Fractional CISO · vCISO · Retainer

Fractional CISO (vCISO) — pass audits and security questionnaires without a full-time hire.

On-demand security leadership for startups and scale-ups: SOC 2, ISO 27001, PCI DSS and HIPAA readiness, security-questionnaire support, and audit sign-off — on a monthly retainer. Led by a CISA holder who also architects the AWS controls behind the policies.

Book a free 30-min callEmail me

What you get

What a fractional CISO does

  • Own your security program without a full-time C-level cost
  • Set risk-based priorities, policies and a compliance roadmap
  • Represent security to your board, customers and auditors

Frameworks & audits

  • SOC 2 Type 1/2, ISO 27001, PCI DSS, HIPAA, GDPR
  • Gap assessment, evidence automation, control implementation
  • Auditor liaison through to a clean report

Security questionnaires & deals

  • Answer customer/investor security questionnaires fast
  • Build a trust page + reusable answer library
  • Unblock enterprise deals stalled on security review

Technical, not just paper

  • Controls implemented in AWS (IAM, KMS, CloudTrail, Config), not just policy docs
  • Vendor & risk management, incident response, awareness training
  • CISA + AWS Pro: the rare mix of governance and hands-on engineering

Proof

0findings — SOC 2 Type 2 & PCI DSS engagements
8-14 wktypical time to audit-ready
Retainerfractional, scales with you
Fractional CISOvCISOSOC 2ISO 27001PCI DSSHIPAASecurity questionnairesRisk assessmentAWS controlsCISA
## What a fractional CISO does - and does not do

The title gets used loosely enough to be worth pinning down. A fractional CISO carries the security leadership function part-time: owning the security programme, making risk decisions, representing security to your board and to customers, and deciding what gets fixed in what order.

What that looks like week to week: setting and defending a risk position rather than producing a list of everything that could theoretically go wrong; owning the security questionnaire and audit response so engineers are not each answering the same questions differently; running vendor and third-party assessment; deciding which findings are accepted, which are mitigated and which stop a release; and translating between engineering reality and what a board or an enterprise buyer needs to hear.

What it is not: it is not a penetration test, and it is not a managed detection service watching your alerts overnight. It is not an engineer who will implement every control themselves, though in my case a good deal of hands-on AWS work comes with it. And it is not a signature for hire - accountability is real, which means occasionally telling you something you would rather not hear before a customer or a regulator does.

The distinction that matters commercially: a consultant produces a report and leaves; a fractional CISO owns the outcome and is still there when the auditor asks a follow-up question three months later.

## When you actually need one

Most companies reach for security leadership at one of a small number of moments, and recognising which one you are in tells you how much you need.

A deal is blocked

An enterprise prospect has sent a 200-question security questionnaire, or wants SOC 2 or ISO 27001 before signing. This is the most common trigger and the most time-boxed. The work is real but it has a definable end, and the mistake is over-committing to a permanent arrangement to solve a deal-shaped problem.

An audit or certification is due

SOC 2, ISO 27001, or a regulator-facing obligation. Needs sustained ownership across months rather than a burst, because the evidence has to accumulate and someone has to make scoping decisions that stick.

Something happened

A breach, a near-miss, or a finding that reached the board. The immediate need is competent incident handling; the durable need is the programme that stops it recurring, and the credibility to say what actually went wrong.

Growth outran the function

Post-funding, or headcount doubled, and security is being done informally by whichever engineer cares most. That works until it does not, and the failure is usually silent - controls that quietly stopped applying while everyone was busy.

If none of these describe you, you may not need a CISO of any kind yet, and I would rather say so than sell you an engagement. Good engineering hygiene - SSO with MFA, least privilege, code review, tested backups, patching that happens - covers a great deal before leadership overhead earns its keep.

## Fractional, full-time, or a managed service

The three options solve different problems and are routinely confused.

A full-time CISO makes sense once security is a continuous, organisation-wide concern - a large team to lead, a regulated environment with permanent obligations, or a threat profile that justifies constant attention. The cost is significant and, more importantly, the role is hard to fill well; a mediocre full-time hire is worse than good part-time leadership because the seat looks occupied.

