
Cybermatch Executive
Hiring a CISO is about far more than filling a role: the credibility of your security set-up with the executive committee, regulators and clients is at stake. At Cybermatch, these searches fall under executive search: they are led by our partners through direct approach, and every finalist is assessed by a peer from the expert committee, an active CISO or cybersecurity director.
The best CISOs are in post, constantly approached, and say little about their situation. Regulatory requirements (NIS 2, DORA, ISO 27001) have sent demand soaring for leaders able to speak technology, risk and strategy at the same time. A job ad is not enough: these candidates are won over by a direct, confidential approach that is credible on substance, led by someone who knows their profession.
NIS 2 · the coming wave of hiring
The French transposition law (the “Resilience” bill) is still going through Parliament and ANSSI’s decrees and frameworks are being prepared: once it is adopted, nearly 15,000 essential and important entities across 18 sectors will have to comply. Management bodies become accountable for their organisation’s cyber risk management, with fines of up to €10 million or 2% of worldwide turnover for essential entities. Hundreds of organisations are looking for a CISO at the same time, from a talent pool that hasn’t grown.
Every search is led by a partner, from scoping to onboarding. Scoping sets the role’s remit, the organisation’s cyber maturity, the reporting line and the sector’s regulatory constraints. The search is then conducted through direct approach, in complete confidence. Finalists meet a member of the expert committee, who provides a written opinion, and take a personality assessment with shared feedback. Confidential due diligence can be carried out with the candidate’s consent.
Other leadership roles (heads of SOC or CERT, R&D directors, VPs of Sales, executives of cyber companies) are presented on our cybersecurity executive search.
The assessor is a CISO or cybersecurity director currently in post and a member of the expert committee. Here is what they look at:
Gross annual ranges observed in France in 2026, excluding bonus and benefits, compiled by Cybermatch from its own searches and public market studies. Paris and regulated sectors sit at the top of the ranges.
| Role | Mid-level | Senior | Lead / head of |
|---|---|---|---|
| CISO (all organisation sizes) | €70k–95k | €95k–140k | €140k–220k |
| Mid-cap and scale-up CISO (by experience) | €90k–105k (6 to 10 years) | €100k–120k (10 to 15 years) | €120k+ (15 years and more) |
| Interim CISO (freelance) | €700–900 / day | €900–1,200 / day | on request |
For comparison, the CESIN study (the French club of information and digital security experts), conducted with OpinionWay in 2024 among 390 security leaders, puts the median gross annual salary of CISOs at €90,000 and the average at €96,543, with 71% receiving variable pay (CESIN 2024 study).
Variable pay commonly represents 10% to 20% for a group CISO. CISSP, CISM and ISO 27001 Lead Implementer certifications, cloud experience and a direct reporting line to executive management push salaries upwards.
Yes. We scope the role according to your status (essential or important entity), your sector and your maturity, then our partners directly approach CISOs who have already led a regulatory compliance programme (NIS 2, DORA, ISO 27001). Every finalist is assessed by an active peer from the expert committee. Given the volume of hiring expected once the transposition law is adopted, we recommend launching the search as early as the mapping and risk-analysis phase, without waiting for the decrees.
Allow three to four weeks for a shortlist of qualified CISOs assessed by a peer, then time for interviews and a three-month notice period in most cases. The new hire therefore usually starts four to six months after launch. An interim CISO can cover the gap.
The CISO owns information security as a whole: strategy, organisation, technology, compliance, crisis management. The GRC manager focuses on governance, risk analysis and regulatory compliance, often within the CISO’s team. At Cybermatch, CISOs and cybersecurity directors fall under executive search; GRC profiles are recruited by the collective (GRC and compliance recruitment).
From a few hundred employees, regulatory exposure (NIS 2, DORA) or a strong dependence on digital systems, yes. Below that, a part-time or interim CISO backed by a service provider is often more realistic. We help you decide at the scoping stage, with no interest in selling you an unnecessary role.
We don’t assess them alone. Every finalist meets a CISO or cybersecurity director in post, a member of our expert committee, who writes an opinion. A personality assessment, shared with both the candidate and the client, completes the evaluation. The recruiter assesses background and motivation; the peer assesses competence.
Yes. We work in France, Belgium, Switzerland, Luxembourg and Monaco, for local roles or European remits managed from France, taking into account each country’s regulatory specifics (FINMA, CSSF, transposed NIS 2).
Hiring a CISO or cybersecurity director falls under Cybermatch Executive: the search works on a retainer paid in three instalments (launch, signed offer, end of probation), with fees capped at 28% of gross annual salary.
Looking for your CISO or cybersecurity director? Describe the role, the context and your constraints: a partner will call you back within 48 hours, in complete confidence.
Are you a cyber expert? Join our talent pool: we only contact you about roles that match your plans.
CandidatesCybermatch Executive: cybersecurity executive search · the expert committee · Cybermatch Collective: GRC & compliance · SOC & cyber defence · offensive security · incident response & DFIR · security engineering · OT, IoT & embedded · IAM & data protection · business functions · about us · client references