Service

Fractional CISO

A named security leader for companies that answer to regulators, and are too small to justify the role full-time.

Fractional CISO, vCISO, virtual CISO, interim CISO: the market uses all four labels for roughly the same thing, and the label matters far less than two questions. Who does the person work for, and can they do the technical work the program depends on, or only describe it?

The difference

A security leader who can write the fix

Most fractional security leadership is advisory. You get someone who has held the title, runs good meetings, and produces a policy set. That is worth something, and it is not what breaks.

What breaks is specific and technical. Whether the vendor’s demo matches the product. Whether the architecture survives the next order of magnitude. Whether a secret is sitting in a build pipeline where it should not be. Whether the recommendation in the penetration test report is even implementable against a load balancer that rotates its certificate every 90 days.

I came to security from engineering, not from compliance, and I still do the work. I can open the architecture, read the code, look at the cloud bill and tell you what is actually wrong, then write the fix and produce documentation that holds up for a regulator. CISSP certified, Azure Solutions Architect, 20+ years running technology organizations, two exits.

What it covers

What the role includes

The title covers a wide range in the market, so here is the specific version.

The security program itself

The risk register, the policy set, and the review cadence that keeps both alive. Not a document pack delivered once and left to rot, but the thing an auditor, a customer or a regulator is actually asking to see when they ask whether you have a program.

Regulator and auditor response

FDA premarket and post-market cybersecurity obligations including Section 524B, the HIPAA Security Rule, and NIST CSF as the spine underneath. When a letter or a finding arrives, somebody has to own the answer and be able to defend it.

Customer and enterprise security review

Security questionnaires, diligence requests, and the architecture questions that arrive late in a deal. These block revenue, and they are answered fastest by the person who actually knows how the system is built.

Application and product security

Authentication and authorization design, secrets in CI/CD pipelines, portal and API security, least privilege for developers, and the security of the repository itself. Most fractional security leaders cannot do this. It is the reason people call me.

Vendor and supplier risk

Defining what your providers must achieve, reading their reports skeptically, verifying that tooling is deployed rather than merely purchased, and escalating when it is not. Including the awkward case where the provider being reviewed is the one selling you the review.

Board and executive reporting

Translating security posture into the decisions and the money a board needs to act on, in language that survives contact with people who are not engineers.

Penetration test programs

Scoping the test against the real attack surface, managing the engagement, and driving findings to documented closure so the evidence is traceable rather than asserted.

Post-incident architecture remediation

Once an incident is contained and the response firm has finished, the architecture, the identity layer and the applications still contain the path that was used. Closing it is engineering work, and it is the part that decides whether it happens again.

What this is not

This is not a managed service, and it is not a 24/7 monitoring operation. I do not want to image your laptops and you should not be paying me to. I also do not do incident response: if you are in an active incident, call a specialist response firm. What I do is the part that comes afterwards.

Who this is for

Where this fits

Companies in regulated industries where a security failure is expensive in a way that is written down somewhere: medical device and SaMD companies, digital health and healthcare IT, legal, and financial services.

The common shape is a company with a real product, real customers, and a security obligation that has outgrown whoever has been absorbing it. Usually somewhere between seed and Series B, or an established firm whose compliance surface grew faster than its technology function.

If security ownership is not the gap and the real problem is architecture, roadmap or build-versus-buy, that is the fractional CTO side of the practice, and it is a different conversation.

When you need one

What usually brings people here

Nobody wakes up wanting a fractional CISO. Something happens first. In order of how often I see it:

01
A regulator, an enterprise customer, or an acquirer is asking

An FDA cybersecurity deficiency letter on a device or a software-only product, a security questionnaire, an audit finding, or diligence that needs answers your environment can actually support.

02
A penetration test came back and nobody can close it

The report is thorough and the findings are real. The testing firm cannot remediate its own findings without losing its independence, and your team does not have the security context to translate a finding into a change.

03
A customer is about to make security a condition of the deal

The questionnaire is longer than expected, the answers need to be true, and the person best placed to write them is the person who understands the architecture underneath.

04
You have had an incident and containment is done

The responders have gone. What remains is the architecture that allowed it, and nobody currently owns closing that.

05
Nobody owns security, so it lands on whoever is free

The MSP handles tickets, the developers ship features, and no single person can tell you what your exposure is, what the policy says, or whether either one is current.

06
The board wants assurance it can act on

Somebody has to own the program and defend it to the people writing the check, in terms they can act on.

Or a defined project

When it is one problem, not a role

Not everything needs a retainer. Two of these arrive often enough to be scoped and priced on their own:

FDA cybersecurity remediation when you are holding a deficiency letter with a 180-day clock on it, or preparing a submission whose cybersecurity section nobody is confident in.

Penetration test remediation when you have a report, a retest date, and nobody in the building who can do the work in between.

Both are fixed-price with a defined scope and an end date. Either can turn into an ongoing arrangement afterwards, and often does, but they do not have to.

How it works

How engagements are structured

Fractional security leadership is a retainer. That is different from the fixed-price project work above, and the difference is deliberate: a project has a finish line, and holding a role does not.

