ESN

Fractional CISO

What does a fractional CISO actually do?

A fractional CISO owns the security program the same way a full-time CISO would, just on a part-time hours commitment. That means ongoing ownership of the program itself, board and executive reporting, vendor and audit management, incident response readiness, and being the person leadership actually asks the risk questions to, not a consultant who shows up quarterly with a slide deck.

From $8,000 / month
~30 hours monthly · three-month minimum Fractional CISO & Security Program Leadership →

The actual job

Ownership, not staff augmentation and not a one-time audit.

Two things a fractional CISO is often confused with: a security engineer who implements tools, and an auditor who assesses and leaves. It's neither. The role is accountable ownership of the program, which in practice looks like: keeping policies current, running vendor risk reviews, sitting in on audits as the person who can answer for the program, being the escalation point if something goes wrong, and translating security posture into terms the board and executives can actually act on.

Best fit is a company between roughly 50 and 500 employees that's regulated or handles sensitive data, and doesn't have anyone internally whose job it is to own this. Below that range, a fixed-scope assessment or advisory hours often make more sense than an ongoing retainer.

Questions

Frequently asked questions

What does a fractional CISO actually do?

Owns the security program: board and executive reporting, vendor and audit management, incident response readiness, and the ongoing risk decisions, on a part-time monthly hours commitment rather than a full-time role.

Is a fractional CISO the same as a security consultant?

No. A consultant typically advises or assesses and then leaves. A fractional CISO holds ongoing, accountable ownership of the program between engagements, not just at the start.

Get started

Talk it through.

Tell me what's going on and I'll send back a written scope before anything is committed.

Start a conversation → See Fractional CISO & Security Program Leadership →