What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Some security leaders choose consulting for greater autonomy, a chance to work across several organizations, and the possibility of applying their experience more broadly. But the move is not simply a change of employer: independent and fractional consultants also have to win clients, run a business, and influence decisions without the authority an in-house CISO may hold. Surveys document pressure in the CISO role, but they do not show how many leaders who leave go on to consult.
Why do security leaders choose consulting?
The clearest explanations come from practitioners who have made the move. They describe wanting more control over their work, variety across clients, and a wider reach for their security expertise. Those are individual accounts, not evidence that most CISOs share the same motivation.
More autonomy and variety
Consulting can mean engaging with several organizations instead of concentrating on one employer. Antanas Kedys, founder and CEO at ACyber, described the appeal this way: “Consulting gives me more autonomy and control over how I work, while still letting me apply the same strategic approach to improving resilience, governance, and practical security execution.” The amount of autonomy depends on the arrangement: an independent consultant may set more of the terms, while a firm or client still shapes the work.
A chance to extend impact
Working across clients can let a consultant address similar challenges in different settings. Nikoloz Kokhreidze, founder of Mandos, said: “I was solving the same problems repeatedly in one company,” he says, “when I could solve them for multiple companies simultaneously, multiplying my impact and helping more businesses grow through pragmatic security leadership.” That is one practitioner’s rationale, not a measured impact comparison between consulting and in-house work.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →#1 Best Overall
Role pressure is context, not proof of a career trend
Several surveys describe strain or concerns around CISO work, but their findings measure different things. Trellix’s vendor-sponsored 2024 survey of more than 500 CISOs across the Americas, Europe, the Middle East, and Asia Pacific found that 91% agreed expanding responsibilities would lead to higher turnover in the role; 49% said they did not see a future as a CISO; and 84% believed the role should be split into technical CISO and business-focused BISO functions. These are respondents’ views, not observed departures or evidence of consulting transitions. Trellix’s survey announcement describes the study.
In a separate survey commissioned by Devo and fielded by Wakefield Research from February 20 to March 1, 2024, 32% of 200 CISOs at organizations with at least $500 million in revenue said they had thought about leaving because of the changing threat and regulatory environment. That measures consideration, not departure or next job. The Devo announcement gives the sample and field dates.
Other evidence has narrower scope. A 2024 Deloitte-NASCIO study of state CISOs reported a median tenure of 23 months; it reflects state-government roles, not private-sector CISO careers. The study covers all 50 states and the District of Columbia. IANS and Artico Search’s public 2025 guide, drawing on more than 800 CISO responses to its 2024 survey, describes typical time in the top CISO role at the same company as two to three years; detailed findings require a report download. The public guide summarizes that work.
None of these figures establishes how many security leaders leave full-time executive roles specifically to become consultants. Broader workforce studies, including ISC2’s 2024 study, concern cybersecurity workers generally rather than CISO career transitions. ISC2’s research page provides its workforce-study materials.
Recommended Free Tools
What kinds of consulting work can a security leader do?
“Consulting” can describe different jobs and business arrangements. The right comparison is not simply consulting versus employment: consider how much client variety and independence you want, who provides the organizational platform, and who owns business development and administration.
| Path | Typical shape | Important trade-off |
|---|---|---|
| Consulting or service firm | Work with clients through an established organization. | The firm provides a platform for client work; the sources do not establish a controlled comparison of income or benefits with independent practice. |
| Independent vCISO | Provide virtual security leadership or advisory services to one or more organizations. | Can offer autonomy and variety, while the practitioner must develop business and manage client relationships. |
| Fractional CISO | Provide part-time, embedded leadership, potentially across multiple clients. | Combines ongoing leadership work with the need to coordinate responsibilities and context across organizations. |
| Retained advisory work | Provide continuing advice under an ongoing engagement. | Work is tied to the client relationship and agreed scope; specific income comparisons are not established by the sources. |
| Project-based or hourly consulting | Take on defined work such as an assessment, roadmap, compliance need, or specific advisory task. | Engagements can be bounded, but continuity of work may vary. |
| Internal CISO | Lead security within one organization. | Keeps the role anchored in one organization, though scope, resources, and executive alignment vary by employer. |
Practitioner accounts and reporting describe these models, but do not establish that one is best for every career or income goal. CSO Online’s coverage of vCISO work outlines several engagement types and career paths. Read its vCISO career-path article. A separate Hitch Partners survey describes a voluntary group of more than 100 full-time U.S.-based vCISO professionals; it was fielded June 13 to July 31, 2023, and should not be treated as representative of all CISOs. Hitch Partners publishes the survey results.
