Capability & Resourcing

Fractional CISO / Virtual CISO

Board-grade security leadership at the fraction of a role that you actually need.

The situation

Most organisations between 50 and 1,000 people need genuine security leadership but cannot justify or attract a full-time CISO.

A fractional CISO gives them a named, senior, certified security executive for an agreed commitment each month: owning the strategy, chairing the governance, facing the board and the regulator, and managing whatever mix of internal staff and suppliers delivers the work. Under NIS2, where management bodies are personally accountable, this is increasingly a governance necessity rather than a convenience.

What the client receives

Schedule of deliverables

  1. 01Named senior security leader with agreed monthly commitment
  2. 02Security strategy and multi-year roadmap ownership
  3. 03Board and audit committee reporting and attendance
  4. 04Governance forum chairing and policy ownership
  5. 05Supplier and security budget management
  6. 06Regulator and auditor interface
  7. 07Escalation path into the full CYBERVETTER practice

Frameworks and standards

Assessment is carried out against named references, so a conclusion can be traced back to the requirement it was measured against.

  • NIST CSF 2.0
  • ISO/IEC 27001
  • NIS2 Art. 20
  • CISM / CISSP practice

Discuss this engagement

Tell us about the mandate, the reporting line and the commitment you need and we will set out the scope, the method and the reporting format.

Contact us