Fractional CISO
The clearest signal is carrying real security obligations, regulatory requirements, client security questionnaires, a cyber insurance policy, without anyone internally accountable for the program. A full-time CISO salary, fully loaded with benefits, typically runs well into six figures; fractional coverage gets the same ownership at a fraction of that, which is usually the right first step before a full-time hire is justified by headcount and revenue.
Signals it's time
A few concrete signals: you're answering vendor security questionnaires ad hoc with no one owning the answers consistently. You have compliance obligations, HIPAA, cyber insurance requirements, client contracts, without a named person responsible for the program. Leadership gets asked security questions in board meetings or client calls and doesn't have a confident answer. Or you've had a scare, a near-miss incident, a failed audit finding, that made it obvious nobody currently owns this.
Best fit for a fractional engagement is roughly 50 to 500 employees, regulated or handling sensitive data, with no dedicated security leader today. Above that range, or once the hours commitment consistently exceeds what fractional coverage can absorb, a full-time hire usually makes more sense, and a fractional CISO can help build the case and the job description for that hire.
Questions
When it carries real security or compliance obligations without anyone accountable for the program, and the hours needed each month do not yet justify a full-time salary. Best fit is roughly 50 to 500 employees, regulated or handling sensitive data.
A full-time CISO with benefits typically runs well into six figures annually. Fractional coverage delivers the same ownership starting from $8,000/month for roughly 30 hours of monthly coverage.
Get started
Tell me what's going on and I'll send back a written scope before anything is committed.