A managed security service gives you monitoring and response capacity. It does not give you decisions. An MSSP will tell you an alert fired; it will not decide whether that finding blocks your release, or how to answer question 147 of a customer's questionnaire, or what risk your board should be told about. These are complements, not alternatives - plenty of companies need both.

A fractional CISO fits when you need the judgement and the accountability but not forty hours of it. In practice that is most companies between roughly twenty and a few hundred people, and the honest signal that you have outgrown it is when the fractional arrangement starts feeling like a bottleneck rather than a relief.

I will tell you which of the three I think you need. If the answer is a full-time hire, saying so early is more useful than a year of engagements that delay it.

## How the engagement is structured

Cadence matters more than volume. Security leadership delivered in an unpredictable burst produces documents; delivered on a rhythm it produces a programme.

A typical arrangement is a fixed monthly commitment - commonly one to four days a month depending on what is in flight - with a standing session, defined escalation for anything urgent, and a quarterly review that goes to whoever needs to see it. Audit periods and incidents are the exceptions where intensity spikes, and it is worth agreeing in advance how that is handled rather than negotiating it mid-incident.

What you should expect to receive: a risk register that reflects your business rather than a template; a prioritised roadmap with things that are explicitly not being done and why, which is the part that makes a roadmap honest; policies that match how you actually operate, because policies describing a fictional company fail audits; questionnaire and audit response handled rather than delegated back to engineering; and board-appropriate reporting that neither hides problems nor manufactures alarm.

Because my background is hands-on AWS and DevOps rather than governance alone, the implementation and the leadership tend to come together - see DevOps and compliance, ISO 27001, SOC 2 readiness and secure cloud landing zone. For how the two roles differ in practice, vCISO versus compliance consultant goes into it properly.

FAQ

What is a fractional CISO / vCISO?

A senior security leader engaged part-time (fractional) or virtually (vCISO) to run your security and compliance program on a retainer — the expertise of a CISO without the full-time salary.

When do I need one?

When customers or investors send security questionnaires, when you're pursuing SOC 2/ISO 27001, or when security decisions are piling up with no one senior to own them.

How does pricing work?

A monthly retainer scaled to scope and stage — typically far less than a full-time CISO, with the ability to dial up around audits and dial down after.

How is this different from a compliance consultant?

A consultant delivers a project; a fractional CISO owns the ongoing program, represents you to auditors and customers, and makes risk decisions — with the technical depth to implement controls in AWS, not just write policy. If you need the AWS platform built as well as governed, see fractional cloud & compliance architect.

How many hours a month is realistic?

One to four days a month covers most companies in steady state. An active SOC 2 or ISO 27001 push, or an incident, temporarily needs more. Be sceptical of an arrangement priced so low that the hours cannot cover a questionnaire cycle - the commitment will quietly become a name on a slide.

Can a fractional CISO sign off for our customers or insurers?

I can hold the role, represent security to customers and regulators, and provide the evidence and attestations that come with that. What I cannot do is provide independent assurance over my own work - certification, formal audit and penetration testing must come from separate parties. Anyone offering to implement, lead and independently assess is describing a conflict.

What happens when we hire someone full-time?

That is a successful outcome, and the engagement should be built to make it easy. Handover covers the risk register, the roadmap with its reasoning, vendor relationships, audit history and the decisions taken along the way. I am also happy to help assess candidates, since I will have a clear view of what the role actually requires by then.

Do you work with our existing engineers or replace them?

Work with them, always. The engineers know the system better than I will for the first several weeks, and a security function imposed over their heads produces compliance theatre rather than security. My job is to set direction and make the calls, not to take the keyboard away.

Are you available in our time zone?

Remote-first across US, UK, UAE, Australia and New Zealand hours, with overlap agreed as part of the engagement rather than left to chance. Incident escalation is defined up front - that is not a conversation to have for the first time during an incident.

Get CISO-level security without the full-time hire.

Free 30-minute call — tell me your stage, frameworks and any deals stuck on security review.

Book a callAll AWS DevOps services →