ESN

Fixed engagement

Fractional CISO & Security Program Leadership

For organizations carrying real security obligations without a full-time security executive. Ongoing ownership of the security program, board and executive reporting, vendor and audit management, incident response readiness, and the risk conversations that leadership actually needs answered.

From $8,000 / month
~30 hours monthly · three-month minimum Scope this engagement →

What's included

Ongoing ownership, not a one-time deliverable.

Who this fits

Best fit: 50 to 500 employees, no dedicated security leader.

Best fit is an organization of roughly 50 to 500 employees that is regulated or handles sensitive data, and does not have a dedicated security leader on staff today.

How it works

Every engagement is scoped before it starts.

A published price tells you what something costs. It does not tell you whether it is the right thing to buy — and those are different questions.

So the engagement begins with a conversation about what is actually going on, then a written scope covering the specific outcomes, what is included, what is not, the timeline, and who is responsible for what. You see that document before any money changes hands.

Questions

Frequently asked questions

What does a fractional CISO do month to month?

Ongoing ownership of the security program: board and executive reporting, vendor and audit management, incident response readiness, and the risk conversations leadership actually needs answered — about 30 hours a month.

How much does it cost?

From $8,000 per month, roughly 30 hours of work monthly, with a three-month minimum engagement.

Who is this a good fit for?

Organizations of roughly 50 to 500 employees that are regulated or handle sensitive data, and that don't have a dedicated security leader on staff today.

How does the engagement start?

With a conversation about what's actually going on, then a written scope covering outcomes, what's included, what isn't, the timeline, and who's responsible for what. You see that document before anything is committed.

Who is actually doing the work?

Tyson McKay, CISSP, with roughly 30 years of IT leadership including CIO and CISO roles in regulated healthcare and legal-technology environments — including taking a healthcare organization's security posture from 35% to 89% over three years.

Get started

Scope this engagement.

Tell me what's going on and I'll send back a written scope before anything is committed.

Scope this engagement → See all engagements →