Services
Fractional CISOFractional CIOAI Readiness & Security AuditStrategic Implementation
Who we serve
NonprofitsChurches & ministriesSmall businessesMSP partners
Company
AboutCase studiesInsightsContactStart with a conversation →
Home/Services/Fractional CISO

Fractional CISO · vCISO

A Chief Information Security Officer, a few days a month.

Security strategy, a living risk register, compliance evidence, vendor oversight, and a calm voice when something goes wrong — from a CISO who has held the title inside public companies and federal programs.

CadenceMonthly steering · quarterly board
Named executiveMike McGee, CISSP · CISA
Also calledvCISO · virtual CISO · CISO-as-a-service
PricingFlat monthly fee, scoped in the first call

The situation

You have security tools. You don’t have a security owner.

The firewall is managed, the backups run, the MSP sends a monthly report. And still nobody in the building can answer the insurer’s questionnaire, sign off on the new AI tool, or tell the board what the actual top three risks are.

What a vCISO owns

The risk register

One living list of what could hurt the organization, ranked, with an owner and a date against each item. Reviewed monthly, reported quarterly.

What a vCISO owns

Policies people follow

Acceptable use, access, incident response, vendor management, AI use — written at the length your staff will actually read, and mapped to the frameworks your customers ask about.

What a vCISO owns

Evidence on demand

When SOC 2, HIPAA, PCI DSS, CMMC, a grant, or a cyber-insurance renewal asks for proof, it exists already — one control set answering every questionnaire.

What a vCISO owns

Vendor and MSP oversight

Your IT provider gets a peer, not a critic. Renewal reviews, SLA accountability, a second opinion before the next platform purchase.

What a vCISO owns

Incident leadership

A written playbook, a tabletop exercise each year, insurer and counsel identified in advance, and an executive on the call who has run one before.

What a vCISO owns

Board-level reporting

A quarterly security report a trustee can read in ten minutes, with the decisions leadership needs to make stated plainly.

How it runs

A predictable rhythm, not a hotline.

Month 1

Onboard

Discovery, a baseline against NIST CSF 2.0, the first risk register, and the policy gap list. Your first steering meeting has real material in front of it.

Monthly

Steer

A standing meeting with leadership: what changed, what is due, what needs a decision. Between meetings, email and a short response window for anything urgent.

Quarterly

Report

Board or executive report, risk register refresh, compliance calendar update, vendor and insurance renewals reviewed before they land.

Annually

Reset

Tabletop exercise, policy review, roadmap and budget for the year ahead, and a plain-spoken assessment of whether the retainer still fits.

Proof

Judgment formed where the stakes were highest.

The bar was set running information security for travel, healthcare, and government platforms, auditing banks and credit unions as an IT security auditor at Coalfire, and thirteen years as a U.S. Navy surface warfare officer. It is the same bar we bring to a church, a clinic, or a twelve-person firm.

0+Years in security leadership
0Days · audit to roadmap
0Business day to a reply

“As an early-stage company, we couldn’t justify a full-time security hire, but we still had enterprise customers asking hard questions.”

TR
Tristan ReesCo-Founder & COO, Code Lexica
NIST CSF 2.0NIST AI RMFSOC 2HIPAAPCI DSSCMMCISO 27001

Questions we hear

Frequently asked

What is the difference between a vCISO and a fractional CISO?
Nothing meaningful. “Virtual CISO” and “fractional CISO” both describe a senior security executive engaged part-time. We say fractional because the executive is on your leadership team, not on a screen somewhere.
Do we still need our MSP?
Almost always, yes. Your MSP runs the environment. The fractional CISO decides what the environment must do, holds the MSP to it, and takes the governance, compliance, and board work off their plate.
How many hours a month is it?
It depends on cadence and scope, which is why we scope in a conversation rather than a price list. Most retainers work out to a few days a month, with more in the onboarding month and around audits or incidents.
Can you help with SOC 2 or HIPAA?
Yes. We build the control set, produce the evidence, and manage the auditor relationship. A fractional CISO is the role most SOC 2 auditors expect to see named in the report.
What happens in an incident?
You call. Mike leads the response with your MSP, insurer, and counsel following a playbook we wrote together in advance. Incident leadership is inside the retainer, not an upsell.

One call, no deck

Start with a conversation.

Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.

info@foreffectai.comMill Creek, WA · Remote-first

Book a 20-minute conversation

Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.

Choose a time
or
Send a short note instead