Chief Information Security Officer
Fractional CISO
The second most-established fractional role after CFO, and for the same reason: the need is compliance-triggered and finite. An enterprise customer conditions a contract on ISO 27001, a regulator names a required officer, an insurer asks for MFA and offline backup attestations before renewal — and a company of eighty people discovers it needs security judgment it cannot justify hiring full-time.
The division of labour matters. A part-time CISO sets direction: the risk register, the roadmap, certification readiness, the incident response plan, the answers to customer security questionnaires, the board pack. Monitoring, triage, penetration testing and incident handling stay with a managed provider or specialists on call. The model that works is direction bought fractionally and operations bought as a service. The model that fails is expecting one person two days a week to also watch the alerts.
What they deliver
- Security programme and a costed 12–18 month roadmap
- ISO 27001 or SOC 2 readiness, through to managing the external auditor
- Incident response plan mapped to each regulator’s notification clock, and the tabletop exercises to test it
- Enterprise customer security questionnaires — often the highest-return work on the whole mandate
- Third-party and vendor risk: tiering, diligence, contract security schedules
- Board and regulator reporting, and managing the MSSP or a small internal team
Signals you need one
- A customer has made ISO 27001 or a security questionnaire a condition of the contract
- You have had a breach, a ransomware scare, or a near-miss nobody formally closed out
- Cyber insurance renewal came back loaded, or declined
- A buyer or investor has commissioned technical due diligence
- Security has been the CTO’s side job and headcount is now past fifty
- You have security engineers but nobody senior enough to set the direction
Saudi Arabia and South Korea both require the named security officer to be an internal, full-time appointment — Saudi under NCA Essential Cybersecurity Controls 1-2-2, which requires cybersecurity roles to be filled by full-time Saudi nationals, and Korea under the Network Act, where the CISO is designated and reported to the Ministry of Science and ICT, with larger companies barred from letting that person hold unrelated duties. In both, a fractional CISO can advise the designated officer but cannot be them. Hong Kong is the opposite case: its critical infrastructure regime expressly allows the security management unit and its supervisor to sit outside Hong Kong, which makes it the most fractional-friendly regime in the region.
Fractional CISO by city
What this costs, and what governs it, changes materially by market. Start where the business is.