← Solutions
CyberPopular

Fractional CISO

Senior security leadership a few days a month: strategy, risk, board reporting and compliance, without the cost of a full-time CISO.

Typical timing
90-day start, then 2–8 days a month
Engagement
Monthly retainer
Delivery framework
User researchDiscoveryAlphaBetaLive

Give the organisation an accountable security leader who sets the strategy, owns the risk register, reports to the board, answers customer due-diligence questionnaires and directs the work, at a fraction of a full-time executive’s cost.

  • Security sits with the IT manager or CTO on top of the day job
  • Customers, insurers or investors ask for a named security lead
  • Plenty of security activity, but no strategy connecting it
How it runs

Activities, step by step

The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.

  1. 01 · User researchDays 1–30

    Listen

    • Interviews with leadership, IT and key suppliers
    • Review of policies, incidents, audits and insurance
    • Crown-jewel assets and risk appetite identified
  2. 02 · DiscoveryDays 31–60

    Assess and plan

    • Maturity assessment against NCSC CAF or NIST CSF 2.0
    • Risk register built and rated
    • Twelve-month security roadmap and budget
  3. 03 · AlphaDays 61–90

    Quick wins

    • Highest-risk gaps closed first
    • Security governance forum established
    • First board report delivered
  4. 05 · LiveMonthly

    Lead

    • Roadmap delivery directed and reported
    • Customer questionnaires and audits handled
    • Incident leadership when it matters

Days flex with the calendar — more around audits and incidents, fewer in steady state.

Deliverables

What you keep at the end.

  • 90-day assessment and twelve-month security roadmap
  • Risk register and security policy set
  • Quarterly board security report
  • Supplier and third-party risk process
  • Named security lead for customers and auditors

Outcomes

What it is built to change.

  • Security spend directed at the risks that matter
  • Faster sales through confident answers to due diligence
  • A board that understands its cyber risk

Often combined with

Every engagement starts with a 45-minute working session with the SME who would own the work. No deck.

Discuss Fractional CISO