How much does a CISO cost in Switzerland? Honest figures

Why nobody gives you a clear number

Most articles on this topic dodge the question. What does a CISO cost? "It depends," "individual," "it is best if we talk first." Understandable, but it is of zero help to you when you are currently planning a budget.

So, here is the short version first. Realistically, a full-time CISO costs a Swiss SME well over CHF 200,000 per year, everything included. A CISO as a Service costs a clear fraction of that. And for most companies with 50 to 500 employees, the full-time position is not the right answer, but rather the unnecessarily expensive one.

Why this is the case, and how to find the right number for your own situation, is what this is all about. No fear-mongering, no framework bingo, just real numbers.

The full-time CISO: the number nobody likes to say out loud

Let's start with what you actually need to compare.

Public salary data for Switzerland shows an average basic salary of around CHF 154,800 per year for a Chief Information Security Officer, with a range that goes up to over CHF 290,000 depending on experience and industry (Source: Salary data jobs.ch). And that is only the basic salary.

On top of that comes what is often forgotten in such comparisons. Social security contributions, pension fund, bonus, holidays, further training, a workplace. In our experience, the total employer cost is therefore significantly higher than the pure gross salary figure, often an extra 20 to 30 percent. So expect a total cost of over CHF 200,000 for an experienced specialist, and in many cases closer to CHF 250,000.

And then the person is simply there. They need to be kept busy. But in an SME with 120 employees, there is rarely 42 hours of CISO work per week. There are phases with a lot of work (an audit, an incident, a certification) and long phases with little. You pay fully for the full-time position during both phases.

That is the real point. A full-time CISO is not too expensive because the salary is high. He is expensive because most of it finances idle time. You are buying capacity that you only really need for a few weeks a year.

Adding to that the second, uncomfortable reality: you have to find this person in the first place. Experienced security managers are rare on the Swiss market, the search takes months, and many SMEs are simply not attractive enough for the good candidates. A vacant full-time position protects no one.

CISO as a Service: what you are actually paying for

This is where it gets interesting, because many people confuse CISO as a Service with "consulting on an hourly basis." That is not what it is, and the difference determines the value.

With the classic consulting model, you buy hours. Someone comes, works on a topic, writes an invoice, and leaves. The responsibility remains with you.

With CISO as a Service, you buy the opposite. Someone takes over security responsibility as a role. They sit in your management meetings, know your risks, speak with your board of directors, manage your service providers, and make the decisions for which nobody else internally has the expertise. Just not full-time, but to the extent that your business actually needs.

That is why CISO-as-a-Service costs are also structured differently. You usually pay a fixed monthly retainer for a defined scope, not per hour. This makes the expenditure plannable, and it uncouples the price from physical presence. Good security is not measured in hours of presence.

What does such a month look like? A fixed rhythm of appointments (management meeting, IT coordination, risk review), reachable for decisions in between, and a clear mandate when there is an emergency. No desk that needs to be occupied eight hours a day. Exactly the role an SME needs, without the baggage it doesn't need.

What the difference between Fractional CISO, vCISO, and CISOaaS is in detail, we have written down separately. For the cost question it is enough to know: you pay for responsibility and judgment, not chair time.

What really drives the price (not the hours)

When companies ask us for a price, they expect an hourly rate. But that is the wrong lever to pull. Four things determine what a CISO as a Service actually costs.

How regulated your industry is. A financial service provider under FINMA supervision or a supplier with ISO 27001 requirements needs more steering than a trading company with no external requirements. More requirements mean more scope and therefore higher costs. That is fair because it follows real demand.

Where you currently stand. A company starting from scratch needs more leadership in the first few months than one that just wants to keep an existing function stable. Setting up costs more than operating, but only temporarily.

How much is already available internally. Do you have an IT department that pulls its weight, or does the CISO have to initiate every measure themselves? The more substance there is internally, the leaner the external share will be.

Whether a certification or an audit is coming up. Building an ISMS or an upcoming recertification creates more work for a few months. A reputable provider will scale the scope back down afterward, instead of keeping it permanently high and charging you for it.

Remember one thing: a good offer scales with your real needs, both up and down. If someone wants to sell you a fixed, high scope, even though your situation does not justify it, that is exactly the overpaying that we constantly see in SMEs. A CISO who does not want to reduce their own scope when they are no longer needed is not working for you.

When which model is worthwhile

No ideology, just a few practical rule-of-thumb principles.

A full-time CISO is worthwhile if security permanently creates full-time work for you. This is realistic above a certain size, with high regulation, or if security is part of your product. For the majority of Swiss SMEs, this is simply not the case, and that is not a weakness, but a sober observation about the actual workload.

A CISO as a Service is worthwhile if you need security leadership, but cannot sensibly fill a 100 percent position. You want someone to set the direction, keep the tool stack under control, and make decisions in an emergency, without carrying a full-time salary plus overheads.

There is also the middle ground, and it is often overlooked. An external CISO builds up the function, sets the direction, brings order to the stack, and hands over after one to two years to an internal person who then manages the ongoing operation more cheaply. You only pay for the expensive experience during the phase in which you really need it, and use the matching, leaner model afterward. For growing companies, this is often the most cost-effective option of all.

And sometimes the honest answer is: none at all yet. If you do not know where you stand, the first step is not a CISO, but a sober inventory. Otherwise, you are buying leadership for problems you haven't even named yet. How to distribute your security budget correctly before you even fill a role is a topic in itself, and usually the more rewarding one.

The most expensive option is neither of the two

Now for the part that the salary comparisons overlook.

The most expensive option is not the full-time CISO and not the external one. It is the state in which nobody really has the role, but everyone pretends they do. The IT department wears the security hat on the side, buys one tool after another, and nobody decides what brings real protection and what only burns budget.

We see this in almost every inventory. Three tools for one job. Licenses for features that were never configured. An annual pen test whose report no one ever reacted to. This adds up, often to more than a CISO would cost, only distributed, invisible, and without anyone taking responsibility for it. Why IT operations alone does not replace a security strategy is described in more detail elsewhere.

An example from practice, anonymized: a medium-sized company, a good two dozen security and monitoring tools, three different providers overlapping in tasks. Nobody could say which tool covered which risk. The first job was to sort out the wild growth, cancel duplicates, and finally configure the remaining tools correctly. The result: fewer contracts, less complexity, and for the first time a clear statement about what is actually protected.

A CISO, whether full-time or as a Service, usually earns their money right there first. Not through more spending, but by cutting the wrong spending. More protection for less money is not a slogan for us, but simply what happens when, for the first time, someone with competence and a mandate organizes security spending. In our experience, the role often pays for itself to a large extent in the first few months, simply through what is not renewed afterward.

The next step

Before you think about hourly rates or retainers, answer a single question: How much security leadership does your business actually generate, week after week?

Answered honestly, this question almost always shows you the right model. and it prevents the most expensive mistake, namely filling a position to ease a feeling rather than to solve a problem.

If you can't work out the number for your situation with certainty, we can calculate it with you in a initial, free consultation. No pitch, no obligation, just an honest assessment of what your business really needs.