- Model
- Fractional / part-time
- Focus
- Strategy, risk & compliance
- Commitment
- Monthly retainer or ad hoc
- Delivered by
- A named cyber security expert
What a fractional CISO does
A Chief Information Security Officer owns the answer to a simple board-level question: are we secure enough, and how do we know? Most small and mid-sized organisations need that answer, and someone accountable for it, long before they can justify a full-time CISO on a six-figure salary. A fractional CISO (also called a virtual CISO, or vCISO) fills that gap — the same ownership and judgement, for a few days a month.
In practice that means owning your security strategy and roadmap, translating technical risk into terms your board and clients understand, running your compliance programme, making sensible tooling and vendor decisions, and being the person who picks up the phone when something goes wrong.
When you need one (and when you don't)
A fractional CISO earns its keep when:
- you are winning larger contracts and buyers now demand security maturity you cannot yet evidence;
- an insurer, regulator or board is asking who actually owns security, and the honest answer is “no one”;
- you have had an incident, or a near miss, and want it not to happen again;
- you are past the point where ad hoc testing is enough, but nowhere near needing a full-time hire.
And we will say so if you do not need one yet. If what you actually need is a penetration test, Cyber Essentials, or a single piece of advice, that is cheaper and quicker, and we will point you there instead of selling a retainer.
What's included
Security strategy & roadmap
A prioritised plan tied to your actual risks and commercial goals, not a generic checklist. Reviewed and adjusted as the business changes.
Risk management
A living risk register the board can govern with: what could hurt you, how likely, what we are doing about it, and who owns each item.
Compliance & audit support
Ownership of Cyber Essentials, IASME, ISO 27001 or SOC 2 as needed, and the person who sits across the table from auditors and client security questionnaires so your team does not have to.
Governance & policy
Policies people can actually follow, security built into how you already work, and awareness that changes behaviour rather than ticking a training box.
Third-party & vendor risk
Your suppliers are part of your attack surface. We assess the ones that matter and hold them to a standard.
Board & stakeholder reporting
Clear reporting for boards, investors, insurers and clients: where you are, where the gaps are, and what closing them costs.
Incident readiness
A plan agreed before you need it, rehearsed, and a named person to lead if the worst happens — with our incident response and monitoring behind them.
Fractional CISO, consultant, or full-time?
A project consultant delivers a report and leaves; the ownership goes with them. A full-time CISO is the right answer eventually, but at £100k+ plus on-costs it is overkill for most organisations under a few hundred staff. A fractional CISO gives you the continuity and accountability of the full-time role at a fraction of the cost, and unlike a one-off consultant, they are still there next quarter when the plan needs to change.
Fractional security expert
Not everyone needs CISO-level governance. If what you are missing is senior hands-on security capability — someone to lead testing, harden your build, review architecture, or mentor your team — we offer the same fractional model at a more technical level. Same principle: a senior expert, part-time, without the full-time hire.
How it works
We start with a short assessment of where you are and what you are trying to achieve, agree a scope and a monthly cadence (a set number of days, scalable), and name the person who will own it. No long lock-ins: the arrangement should flex with the business, including scaling down when you are in a steady stretch.
Common questions
What's the difference between a fractional CISO and a virtual CISO (vCISO)?
In practice, none. ‘Fractional CISO’, ‘virtual CISO’ and ‘vCISO’ all describe a senior security leader working with you part-time rather than as a full-time employee. We use whichever term you are comfortable with.
How much of their time do we get?
As much as the role needs and no more. Most engagements run on a monthly retainer of a set number of days, scaled up around audits, funding rounds or incidents and down when things are steady.
Is this a sales or account-management role?
No. You work directly with the cyber security expert doing the work. There is no account manager in between and no junior analyst the work is quietly handed to.
Can you also deliver the testing and compliance work?
Yes. We can own the strategy and deliver the penetration testing, Cyber Essentials, monitoring and vulnerability management underneath it, or coordinate your existing suppliers — whichever gives you better value.
What size of organisation is this for?
Typically SMEs, scale-ups, schools and multi-academy trusts, and charities: organisations that need real security leadership and accountability but cannot justify, or do not yet need, a full-time CISO.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day