top of page

EXECUTIVE SECURITY LEADERSHIP, WITHOUT THE HEADCOUNT.

The problem

Most mid-market and mid-size enterprise organisations sit in an uncomfortable gap. They are large enough that the board is asking about cyber risk, and a regulator may be asking too. They are not large enough — or not yet ready — to justify a full-time CISO at market rate.

So the responsibility lands somewhere it does not belong. Usually on an IT Director who is already running infrastructure and service delivery, and who has neither the mandate to say no to the business nor the standing to take a position to the board.

 

The symptoms are consistent. Security decisions are made by whoever raised the ticket. There is no risk appetite anyone can state. Compliance work is done reactively, in the weeks before an audit. And when the board asks "are we secure?", the answer is a list of the tools that have been purchased.

 

None of that is a resourcing problem. It is an absence of security leadership — and leadership is not a full-time-equivalent calculation.

What the role actually is

Design authority. Someone with the standing to approve or reject a design, and the technical depth to be right.

Board translation. Converting technical risk into financial exposure the board can weigh against every other investment on the table.

 

Regulatory ownership. A named individual accountable for the organisation's position against the frameworks it reports to.

Capability development. Building the internal team's judgement so the dependency reduces over time rather than deepening.

OUR APPROACH

  1. Establish the mandate before anything else. A fractional CISO without decision rights is an expensive advisor. We agree in writing what we can approve, what we escalate, who we report to, and what happens when the business disagrees with us.

  2. Baseline the position honestly, in the first thirty days. Current capability, regulatory exposure, the three things that would hurt most, and what the board currently believes — which is often materially different from reality.

  3. Set a risk appetite in monetary terms. Using Open FAIR methodology, priority scenarios are expressed as probable annualised loss ranges. Until a board has approved a number, every subsequent security investment is a matter of persuasion rather than assessment.

  4. Build the governance rhythm. A security steering forum that makes decisions, an Architecture Review Board that gates designs, a board reporting pack that says something. Monthly and quarterly cadence, defined agendas, tracked actions.

  5. Run the architecture and regulatory programme. Target-state architecture, dependency-ordered roadmap, framework assessment cycles, third-party assurance. This is where the retained days are actually spent.

  6. Develop the internal team, deliberately. Mentoring, design review with your engineers present, and documented decision rationale so the reasoning stays when we leave. The objective is a reducing dependency, not a permanent one.

ENGAGEMENTS

VC-01 Fractional CISO — Retained

Typical duration: 4-6 days/month, 12 month minimum

Full role: governance, architecture authority, board reporting, regulatory ownership

VC-02 Fractional CISO — Light

Typical duration: 2-3 days/month

Governance cadence, board reporting, escalation point. Architecture on call-off

VC-03 First 90 Days

Typical duration: 15-20 days

Baseline, risk appetite, governance design, prioritised roadmap. Standalone or as onboarding

VC-04 CISO Transition Support

Typical duration: 3-5 days/month, 6 months

Bridging a departure, or mentoring a first-time CISO into the role

VC-05 Board Cyber Advisory

Typical duration: 1-2 days/quarter

Board or audit committee only. No operational role

WHAT A FRACTIONAL CISO CANNOT DO

We would rather set this out plainly than have you discover it later.

We cannot be your incident commander at two in the morning. At four days a month, we are not an on-call function. We will design your incident response capability, exercise it, and support you through the aftermath of a serious incident — but you need either an internal responder or a retained IR provider. We will help you select one.

 

We cannot substitute for an internal security team. A fractional CISO with no one to direct is a consultant writing documents. The model works where there is at least some internal capability to lead.

 

We cannot carry your regulatory accountability. Regulatory obligations attach to your organisation and its officers. We can own the programme, produce the evidence and represent you technically. The accountability remains yours — and any provider suggesting otherwise is misleading you.

 

We will not stay longer than we are useful. If the right answer is to hire a permanent CISO, we will say so and help you write the specification and interview for it.

FRAMEWORKS APPLIED

NCA ECC-2:2024 · UAE Information Assurance Standard v2 · SAMA Cyber Security Framework · NIST CSF 2.0 · ISO/IEC 27001:2022 · NCSC CAF v4.0 · Open FAIR · NIST SP 800-161r1

Led by a practitioner holding CISSP, CISM and Associate C|CISO, with 28 years in IT and cybersecurity.

bottom of page