Conflating them produces both wrong answers at once. As an executive hire, almost no startup needs a CISO at seed or Series A — the workload wouldn’t fill an executive calendar, and the compensation would distort the payroll. As a function, the need starts embarrassingly early: the day production holds customer data, somebody is already making CISO decisions — who gets admin access, what happens when a laptop disappears, which vendor is safe to connect — whether or not anyone calls them that.
The default is that the CTO absorbs it informally, and informal is precisely the problem. Buyers and investors want a name attached to security, and a founder juggling it between sprints doesn’t read as a name — it reads as a gap. Meanwhile the work itself — questionnaires, policies, access reviews — accumulates on whichever calendar can least afford it.
So sequence it: give the function a real owner now, defer the title until scale forces the issue. Fractional coverage is how most startups thread that — a named security leader sized to actual decision volume, with the program documented so it transfers cleanly to an eventual executive. The early-stage version is laid out in vCISO for startups; the criteria for when the full-time hire becomes right are in vCISO vs full-time CISO.
A short list, done consistently: access decisions and periodic reviews, an incident plan people have actually read, vendor sanity checks, honest answers on security questionnaires, and one person empowered to say no. It’s a few focused hours a week — which is exactly why a fractional owner fits the stage.
They ask something sharper: who is accountable for security, and can we meet them. A fractional leader with a real program and crisp answers clears that bar; an org-chart title with nothing behind it doesn’t. What gets evaluated is substance, not the employment arrangement.