Fractional CISO

Senior security leadership without a full-time salary. You get a named, hands-on cyber security expert who owns your strategy, risk and compliance — scaled to what your organisation actually needs, dialled up before an audit or a funding round and down when things are steady.

Model
Fractional / part-time
Focus
Strategy, risk & compliance
Commitment
Monthly retainer or ad hoc
Delivered by
A named cyber security expert

What a fractional CISO does

A Chief Information Security Officer owns the answer to a simple board-level question: are we secure enough, and how do we know? Most small and mid-sized organisations need that answer, and someone accountable for it, long before they can justify a full-time CISO on a six-figure salary. A fractional CISO (also called a virtual CISO, or vCISO) fills that gap — the same ownership and judgement, for a few days a month.

In practice that means owning your security strategy and roadmap, translating technical risk into terms your board and clients understand, running your compliance programme, making sensible tooling and vendor decisions, and being the person who picks up the phone when something goes wrong.

When you need one (and when you don't)

A fractional CISO earns its keep when:

  • you are winning larger contracts and buyers now demand security maturity you cannot yet evidence;
  • an insurer, regulator or board is asking who actually owns security, and the honest answer is “no one”;
  • you have had an incident, or a near miss, and want it not to happen again;
  • you are past the point where ad hoc testing is enough, but nowhere near needing a full-time hire.

And we will say so if you do not need one yet. If what you actually need is a penetration test, Cyber Essentials, or a single piece of advice, that is cheaper and quicker, and we will point you there instead of selling a retainer.

What's included

Security strategy & roadmap

A prioritised plan tied to your actual risks and commercial goals, not a generic checklist. Reviewed and adjusted as the business changes.

Risk management

A living risk register the board can govern with: what could hurt you, how likely, what we are doing about it, and who owns each item.

Compliance & audit support

Ownership of Cyber Essentials, IASME, ISO 27001 or SOC 2 as needed, and the person who sits across the table from auditors and client security questionnaires so your team does not have to.

Governance & policy

Policies people can actually follow, security built into how you already work, and awareness that changes behaviour rather than ticking a training box.

Third-party & vendor risk

Your suppliers are part of your attack surface. We assess the ones that matter and hold them to a standard.

Board & stakeholder reporting

Clear reporting for boards, investors, insurers and clients: where you are, where the gaps are, and what closing them costs.

Incident readiness

A plan agreed before you need it, rehearsed, and a named person to lead if the worst happens — with our incident response and monitoring behind them.

Fractional CISO, consultant, or full-time?

A project consultant delivers a report and leaves; the ownership goes with them. A full-time CISO is the right answer eventually, but at £100k+ plus on-costs it is overkill for most organisations under a few hundred staff. A fractional CISO gives you the continuity and accountability of the full-time role at a fraction of the cost, and unlike a one-off consultant, they are still there next quarter when the plan needs to change.

Fractional security expert

Not everyone needs CISO-level governance. If what you are missing is senior hands-on security capability — someone to lead testing, harden your build, review architecture, or mentor your team — we offer the same fractional model at a more technical level. Same principle: a senior expert, part-time, without the full-time hire.

How it works

We start with a short assessment of where you are and what you are trying to achieve, agree a scope and a monthly cadence (a set number of days, scalable), and name the person who will own it. No long lock-ins: the arrangement should flex with the business, including scaling down when you are in a steady stretch.

Common questions

What's the difference between a fractional CISO and a virtual CISO (vCISO)?

In practice, none. ‘Fractional CISO’, ‘virtual CISO’ and ‘vCISO’ all describe a senior security leader working with you part-time rather than as a full-time employee. We use whichever term you are comfortable with.

How much of their time do we get?

As much as the role needs and no more. Most engagements run on a monthly retainer of a set number of days, scaled up around audits, funding rounds or incidents and down when things are steady.

Is this a sales or account-management role?

No. You work directly with the cyber security expert doing the work. There is no account manager in between and no junior analyst the work is quietly handed to.

Can you also deliver the testing and compliance work?

Yes. We can own the strategy and deliver the penetration testing, Cyber Essentials, monitoring and vulnerability management underneath it, or coordinate your existing suppliers — whichever gives you better value.

What size of organisation is this for?

Typically SMEs, scale-ups, schools and multi-academy trusts, and charities: organisations that need real security leadership and accountability but cannot justify, or do not yet need, a full-time CISO.

Related

Not sure if you need a fractional CISO?

That's exactly the first conversation, and it's free. Tell us where you are and we'll tell you honestly what you need — including if it's less than a retainer.