Fractional CISO · vCISO
A Chief Information Security Officer, a few days a month.
Security strategy, a living risk register, compliance evidence, vendor oversight, and a calm voice when something goes wrong — from a CISO who has held the title inside public companies and federal programs.
The situation
You have security tools. You don’t have a security owner.
The firewall is managed, the backups run, the MSP sends a monthly report. And still nobody in the building can answer the insurer’s questionnaire, sign off on the new AI tool, or tell the board what the actual top three risks are.
The risk register
One living list of what could hurt the organization, ranked, with an owner and a date against each item. Reviewed monthly, reported quarterly.
Policies people follow
Acceptable use, access, incident response, vendor management, AI use — written at the length your staff will actually read, and mapped to the frameworks your customers ask about.
Evidence on demand
When SOC 2, HIPAA, PCI DSS, CMMC, a grant, or a cyber-insurance renewal asks for proof, it exists already — one control set answering every questionnaire.
Vendor and MSP oversight
Your IT provider gets a peer, not a critic. Renewal reviews, SLA accountability, a second opinion before the next platform purchase.
Incident leadership
A written playbook, a tabletop exercise each year, insurer and counsel identified in advance, and an executive on the call who has run one before.
Board-level reporting
A quarterly security report a trustee can read in ten minutes, with the decisions leadership needs to make stated plainly.
How it runs
A predictable rhythm, not a hotline.
Onboard
Discovery, a baseline against NIST CSF 2.0, the first risk register, and the policy gap list. Your first steering meeting has real material in front of it.
Steer
A standing meeting with leadership: what changed, what is due, what needs a decision. Between meetings, email and a short response window for anything urgent.
Report
Board or executive report, risk register refresh, compliance calendar update, vendor and insurance renewals reviewed before they land.
Reset
Tabletop exercise, policy review, roadmap and budget for the year ahead, and a plain-spoken assessment of whether the retainer still fits.
Proof
Judgment formed where the stakes were highest.
The bar was set running information security for travel, healthcare, and government platforms, auditing banks and credit unions as an IT security auditor at Coalfire, and thirteen years as a U.S. Navy surface warfare officer. It is the same bar we bring to a church, a clinic, or a twelve-person firm.
“As an early-stage company, we couldn’t justify a full-time security hire, but we still had enterprise customers asking hard questions.”
Questions we hear
Frequently asked
What is the difference between a vCISO and a fractional CISO?
Do we still need our MSP?
How many hours a month is it?
Can you help with SOC 2 or HIPAA?
What happens in an incident?
One call, no deck
Start with a conversation.
Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.
Book a 20-minute conversation
Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.
Choose a time