Services
Fractional CISOFractional CIOAI Readiness & Security AuditStrategic Implementation
Who we serve
NonprofitsChurches & ministriesSmall businessesMSP partners
Company
AboutCase studiesInsightsContactStart with a conversation →

Fractional CIO & CISO leadership for nonprofits and small businesses.

A part-time technology and security executive with public-company and federal experience — executive judgment on security, compliance, and safe AI adoption, without the executive salary.

Leadership experience
ExpediaConcurAccoladeVacasaCoalfireU.S. NavyExpediaConcurAccoladeVacasaCoalfireU.S. Navy

The situation

You run an organization that matters. Somewhere between the board deck, the vendor renewals, the insurance questionnaire, and the AI tool your staff already installed, nobody owns the technology risk. Not because your team isn’t capable — because that job belongs to an executive you can’t hire full-time.

ForEffect is that executive, a few days a month. Strategy, security, compliance, and AI governance handled by someone who has done it inside public companies and federal systems — and who explains it in plain English.

How we work

Three ways to put a CIO and CISO on your side.

Most clients start with a 30-day audit, then keep us on as their fractional executive. Some need hands on the keyboard for a defined project. Each one is scoped in a conversation, not a form.

Entry point · 30 days

AI Readiness & Security Audit

A fixed-scope, 30-day assessment of your AI strategy, security posture, and compliance gaps. You get a prioritized roadmap your board can read and your IT partner can execute — not a 90-page PDF that gathers dust.

  • Where AI is already in use, sanctioned or not, and what it touches
  • Security posture against NIST CSF 2.0, mapped to the frameworks your customers ask about
  • A ranked, costed roadmap with the first 90 days spelled out
NIST CSF 2.0 · current-state tiers
Deliverable · prioritized roadmapAbout the audit
Ongoing · monthly retainer

Fractional CIO / CISO Most popular

A part-time technology executive on your leadership team. Strategy, vendor oversight, board reporting, compliance, and incident response — the calls a CIO and CISO make, made by one who has held both titles.

  • Monthly steering with leadership; quarterly reporting for the board
  • Owner of your risk register, policies, and vendor and cyber-insurance questionnaires
  • First call when something goes wrong, with a plan already written
Where the fractional executive sits
Cadence · monthly + quarterly boardAbout the retainer
Project · scoped per engagement

Strategic Implementation

Hands-on delivery when the roadmap needs building: AI integration with guardrails, security program rollouts, and automation that connects the tools you already own — no new software to buy.

  • Governed AI workflows on top of your existing systems
  • Security program build-outs: policies, controls, evidence, and the people who run them
  • Fixed scope, fixed timeline, one accountable executive
Only your tools, plus the guardrails
Terms · custom, scoped per projectAbout implementation

What a fractional executive actually does

The work between the org chart and the outage.

01of 06
Strategy

A technology plan the board can fund.

Three-year roadmap, annual budget, and the two or three bets that actually move the mission. Written for trustees, not engineers.

ROADMAPBUDGETBOARD DECK
Security

A program, not a product.

Controls chosen for your risk, an owner for each one, and evidence you can hand to an auditor, an insurer, or an enterprise customer.

NIST CSF 2.0SOC 2ISO 27001
AI governance

Adopt AI without inheriting its risk.

An acceptable-use policy, a tool inventory, and guardrails around the workflows that touch member, donor, or patient data.

NIST AI RMFPOLICYINVENTORY
Compliance

Questionnaires answered with a straight face.

HIPAA, PCI DSS, CMMC, grant and cyber-insurance requirements — mapped once to a single control set so you stop answering the same question five ways.

HIPAAPCI DSSCMMC
Vendors & MSPs

Someone on your side of the contract.

Renewal reviews, SLA accountability, and a second opinion before the next platform purchase. Your IT provider gets a peer, not a critic.

RENEWALSSLA REVIEWDUE DILIGENCE
Incident response

The plan exists before the phone rings.

Tabletop exercises, a written playbook, insurer and counsel on speed dial, and a calm voice on the call when it matters.

PLAYBOOKTABLETOPCOMMS

Track record

Twenty years securing public companies and federal systems. Now on call for yours.

The judgment behind ForEffect was formed running IT and security for travel, healthcare, and government platforms, auditing banks and credit unions, and serving as a U.S. Navy officer. That is the bar we bring to a church, a clinic, or a twelve-person firm.

0+Years in security leadership
0Days · audit to roadmap
0Business day to a reply
CISSPCertified Information Systems Security Professional(ISC)²
CISACertified Information Systems AuditorISACA
CMACertified Management AccountantIMA
NIST CSF 2.0NIST AI RMFCMMCHIPAAPCI DSSSOC 2ISO 27001

Client voices

Leaders who wanted a partner, not a vendor.

“What stood out about working with Mike and ForEffect was that they took the time to understand how our church actually operates before writing a line of code.”

AJ
Alex JohnsonExecutive Pastor, Gold Creek Community Church

“As an early-stage company, we couldn’t justify a full-time security hire, but we still had enterprise customers asking hard questions.”

TR
Tristan ReesCo-Founder & COO, Code Lexica

Leadership

One executive. Both chairs. Fifteen years of holding them.

Mike McGee has led IT and information security as a VP and CISO inside public companies and federal programs, audited financial institutions as an IT security auditor, and served thirteen years as a surface warfare officer in the U.S. Navy. He founded ForEffect so organizations without a seven-figure IT budget could have the same quality of decision-making.

He holds an MBA in Financial Management from the Naval Postgraduate School and a B.S. in Economics from the U.S. Naval Academy — which is why the budget conversation and the security conversation happen in the same meeting.

VP, IT & Information SecurityVACASA
CISO · SVP Government SolutionsACCOLADE
Director, Information SecurityEXPEDIA
Director, Security & ComplianceCONCUR
IT Security AuditorCOALFIRE
Surface Warfare OfficerU.S. NAVY

Read Mike’s full background

Who we serve

Built for the organizations a full-time CISO was never priced for.

Each of these has its own page, its own proof, and the same first conversation.

Questions we hear

Frequently asked

What is a fractional CIO or CISO?
A senior technology or security executive who works with your organization part-time — typically a few days a month — carrying the same responsibilities a full-time CIO or CISO would: strategy, risk, vendor oversight, compliance, board reporting, and incident leadership. You get the judgment without the salary, benefits, and recruiting cost of a full-time hire.
How is ForEffect different from a managed service provider (MSP)?
An MSP runs your technology day to day: help desk, patching, backups, monitoring. ForEffect sits on your leadership team and decides what should be run, why, and to what standard — then holds vendors, including your MSP, accountable to it. Most of our clients keep their MSP; we work alongside them.
What does an engagement cost?
Every engagement is scoped in the first conversation. The 30-day AI Readiness & Security Audit is a fixed fee; the fractional CIO/CISO retainer is a flat monthly fee based on cadence and scope; implementation projects are quoted per project. We publish real numbers when we scope, not surprises after.
Where do you work?
ForEffect is based in Mill Creek, Washington, in the Seattle area, and works remote-first. Most clients are in Washington State; we also serve organizations across the United States, with on-site time when it matters.
How quickly can we start?
An audit can usually begin within two weeks of the first conversation. Retainers typically start with a 30-day onboarding month so the first steering meeting has a real risk register in front of it.

One call, no deck

Start with a conversation.

Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.

info@foreffectai.comSeattle · Remote-first

Book a 20-minute conversation

Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.

Choose a time
or
Send a short note instead