KEYSTONE CYBER

Home Disciplines CISO & security leaders

SECURITY LEADERSHIP

CISO & security leadership search

Security leadership searches are confidential, retained and slow by design. The wrong CISO costs an organisation two years, so we would rather spend six weeks getting it right.

Mandates we run

CISO
Full accountability for security strategy, risk posture and the board conversation.
HEAD OF SECURITY
Operational leadership below executive level, common in mid-size organisations and scaling businesses.
DEPUTY CISO
Succession and delivery depth in larger functions.
SECURITY PROGRAMME DIRECTOR
Time-bound transformation leadership — a maturity programme, a post-incident rebuild, a regulatory remediation.
INTERIM & FRACTIONAL
Experienced leadership on a part-time or fixed-term basis, where a permanent executive hire is not yet justified.

The question that decides the search

Most failed CISO hires come from a single unexamined assumption: that security leadership is one job. It is at least three. Building a first security function from nothing is entrepreneurial work — no budget, no team, everything to prove. Maturing an established function is institutional work — governance, metrics, regulatory relationships, slow change through other people. Recovering from an incident is crisis work, with a board that has lost patience.

The leaders who excel at one are frequently poor at another. So the first thing we establish is which of those jobs you are actually hiring for, and whether your organisation agrees with itself on the answer. Where the executive team and the board describe different mandates, that surfaces at briefing rather than at final stage.

How a retained search runs

We tell you what we think the risk is with each candidate. A shortlist where every candidate is described as excellent is a shortlist that has not been assessed.

South Africa and the UK

We run leadership mandates across South AfricaCape Town and Johannesburg — and in the United Kingdom, with most UK work in London.

Common questions

Are CISO searches confidential?

Almost always, and we run them that way by default. Incumbent CISOs are rarely on the market openly, and an incoming leader usually cannot afford a visible process. Nothing is advertised.

What is the difference between contingency and retained search here?

At leadership level, retained. A CISO search is a mapped, approached, assessed process over weeks, not a shortlist from an existing pool. Contingency economics do not support that work and we would rather say so than take the brief cheaply.

Do you place fractional or interim CISOs?

Yes. Interim and fractional leadership is common where an organisation needs security direction before it can justify a permanent executive hire, or needs cover during a search.

How do you assess a CISO candidate?

On the fit between what they have actually run and what you need built. A leader who matured a programme in a regulated bank is a different candidate from one who stood up a first security function in a scaling business. Both are strong; only one fits your brief.

Who should be involved from our side?

For a permanent CISO, whoever the role reports to plus at least one board or audit-committee voice, and ideally a technical peer. Searches that involve the board only at the final stage tend to restart.

Related disciplines

Discuss a confidential mandate

Leadership conversations start privately. Call or email the founding partner directly.