Singapore · Chief Information Security Officer
Fractional CISO in Singapore
The second most-established fractional role after CFO, and for the same reason: the need is compliance-triggered and finite. An enterprise customer conditions a contract on ISO 27001, a regulator names a required officer, an insurer asks for MFA and offline backup attestations before renewal — and a company of eighty people discovers it needs security judgment it cannot justify hiring full-time.
A foreign-owned SME frequently cannot obtain an Employment Pass for a full-time foreign executive because of COMPASS. Contracted leadership is the only legal route to that expertise.
What they deliver
- Security programme and a costed 12–18 month roadmap
- ISO 27001 or SOC 2 readiness, through to managing the external auditor
- Incident response plan mapped to each regulator’s notification clock, and the tabletop exercises to test it
- Enterprise customer security questionnaires — often the highest-return work on the whole mandate
- Third-party and vendor risk: tiering, diligence, contract security schedules
- Board and regulator reporting, and managing the MSSP or a small internal team
Signals you need one
- A customer has made ISO 27001 or a security questionnaire a condition of the contract
- You have had a breach, a ransomware scare, or a near-miss nobody formally closed out
- Cyber insurance renewal came back loaded, or declined
- A buyer or investor has commissioned technical due diligence
- Security has been the CTO’s side job and headcount is now past fifty
- You have security engineers but nobody senior enough to set the direction
Saudi Arabia and South Korea both require the named security officer to be an internal, full-time appointment — Saudi under NCA Essential Cybersecurity Controls 1-2-2, which requires cybersecurity roles to be filled by full-time Saudi nationals, and Korea under the Network Act, where the CISO is designated and reported to the Ministry of Science and ICT, with larger companies barred from letting that person hold unrelated duties. In both, a fractional CISO can advise the designated officer but cannot be them. Hong Kong is the opposite case: its critical infrastructure regime expressly allows the security management unit and its supervisor to sit outside Hong Kong, which makes it the most fractional-friendly regime in the region.
The Singapore numbers
The full Singapore picture — tax, regulation and market context →
What governs this in Singapore
Employment Pass qualifying salary and COMPASS
EP salary floor S$5,600 at age 23 rising to S$10,700 at 45+, and higher in financial services; rising again in January 2027. Stage 2 requires 40 COMPASS points, and the local-employment-share criterion is the one that defeats small foreign-owned entities. Exemption from COMPASS at a fixed monthly salary of S$22,500.
Fair Consideration Framework
A fourteen-day MyCareersFuture advertisement is required before most EP applications. Non-compliance leads to debarment from work pass privileges.
Companies Act s.145
At least one director must be ordinarily resident in Singapore, and a company secretary must be appointed within six months. Foreign-owned entities usually buy a nominee resident director — a live governance question when the fractional executive is the only senior person on the ground.
IRAS withholding tax
Non-resident director’s fees 24%; non-resident professionals 15% of gross. Crucially, there is no withholding where the services are performed wholly outside Singapore — the single most important line in a cross-border fractional contract.