Service

Fractional CISO and CTO

When you need both, and cannot fund two executives to get them.

This is the common position for a seed to Series B medtech or digital health company. There is a product that a regulator will eventually read, an architecture that has outgrown the person who started it, and a first enterprise customer asking questions nobody has had to answer before. Two of those are security problems and one is an architecture problem, except that in practice they are the same problem seen from different chairs.

Hiring two fractional executives to cover it is the obvious move and usually the wrong one. It costs more, and it introduces a negotiation between them into every decision that matters.

Why one person

At this stage they are the same job

Not always, and not forever. But at the size where this question comes up, almost every decision worth having a senior person on touches both sides at once.

The submission is an architecture document

A premarket cybersecurity package describes how the system authenticates, authorizes, segregates and updates itself. Writing it is a security job. Making it true is an architecture job. When two people own those separately, the document and the product drift, and a reviewer finds the gap.

The enterprise customer asks both questions at once

A security questionnaire is answered by whoever knows how the system is built. Half the questions are policy and half are architecture, and the ones that hold up a deal are usually the architecture ones wearing policy clothes.

Build versus buy has a compliance answer

Whether to build a component or buy one is a technology decision with a regulatory consequence attached: a bought component arrives with a vendor to assess, an agreement to hold, and a supply chain entry to monitor. Deciding it without both halves in the room produces a decision that gets revisited.

Cloud cost and cloud exposure are one inventory

The resource nobody can account for is a line on the bill and an unmonitored thing with an address. Two owners build the same picture of the estate twice and act on it once.

Remediation needs someone who can change the system

A penetration test finding or a deficiency item is closed by changing the product. A security owner who cannot direct that change has to negotiate for it, which is where the calendar goes.

The board wants one answer

Technology risk and security risk arrive at a board as one question about whether the company can do what it says it can. Two part-time executives produce two partial answers and leave the synthesis to the person least equipped to do it.

What it covers

Both sets of responsibilities, one owner

The security side

The risk register, the policy set, vendor and supplier risk, regulator and auditor response, FDA premarket obligations including Section 524B, HIPAA Security Rule posture, penetration test programs, and the reporting that reaches your board. The full version is on the fractional CISO page.

The technology side

Architecture ownership, the technology roadmap, build versus buy, cloud cost and posture, vendor and team oversight, technical due diligence, and AI in environments where the data governance has to hold. The full version is on the fractional CTO page.

And the part that only exists in the combination

Deciding which of the two a given problem actually is. A surprising amount of what looks like a security problem is an architecture problem that has been left long enough to become one, and the reverse is true just as often. Someone holding both makes that call in a conversation instead of a meeting.

Who this is for

Seed through Series B, in a regulated market

Medtech and digital health companies most of all, because they hit both obligations earliest: a premarket submission that has to describe the architecture accurately, and enterprise health system customers who audit their vendors properly.

The signal that this is the right arrangement is usually a first outside party asking for evidence. A submission, a questionnaire, a diligence process, a partner agreement. Before that point a conversation is free and a retainer is probably early, and I will tell you so.

When this is the wrong purchase

If one side is clearly dominant, buy that side. A company holding a deficiency letter with a solid engineering team does not need a fractional CTO attached to the fix, and a company with a stalled platform and no regulatory pressure does not need a security program bolted on. Paying for both when you need one is the mistake in the other direction.

How it works

One retainer, named responsibilities

One arrangement, sized by the responsibilities I own across both sides rather than by hours in the building. It starts by writing down which of them are mine, what arrives on what cadence, and what I am accountable for producing, because a monthly fee for unspecified availability is how these engagements quietly turn into nothing.

Retainers start at $5,000/month. The combined arrangement is more than a single pillar and considerably less than two, but the saving is not the main argument. The main argument is that one person holding both does not have to negotiate with themselves.

The role reports to the CEO or the board. Everything I build, document and configure is yours, and the engagement is designed so you can end it without losing the program or the architecture.

Work with a defined finish line is quoted separately as fixed-bid, and often runs alongside: a deficiency letter response, a penetration test remediation, or an architecture review.

Comparison

Versus the alternatives

Versus two fractional executives

More expensive, and slower where it matters. Two part-time people who each see half of a decision have to reach agreement before anything moves, and neither of them owns the outcome. It is the right structure at a size where each role is a full job, and an expensive one before that.

Versus one full-time hire covering both

This is a real option and sometimes the right one. The difficulty is supply: people who have genuinely held both, in a regulated market, are rare and priced accordingly, and a company at this stage usually discovers that the candidates it can afford have held one.

Versus waiting

Waiting is defensible right up until an outside party asks for evidence, at which point the cost of not having had anybody stops being theoretical and starts being a date on a calendar. The argument for why this step gets skipped, and what it costs, is in the technology stage most growing companies skip.

Common questions

Questions I get asked first

Why would one person hold both roles?

Because at this stage the two jobs are the same argument. Almost every security decision is an architecture decision, and almost every architecture decision has a compliance consequence. Splitting them across two part-time executives means the two of them have to agree before anything moves, which is slower and more expensive than one person deciding.

Is that not too much for one person?

It is, eventually, and that is the point at which you hire. Below that line the combined load is one role, and treating it as two produces meetings rather than decisions. I will tell you when it crosses over, and I would rather say it early than bill through it.

What does it cost compared to two separate arrangements?

Less than two, and not double a single pillar. It is one retainer sized by the responsibilities owned across both, starting at $5,000 a month. The saving is real but it is not the main argument; the main argument is that one person holding both does not have to negotiate with themselves.

We are pre-revenue. Is this premature?

Often, yes, and I will say so. The point where it stops being premature is usually the first time an outside party asks for evidence: a premarket submission, a first enterprise customer, a diligence process, or a partner who sends a questionnaire. If none of those are on your horizon, a conversation costs nothing and a retainer is probably early.

What happens when we outgrow it?

You hire, in the order the work demands rather than the order an org chart suggests, and I help you do it. Everything built, documented and configured is yours, and the arrangement is designed so that ending it does not cost you the program or the architecture.

Related reading

Written on this

Start with a conversation

Tell me what’s going on. If one side is the real problem I will say so and scope that instead.

Bring your FDA letter, pen test report, audit deadline, or architecture problem. You'll talk to me, not a sales rep.

Not ready for a call? Send a message instead.

For companies looking to engage BATO. Vendors, please email.