The retainer is sized by the responsibilities I own, not by the hours I am in the building. What makes it worth buying is that those responsibilities are named: a monthly fee for unspecified availability is how these engagements quietly turn into nothing. The value is concentrated in a handful of moments anyway, where someone senior looks at what is about to be decided and says there is a better way to do it. You still decide. You decide from a position of knowledge rather than ignorance, and over three years that difference compounds.

So every engagement starts by writing down which of the responsibilities above are mine, what arrives on what cadence, and what I am accountable for producing. The role reports to the CEO or the board, because a security function that reports to the thing it is reviewing is not a security function.

Retainers start at $5,000/month. Where an engagement lands above that depends on how much estate there is and how much of it is urgent. Tell me what is going on and I will come back with a shape and a price.

Two things hold regardless of the numbers. Everything I build, document and configure is yours, and the engagement is designed so you can end it without losing the program. And when the work in one area grows past what a fractional owner should be doing, I will tell you to hire.

Comparison

Versus the alternatives

Versus an MSP

An MSP delivers services. A fractional CISO decides what those services must achieve and verifies that they do. Different jobs, and they cannot be the same supplier, because the second one includes judging whether the first one is performing.

Versus a vCISO or vCIO sold by your MSP

Worth separating, because the labels get used interchangeably and what sits behind them does not. A vCISO sold by your managed provider is a service that provider delivers: a recurring security advisory function, staffed by them, reviewing an environment they also build and run. A vCIO is the same arrangement pointed at technology strategy. A fractional or interim CISO is a named executive who joins your leadership team part-time and works for you.

The distinction is not academic, because a large part of this role is deciding what your providers must achieve and then checking whether they did. A provider-sold vCISO is being asked to grade its own employer’s work, which is a position no individual can be expected to hold well however good they are.

It is an easy failure to walk into. A company decides it needs independent oversight of its managed provider, agrees with the principle, and then buys that oversight from the provider. The questions that would surface the provider’s own gaps are never the ones asked. Nobody acts in bad faith. Oversight simply has to come from outside the thing being overseen. That argument is set out in why your MSP is not your security program.

Versus a full-time CISO

The rule I use: hire full-time when there is enough work in one specialization to keep one person genuinely busy. Below that line a full-time security hire spends a large share of the week looking for work to do, at a salary that assumes they never will.

The moment security becomes a full week of work, hire for it. I will say so, and I would rather say it early than bill through it.

What to look for

Why these engagements fail

Almost always the same reason: missing domain expertise.

Someone holding this role has to understand enough about security, infrastructure, cloud and application development to be useful in all of them. The gap I see most often is application development. Someone arrives from a compliance, network or people-management background, and then cannot help with the things that actually break: securing code repositories, protecting application secrets inside an automated CI/CD pipeline, or making sure developers work under least privilege.

The second failure is the role being handed to whoever is organized and available. It is not a reporting line you give the CFO or the COO. It is not a project manager who runs the vendor calls.

When you are evaluating anyone for this role, including me, ask them to walk you through how a secret gets from a vault into a running container without ever existing in a repository. The answer tells you what you need to know in about two minutes.

Common questions

Questions I get asked first

What does a fractional CISO actually do?

Owns the security program rather than advising on it. That means the risk register, the policy set, vendor and supplier risk, the answers that go back to regulators, auditors and enterprise customers, and the reporting that reaches your board. The distinguishing part is that I also do the technical work the program depends on, rather than handing you a list for someone else to implement.

Is a fractional CISO the same as a vCISO or a virtual CISO?

The labels get used interchangeably. In practice the difference that matters is who the person works for. A vCISO sold by your managed provider is a service that provider delivers. A fractional or interim CISO joins your leadership team part-time and works for you, which matters most when the job includes judging whether your provider is performing.

How much time does it take, and what does it cost?

Retainers start at $5,000 a month, sized by the responsibilities I own rather than by hours in the building. Where an engagement lands above that depends on how much estate there is and how much of it is urgent. Every one starts by writing down which responsibilities are mine and what I am accountable for producing, because a monthly fee for unspecified availability is how these quietly turn into nothing.

Do you handle incident response?

No. If you are in an active incident, call a specialist response firm. What I do is the part afterwards: once containment is done and the responders have gone, fixing the architecture, the identity layer and the applications so the same path does not work twice.

Which frameworks do you work to?

NIST CSF, the HIPAA Security Rule, and FDA premarket and post-market cybersecurity guidance including Section 524B. Which one leads depends on who is asking you the question, and for most regulated companies more than one applies at once.

What happens when the work outgrows a fractional arrangement?

I tell you to hire, and I would rather say it early than bill through it. The rule I use is that a full-time hire makes sense once there is enough work in one specialization to keep one person genuinely busy. Everything I build, document and configure is yours, and the engagement is designed so you can end it without losing the program.

Related reading

Written on this

Start with a conversation

Tell me what’s going on. If a fractional arrangement is the right answer I will scope it. If it is not, I will say what is.

Bring your FDA letter, pen test report, audit deadline, or security questionnaire.

For companies looking to engage BATO. Vendors, please email.