CFrFractionalOFind a firm

Chief Information Security Officer

Fractional CISO

The second most-established fractional role after CFO, and for the same reason: the need is compliance-triggered and finite. An enterprise customer conditions a contract on ISO 27001, a regulator names a required officer, an insurer asks for MFA and offline backup attestations before renewal — and a company of eighty people discovers it needs security judgment it cannot justify hiring full-time.

The division of labour matters. A part-time CISO sets direction: the risk register, the roadmap, certification readiness, the incident response plan, the answers to customer security questionnaires, the board pack. Monitoring, triage, penetration testing and incident handling stay with a managed provider or specialists on call. The model that works is direction bought fractionally and operations bought as a service. The model that fails is expecting one person two days a week to also watch the alerts.

What they deliver

  • Security programme and a costed 12–18 month roadmap
  • ISO 27001 or SOC 2 readiness, through to managing the external auditor
  • Incident response plan mapped to each regulator’s notification clock, and the tabletop exercises to test it
  • Enterprise customer security questionnaires — often the highest-return work on the whole mandate
  • Third-party and vendor risk: tiering, diligence, contract security schedules
  • Board and regulator reporting, and managing the MSSP or a small internal team

Signals you need one

  • A customer has made ISO 27001 or a security questionnaire a condition of the contract
  • You have had a breach, a ransomware scare, or a near-miss nobody formally closed out
  • Cyber insurance renewal came back loaded, or declined
  • A buyer or investor has commissioned technical due diligence
  • Security has been the CTO’s side job and headcount is now past fifty
  • You have security engineers but nobody senior enough to set the direction
Two markets where this does not work

Saudi Arabia and South Korea both require the named security officer to be an internal, full-time appointment — Saudi under NCA Essential Cybersecurity Controls 1-2-2, which requires cybersecurity roles to be filled by full-time Saudi nationals, and Korea under the Network Act, where the CISO is designated and reported to the Ministry of Science and ICT, with larger companies barred from letting that person hold unrelated duties. In both, a fractional CISO can advise the designated officer but cannot be them. Hong Kong is the opposite case: its critical infrastructure regime expressly allows the security management unit and its supervisor to sit outside Hong Kong, which makes it the most fractional-friendly regime in the region.

Tell us what is going on

We reply within one working day.