Services / 05

Fractional CISO

A named security leader inside your leadership team, part-time: strategy, budget, board reporting and vendor decisions without the full-time hire.

STRATEGYBOARDROADMAP
Overview

What the practice does.

You get a specific person, not a rotating bench. They attend your leadership meetings, own the security roadmap, report to your board, hold your vendors to account and make the decisions a CISO makes.

Behind them sits the rest of our practice: testers, assessors, incident responders and the products we built for the work. You pay for the days you need.

What you get

Deliverables.

Each item is something you keep: a document, a register, a plan. All of it is scoped and priced before the work starts.

01

A named CISO on a fixed cadence

One, two or more days a week, with a deputy who knows your environment for cover. The cadence flexes around audits, incidents and board cycles.

02

Security program and roadmap

A written program with priorities, owners, budget and measures, reviewed quarterly with leadership.

03

Board and executive reporting

Quarterly board papers and someone who can stand in front of directors, auditors and customers and answer the hard question.

04

Vendor, contract and architecture decisions

Security review of major purchases, contract language, and the architecture calls that are expensive to reverse.

05

Incident leadership

When something happens, your CISO runs the response alongside your team, with our incident response practice behind them.

How it runs

The four steps, applied.

The method is the same for every practice. This is what each step means here.

01 / SCOPE

A 30-day onboarding: current-state review, stakeholder interviews, risk register and a first roadmap agreed with leadership.

02 / TEST

The program runs. Controls are implemented, tested and measured. Your CISO is in the room when decisions are made.

03 / VERIFY

Each quarter an independent consultant from our practice reviews progress against the roadmap, so the person running the program is not the only one grading it.

04 / REPORT

Monthly operating report, quarterly board paper, annual program review.

When to call us

The situations this is built for.

Too big to have nobody, too small for a full-time hire

Security decisions are being made by whoever is nearest. You need an owner with authority and a budget.

A customer, regulator or insurer wants a named accountable executive

Enterprise contracts, SOC 2 and cyber insurance increasingly expect someone to own security by name.

You are between CISOs or building toward one

Cover the gap, stabilise the program and leave a well-documented role for the permanent hire to step into.

Questions

Asked before most engagements.

How many days a week?

Most clients run one or two days a week, with more during audits, incidents and major projects. The cadence is set in the engagement and reviewed quarterly.

Will the same person show up?

Yes. You get a named CISO and a named deputy. Continuity is the point.

Can the fractional CISO also do the testing?

No, and that is deliberate. Testing and assessment are done by other consultants in the practice so your CISO is not grading their own work.

Request a quote

Tell us what you need tested, assessed or governed.

A consultant, not a sales team, replies within one business day with a scope and a fixed price. For self-serve testing, go straight to Frontier Verify.

Start on Frontier Verify