
EXECUTIVE SECURITY LEADERSHIP, WITHOUT THE HEADCOUNT.
The problem
Most mid-market and mid-size enterprise organisations sit in an uncomfortable gap. They are large enough that the board is asking about cyber risk, and a regulator may be asking too. They are not large enough — or not yet ready — to justify a full-time CISO at market rate.
So the responsibility lands somewhere it does not belong. Usually on an IT Director who is already running infrastructure and service delivery, and who has neither the mandate to say no to the business nor the standing to take a position to the board.
The symptoms are consistent. Security decisions are made by whoever raised the ticket. There is no risk appetite anyone can state. Compliance work is done reactively, in the weeks before an audit. And when the board asks "are we secure?", the answer is a list of the tools that have been purchased.
None of that is a resourcing problem. It is an absence of security leadership — and leadership is not a full-time-equivalent calculation.
What the role actually is
Design authority. Someone with the standing to approve or reject a design, and the technical depth to be right.
Board translation. Converting technical risk into financial exposure the board can weigh against every other investment on the table.
Regulatory ownership. A named individual accountable for the organisation's position against the frameworks it reports to.
Capability development. Building the internal team's judgement so the dependency reduces over time rather than deepening.
OUR APPROACH
-
Establish the mandate before anything else. A fractional CISO without decision rights is an expensive advisor. We agree in writing what we can approve, what we escalate, who we report to, and what happens when the business disagrees with us.
-
Baseline the position honestly, in the first thirty days. Current capability, regulatory exposure, the three things that would hurt most, and what the board currently believes — which is often materially different from reality.
-
Set a risk appetite in monetary terms. Using Open FAIR methodology, priority scenarios are expressed as probable annualised loss ranges. Until a board has approved a number, every subsequent security investment is a matter of persuasion rather than assessment.
-
Build the governance rhythm. A security steering forum that makes decisions, an Architecture Review Board that gates designs, a board reporting pack that says something. Monthly and quarterly cadence, defined agendas, tracked actions.
-
Run the architecture and regulatory programme. Target-state architecture, dependency-ordered roadmap, framework assessment cycles, third-party assurance. This is where the retained days are actually spent.
-
Develop the internal team, deliberately. Mentoring, design review with your engineers present, and documented decision rationale so the reasoning stays when we leave. The objective is a reducing dependency, not a permanent one.
ENGAGEMENTS
VC-01 Fractional CISO — Retained
Typical duration: 4-6 days/month, 12 month minimum
Full role: governance, architecture authority, board reporting, regulatory ownership
VC-02 Fractional CISO — Light
Typical duration: 2-3 days/month
Governance cadence, board reporting, escalation point. Architecture on call-off
VC-03 First 90 Days
Typical duration: 15-20 days
Baseline, risk appetite, governance design, prioritised roadmap. Standalone or as onboarding
VC-04 CISO Transition Support
Typical duration: 3-5 days/month, 6 months
Bridging a departure, or mentoring a first-time CISO into the role
VC-05 Board Cyber Advisory
Typical duration: 1-2 days/quarter
Board or audit committee only. No operational role
WHAT A FRACTIONAL CISO CANNOT DO
We would rather set this out plainly than have you discover it later.
We cannot be your incident commander at two in the morning. At four days a month, we are not an on-call function. We will design your incident response capability, exercise it, and support you through the aftermath of a serious incident — but you need either an internal responder or a retained IR provider. We will help you select one.
We cannot substitute for an internal security team. A fractional CISO with no one to direct is a consultant writing documents. The model works where there is at least some internal capability to lead.
We cannot carry your regulatory accountability. Regulatory obligations attach to your organisation and its officers. We can own the programme, produce the evidence and represent you technically. The accountability remains yours — and any provider suggesting otherwise is misleading you.
We will not stay longer than we are useful. If the right answer is to hire a permanent CISO, we will say so and help you write the specification and interview for it.
