security Breaches Survey 2025/2026, published by DSIT and the Home Office on 30 April 2026, reports board level responsibility for cyber security at 29% of micro, 37% of small, 52% of medium and 68% of large businesses, and use of an outsourced cyber security provider at 27% of businesses overall, including 24% of micro, 39% of small and 51% of medium businesses. That DSIT's report on cyber security skills in the UK labour market, published on 19 September 2025, records 49% of businesses with a basic technical skills gap, 30% with an advanced skills gap, a workforce of approximately 143,000 and 32,370 core cyber job postings, down 33% on the previous year. That the ISC2 2025 Cybersecurity Workforce Study, published on 4 December 2025 from 16,029 respondents, reports 59% citing critical or significant skills needs and 88% experiencing at least one significant consequence. That IT Jobs Watch reports a median advertised salary of £90,000 for permanent Head of Information Security roles in the six months to 21 September 2026, against £112,500 a year earlier.
Assessed. That a senior hire made before foundations exist spends much of its first year on procurement and documentation is our assessment from the structure of the role, not a measured statistic. That the next six to twelve months represent a favourable hiring window is our reading of the posting and salary data; advertised salaries measure vacancies rather than agreed pay, and IT Jobs Watch figures reflect the roles advertised in that period. That enterprise buyers increasingly expect a named internal owner is our assessment from procurement and questionnaire practice.
Not known. Whether the fall in advertised senior salaries will persist into 2027. How long, on average, a first security hire takes to become productive in a company of this size; no independent UK figure exists. The proportion of UK growth companies that hire a security leader before obtaining any certification.
What would need to be true in your business before a security hire could succeed in its first ninety days?
Garzon Cyber Solutions puts the foundations in place with specialist technology partners, maps compliance to what buyers and regulators actually ask for, and recruits the person who will own it, on contingency. Cybersecurity, compliance and talent, delivered in that order, as one capability.
Start the Conversation →Sources: DSIT and Home Office, Cyber Security Breaches Survey 2025/2026, 30 April 2026 · DSIT, Cyber Security Skills in the UK Labour Market 2025, September 2025 · ISC2, 2025 Cybersecurity Workforce Study, December 2025 · IT Jobs Watch, Head of Information Security, six months to 21 September 2026