Fractional CISOA named security leader on a retainer
You need experienced security leadership, but a $400K salary isn't in the cards. With fractional CISO services, you get board reporting, strategic planning, and compliance oversight - without the full-time cost.

Trusted by
Comprehensive Security Leadership
Everything you'd expect from a full-time CISO - strategy, governance, compliance, and technical guidance - tailored to your organization's size and needs.
Security Strategy & Roadmap
A prioritized, multi-year security roadmap aligned with your business objectives and risk tolerance.
Board & Executive Reporting
Quarterly security reports that communicate risk in business terms, not technical jargon.
Risk Assessment & Management
Ongoing risk identification, assessment, and treatment planning with regular reviews.
Compliance Program Oversight
SOC 2, HIPAA, PCI DSS, ISO 42001, ISO 27701, HITRUST, DORA, NIS2, CMMC, FISMA, FINRA - managed and monitored.
Vendor Security Reviews
Third-party risk assessments to ensure your vendors meet your security standards.
Incident Response Planning
IR playbooks, tabletop exercises, and on-call support for security incidents.
Security Awareness Training
Program oversight and custom training for your team's specific risk profile.
Security Architecture Review
Ongoing guidance on security tooling, cloud architecture, and technical decisions.
Starting ranges
Starting at $2k for SMB. Most retainers are $10k. Growth is the default for an audit, raise, or AI rollout. Enterprise is extra leadership capacity, not a SOC.
Foundation
For small and mid-size businesses
10-15 hrs/month
For SMBs that need a named security owner, a roadmap, and templates. Ten to fifteen hours a month. Not the tier for an audit, raise, or AI rollout.
- Monthly strategic check-in
- Security roadmap development
- Basic risk assessment
- Policy templates & review
- Email support
Growth
For scaling companies
20-30 hrs/month
The default for an audit, raise, or AI rollout. Twenty to thirty hours, board materials, and compliance program ownership.
- Bi-weekly strategic calls
- Board presentation support
- Compliance program management
- Vendor security reviews
- Incident response support
- Security awareness oversight
- Priority support
Enterprise
For complex organizations
40+ hrs/month
Full executive capacity for complex organizations. Not a SOC. I coordinate incidents with your team and your MDR; I do not staff around-the-clock operations.
- Weekly executive alignment
- Board meeting attendance
- Multi-framework compliance
- M&A due diligence support
- Team mentorship
- Priority incident coordination
- Custom deliverables
All engagements start with a 30-minute call to understand your needs. No long-term contracts required - we can adjust scope as your needs evolve.
Included vs. Add-ons
Transparent pricing means knowing exactly what your retainer covers.
Included
Core Fractional CISO Services
Security Strategy & Roadmap
Multi-year alignment with business goals
Board Risk Reporting
Quarterly presentations in business language
Policy Management
Creation and annual review of core policies
Vendor Security Reviews
Assessment of third-party risk
Compliance Oversight
Ongoing maintenance of SOC 2 / HIPAA controls
Incident Response Support
Guidance during security events
Add-ons
Available for additional fees
Initial Audit Preparation
Heavy lifting for first-time SOC 2/ISO audits
Technical Testing
Penetration testing and vulnerability scanning
Third-Party Audits
Cost of external auditors (e.g. CPA firms)
On-site Travel
Expenses for in-person visits outside home region
Full-time Hiring Support
Recruiting and interviewing permanent staff
Common Questions
Answers to frequently asked questions about fractional CISO services.
Client Success Stories
Financial Services / Healthcare, Technology / GovTech results from prior engagements.
See if a fractional CISO is the fit
Thirty minutes is enough to see whether fractional CISO services are the right next step, or if a lighter path will get you through the next deadline.