What changes when a CISO becomes a consultant?
Influence replaces some direct authority
An in-house CISO may have organizational authority to set requirements or direct internal work. A consultant generally advises a client, while implementation and final decisions remain with the client. “As a CISO, you can mandate; as a consultant, you can only influence,” says Nigel Gibbons, director and senior advisor at NCC Group.
Rank #4
Security judgment, prioritization, crisis management, and the ability to translate technical risk into business consequences still matter. Communication becomes especially important when the consultant must persuade leaders who do not report to them. “All of your security and compliance knowledge is wasted if you cannot communicate to a business audience,” says Carlota Sage, founder of Pocket CISO.
Business development becomes part of the job
Independent consultants must find work as well as deliver it. That can involve selecting a client segment, explaining which problems they solve, demonstrating credibility, reconnecting with contacts, building visibility, and marketing their expertise. It also adds writing, proposals, client acquisition, accounting, and administrative work to the week.
Best Value
Kokhreidze characterized the sales burden this way: “Eighty percent of your work is actually selling yourself,” says Kokhreidze. “You are first a business, and CISO second.” Treat that as his interview observation, not a measured share of consultants’ working hours. Another practitioner interviewed by CSO Online warned that it could take 12–18 months to land a first client if prospects were not already asking for consulting; that is one person’s experience, not a reliable forecast for every new practice.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How can a security leader prepare for the transition?
Practitioners interviewed by CSO Online described building visibility, testing ideas, reconnecting with professional contacts, and mapping potential clients before leaving an employed role. Their advice is experience-based rather than a statistically proven recipe. A useful preparation sequence is:
- Choose the work and buyer. Define the client segment you want to serve and the specific security problems you can credibly address.
- Explain your value in business terms. Connect security expertise to resilience, governance, risk priorities, or execution outcomes that decision-makers recognize.
- Test interest before relying on it. Reconnect with relevant contacts, build professional visibility, and explore whether prospective clients have needs that fit your offer.
- Plan for the business work. Account for sales, marketing, proposals, writing, client relationship management, bookkeeping, and administration—not just billable security advice.
- Clarify the engagement boundaries. Agree on scope, responsibilities, decision authority, and what the client must implement; advice does not automatically give a consultant control over delivery.
- Review professional and legal exposure. Devo’s survey reported that respondents sought indemnification, insurance, or outside counsel. That finding is not legal advice or a universal insurance prescription; review contracts, jurisdiction, and professional needs with qualified advisers.
Does demand for vCISO services mean more CISOs are becoming consultants?
No. Provider surveys indicate interest in the services market, not the number of individual security leaders changing careers. In Cynomi’s 2024 survey, Global Surveyz interviewed 200 senior security leaders at North American MSPs and MSSPs in June and July; 75% reported very high demand for vCISO services. In the 2025 survey of 200 leaders at North American MSPs and MSSPs, 79% reported high SMB demand. These are service-provider perceptions, not counts of CISO transitions. Cynomi’s 2024 report and 2025 report describe those surveys.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallWhat the available evidence can—and cannot—tell you
Interviews explain why particular practitioners chose consulting; they cannot show how common those reasons are. Surveys from Trellix and Devo describe role pressures and intentions, but do not follow respondents to determine whether they left or what work they took next. The available sources also do not provide a reliable comparison of earnings between employed CISO roles and independent consulting. Treat consulting as a career option with specific attractions and operating demands, not as a proven mass exit from security leadership.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

