The security leader you don't have to hire full-time
You need someone accountable for security: setting the strategy, fielding the board's questions, still in the room when a control fails three weeks before an audit. That's the CISO job description. We do it fractionally, strategy with your leadership team, execution with your engineers, one person accountable for both.
Somewhere between 20 and 150 employees, security stops being something your CTO handles between sprints and turns into a board-level question. A full-time CISO costs real money: salary, equity, a team underneath them. Most companies that size don't need one five days a week. They need one who shows up when it matters and stays accountable in between.
This isn't a slide deck and a quarterly check-in. Your vCISO sets the roadmap with your leadership team, then works directly with engineering and IT to build it. Same person writing the strategy memo and configuring the MFA policy. Nobody hands off a plan and disappears.
Some weeks that's light: a standing call, a policy review, an email thread. During a SOC 2 audit, a fundraise, or an incident, it's a lot more. Either way, you have one name attached to security instead of a responsibility scattered across people who already have full-time jobs and no time to own it properly.
What's included
Security strategy & roadmap
A prioritized plan tied to deals you're trying to close and risk you're actually carrying, not a framework checklist copied from a template.
Board & investor reporting
Updates your board can actually use to make a decision, not a slide full of red, yellow, and green icons.
Program ownership
One person accountable for policies, controls, tooling, and the vendor decisions that come with all of it.
Customer & vendor security reviews
We take the security questionnaire and the vendor risk call off your plate and own the answer.
Incident readiness
A response plan and a tabletop exercise, so the first real incident isn't the first time anyone's thought about one.
Direct access
Slack, email, a standing call. An actual member of the team, not a support ticket.
Frequently asked questions
How is this different from hiring a full-time CISO?
A full-time CISO is a six-figure salary before equity, benefits, or a supporting team, and most companies under 200 employees don't have five days a week of CISO-level work to fill. A fractional CISO gives you the same accountability and the same strategic ownership, scoped to what your business actually needs this quarter.
Will this replace our CTO or IT team?
No. We're not there to compete with your CTO for authority. We're there to take security off a plate that's already full. Your vCISO owns the security program; your team keeps shipping product. Where the work touches engineering, we work with them directly, not around them.
Can this scale up during an audit or a fundraise?
Yes. That's the whole point of the model. Hours flex up during a SOC 2 push, due diligence, or an active incident, then come back down to steady-state once things settle. You're not paying full-time rates for a part-time need, or scrambling to find help when the need spikes.
What does a typical week actually look like?
Depends where you are. Early on: stakeholder interviews, gap assessment, roadmap. In steady state: a standing sync, whatever's currently in flight, and being reachable when a questionnaire lands or your board asks a pointed question.
Ideal for
- Startups and scale-ups with no dedicated security leader
- Companies moving upmarket where enterprise deals require security sign-off
- Boards and investors that expect a real answer to who owns security here
- Teams where security responsibilities are split between the CTO, a Slack channel, and hope
Related services
Ready to talk through Fractional CISO?
The audit's in six weeks. The questionnaire's due Friday. Let's talk Tuesday. Book a free consultation and we'll tell you straight what it takes to get your program built, certified, and operating.