Fractional CISO
Fractional CISO engagements typically run from around $5,000 to $15,000 a month, depending on company size, regulatory exposure, and how many hours of coverage you need. My own rate is published rather than quoted: Fractional CISO & Security Program Leadership starts from $8,000 a month, for roughly 30 hours of monthly coverage, with a three-month minimum.
What drives the price
The number moves on three things: how many hours of coverage the business actually needs each month, whether the business carries real regulatory obligations (HIPAA, cyber insurance requirements, client security questionnaires), and how mature the existing security program is when I start. A company with no documented program and an upcoming audit costs more attention in month one than a company that already has policies in place and just needs ongoing ownership.
What's included at my rate: ongoing ownership of the security program, board and executive reporting, vendor and audit management, incident response readiness, and the risk conversations leadership actually needs answered. That's the difference between a fractional CISO and a one-time assessment: the assessment ends, the fractional role doesn't.
Why publish a number at all
Most fractional CISO pricing lives behind a "let's hop on a call" wall. I publish mine because a business evaluating whether it can afford real security leadership shouldn't have to sit through a sales conversation just to learn the range. The published number is the starting point; the actual scope still gets written down before anything is committed.
Questions
Typically $5,000 to $15,000 a month across the market, depending on hours and regulatory exposure. My own rate starts from $8,000/month for roughly 30 hours of monthly coverage, three-month minimum.
It's almost always a monthly retainer tied to an expected hours commitment, not an hourly rate, because the role is ongoing ownership, not project work billed by the hour.
It includes ownership: board and executive reporting, vendor and audit management, incident response readiness, and the day-to-day decisions, not just periodic advice.
Get started
Tell me what's going on and I'll send back a written scope before anything is committed.