Fractional CISO

CISO-level leadership, at the fraction of time it actually takes

Senior security leadership on retainer for companies too complex for no CISO and too small for a full-time one.

Book a consultation →

There is a gap between "we need someone senior thinking about security" and "we can justify a $350,000 hire." Most companies between 100 and 1,000 employees live in it. A fractional CISO fills that gap: real security leadership on a few days a month, without the headcount.

What you are actually buying

Not monitoring. Not a tool. Not a junior analyst with a checklist. You are buying the judgment of someone who has run security programs and can tell you which three things matter this quarter and which twelve can wait, then defend that call to your board.

The work usually covers a security strategy and roadmap tied to your business rather than a generic maturity model, board and executive reporting in language executives use, risk register ownership, vendor and third-party risk, audit and questionnaire readiness, incident response planning and the tabletop that proves it works, and direction for whoever handles security day to day.

Three shapes this takes

Advisory

Roughly one to two days a month. A standing call, board and audit support, and someone to phone when something unexpected lands. Right for companies with competent IT who need direction rather than execution.

Operational

Roughly four to six days a month. Everything above plus running the program: driving remediation, managing vendors and assessments, and working directly with your team. This is the most common shape.

Embedded

Two or more days a week. For companies going through something specific: a certification push, an acquisition, remediation after an incident, or a customer requirement with a deadline attached. Usually time-boxed, and often steps down to operational afterward.

We will tell you honestly which one fits, including when the answer is that you are not ready for any of them yet.

How the first ninety days run

The first month is assessment: what you have, what you are exposed to, what your contracts and customers already obligate you to, and where the real gaps sit as opposed to the theoretical ones. You get a written picture and a prioritized roadmap rather than a maturity score.

The second month is sequencing and starting the work that matters most. Usually that is identity, access, and the handful of controls that would actually have stopped the incidents your peers are having.

By the third month you should have a board-ready reporting rhythm, a risk register someone owns, and visible movement on the top items. If you cannot see progress by then, something is wrong with the engagement and we would rather say so.

When a fractional CISO is the wrong answer

Under about fifty people with no regulated data and no enterprise customers, you probably need good IT hygiene and a managed security service, not a CISO. Past roughly 1,000 employees, or with a security team of any size, you likely need a full-time leader and we can help you hire one.

The fit is the middle: enough risk and enough scrutiny to need senior judgment, not enough to justify the salary.

The credential question

Ask any fractional CISO what they have actually run. Ours: enterprise security programs across healthcare, finance, government, and the defense supply chain, security due diligence on a $1B acquisition, a transformation program that produced $5.8M in savings, and two U.S. AI patents. Engagements are led personally, not staffed to someone junior.

Book a call and we will give you a straight read on which shape fits, or tell you that you do not need this yet.

Outcomes

What you get

A roadmap tied to your business

Prioritized by what actually threatens your revenue and your contracts, not by a generic maturity model.

Board conversations that land

Security reported in terms executives can act on, so budget requests stop being a translation exercise.

Questionnaires stop being a fire drill

Customer security reviews, audits, and insurance renewals answered from evidence that already exists.

Questions

Frequently asked

How many days a month do we need?

Advisory runs one to two days, operational four to six, embedded two or more days a week. Most companies land on operational. We will recommend a shape after the first conversation rather than selling you the largest one.

Is this the same as a vCISO?

The terms are used interchangeably. Some firms use vCISO for a mostly remote, lighter-touch service and fractional CISO for deeper involvement. What matters is the seniority of the person and how much of their attention you actually get.

What if we have an incident?

Response is part of the engagement. Planning and tabletops come first so the plan exists before it is needed. If something significant happens, we are on it, and if it exceeds what a fractional engagement can cover we say so and bring in specialist IR rather than pretending otherwise.

Can you work with our existing IT team or MSP?

Yes, and that is the usual arrangement. We provide direction and they execute. Good MSPs welcome it because it gives them clear priorities instead of guesswork.

How long do engagements run?

Most are ongoing with a quarterly review. Embedded engagements are usually time-boxed around a specific goal. There is no long lock-in; if we are not adding value you should be able to leave.

Do you help us hire a full-time CISO eventually?

Yes, and for many clients that is the goal. We can define the role, help evaluate candidates, and hand over a program that is already running rather than leaving them a blank page.