Skip to main content
CISSP-ISSAP · 20+ Years · #10 OnCon Icon, 2022

Fractional CISOA named security leader on a retainer

You need experienced security leadership, but a $400K salary isn't in the cards. With fractional CISO services, you get board reporting, strategic planning, and compliance oversight - without the full-time cost.

Your board gets clarity
Your team stays focused
Your security scales

Trusted by

  • The Coca-Cola Company
  • Cigna
  • Optum Health
  • Lumen Technologies
  • Fannie Mae
  • Marriott
  • CDW
  • WWT
  • Carter's
  • Katalon
  • Hood Container
  • Envista Forensics
  • Cardow Jewelers
  • COR Partners
  • Eberl's
  • Payspan
  • ABM
What's Included

Comprehensive Security Leadership

Everything you'd expect from a full-time CISO - strategy, governance, compliance, and technical guidance - tailored to your organization's size and needs.

Security Strategy & Roadmap

A prioritized, multi-year security roadmap aligned with your business objectives and risk tolerance.

Board & Executive Reporting

Quarterly security reports that communicate risk in business terms, not technical jargon.

Risk Assessment & Management

Ongoing risk identification, assessment, and treatment planning with regular reviews.

Compliance Program Oversight

SOC 2, HIPAA, PCI DSS, ISO 42001, ISO 27701, HITRUST, DORA, NIS2, CMMC, FISMA, FINRA - managed and monitored.

Vendor Security Reviews

Third-party risk assessments to ensure your vendors meet your security standards.

Incident Response Planning

IR playbooks, tabletop exercises, and on-call support for security incidents.

Security Awareness Training

Program oversight and custom training for your team's specific risk profile.

Security Architecture Review

Ongoing guidance on security tooling, cloud architecture, and technical decisions.

Pricing Guidance

Starting ranges

Starting at $2k for SMB. Most retainers are $10k. Growth is the default for an audit, raise, or AI rollout. Enterprise is extra leadership capacity, not a SOC.

Foundation

For small and mid-size businesses

Starting at $2,000/mo

10-15 hrs/month

For SMBs that need a named security owner, a roadmap, and templates. Ten to fifteen hours a month. Not the tier for an audit, raise, or AI rollout.

  • Monthly strategic check-in
  • Security roadmap development
  • Basic risk assessment
  • Policy templates & review
  • Email support
See if I should be in the room
Where most work starts

Growth

For scaling companies

Starting at $10,000/mo

20-30 hrs/month

The default for an audit, raise, or AI rollout. Twenty to thirty hours, board materials, and compliance program ownership.

  • Bi-weekly strategic calls
  • Board presentation support
  • Compliance program management
  • Vendor security reviews
  • Incident response support
  • Security awareness oversight
  • Priority support
See if I should be in the room

Enterprise

For complex organizations

Custom pricing

40+ hrs/month

Full executive capacity for complex organizations. Not a SOC. I coordinate incidents with your team and your MDR; I do not staff around-the-clock operations.

  • Weekly executive alignment
  • Board meeting attendance
  • Multi-framework compliance
  • M&A due diligence support
  • Team mentorship
  • Priority incident coordination
  • Custom deliverables
See if I should be in the room

All engagements start with a 30-minute call to understand your needs. No long-term contracts required - we can adjust scope as your needs evolve.

Scope Clarity

Included vs. Add-ons

Transparent pricing means knowing exactly what your retainer covers.

Included

Core Fractional CISO Services

  • Security Strategy & Roadmap

    Multi-year alignment with business goals

  • Board Risk Reporting

    Quarterly presentations in business language

  • Policy Management

    Creation and annual review of core policies

  • Vendor Security Reviews

    Assessment of third-party risk

  • Compliance Oversight

    Ongoing maintenance of SOC 2 / HIPAA controls

  • Incident Response Support

    Guidance during security events

Add-ons

Available for additional fees

  • Initial Audit Preparation

    Heavy lifting for first-time SOC 2/ISO audits

  • Technical Testing

    Penetration testing and vulnerability scanning

  • Third-Party Audits

    Cost of external auditors (e.g. CPA firms)

  • On-site Travel

    Expenses for in-person visits outside home region

  • Full-time Hiring Support

    Recruiting and interviewing permanent staff

FAQ

Common Questions

Answers to frequently asked questions about fractional CISO services.

A consultant typically delivers a specific project or assessment and moves on. A fractional CISO becomes an ongoing member of your leadership team - attending meetings, building relationships with your team, and providing continuity over time. I'm invested in your long-term security posture, not just delivering a report.

Next step

See if a fractional CISO is the fit

Thirty minutes is enough to see whether fractional CISO services are the right next step, or if a lighter path will get you through the next deadline.