Fractional and virtual CISO

Security leadership for companies that just got asked to prove it.

Virtual CISO leadership and ISO 27001, SOC 2, and compliance programs built to hold up when a customer, an auditor, or a regulator looks closely.

  • CISSP
  • CISA
  • GSLC
  • CISO and vCISO
  • USMC veteran
  • 29 years in the field
01 — Services

What I'm usually called in for

Three situations account for most engagements. If yours looks like one of these, we should talk.

A compliance deadline you can't miss

A framework has become a condition of doing business. I build the program end to end — risk analysis, policies, controls, and the evidence to back them up — so it survives the first serious look.

SOC 2 · ISO 27001 · HIPAA · CMMC · PCI DSS · NIST · and others

A deal blocked by a security review

An enterprise customer sent a questionnaire and the answers aren't there yet. I organize the evidence, answer what's answerable, and close the gaps that are holding up signature.

Questionnaires · Diligence · Evidence packages

Security leadership you can't yet hire

You need someone accountable for the security program without carrying a full-time executive. A virtual CISO on retainer covers the roadmap, vendor risk, and board and customer reporting.

Fractional CISO · Virtual CISO (vCISO) retainer

Retainers start at $2,000/month — see what each tier includes

What it costs: vCISO retainers run $2,000, $6,500, or $12,000 per month depending on scope, billed monthly against a written scope of services. Project work such as an ISO 27001 implementation is quoted as a fixed fee. See the tiers.

02 — ISO 27001

ISO 27001, from scoping to certification

For companies whose customers, partners, or overseas buyers now require certification. I build the ISMS to ISO/IEC 27001:2022 with your team and stay with you through both audit stages.

01

Scope and gap assessment

Define what the ISMS covers and measure where you stand against the standard and Annex A. You get a gap report and a realistic timeline to certification.

02

Risk assessment and treatment

A documented risk methodology, a risk register, and a treatment plan. This decides which controls you need and why, and it's the first thing an auditor tests.

03

Build the ISMS

Policies, procedures, and controls written for how your company actually operates, plus a Statement of Applicability that ties every Annex A control to a decision.

04

Internal audit and management review

Both are required before certification, and both are commonly left too late. They're completed and documented before the certification body arrives.

05

Stage 1 and Stage 2 audit support

I prepare you for both stages, support you during the audits, and work through any nonconformities until the certificate is issued.

Already have SOC 2? Much of the control work carries over, so ISO 27001 is usually a shorter project than starting from scratch. Certification is issued by an accredited certification body; my role is getting you ready to pass.

03 — Process

How engagements work

No open-ended hourly arrangements. Scope and price are agreed before work starts.

01

Discovery call

Thirty minutes. What's driving the deadline, what's already in place, and what you're actually obligated to do — which is often narrower than you've been told.

02

Written scope of work

A fixed fee against defined deliverables, each with a stated completion standard. You know what you're getting and what it costs before anyone signs.

03

Built, documented, handed over

The program is yours to run when I'm done — editable policies, a live risk register, and a compliance calendar. Retainer support afterward is optional, not assumed.

Every engagement is scoped and priced to what the situation actually requires. Retainers are scoped separately.

04 — Background

Who you'd be working with

Jason Hamilton, founder of INeedACISO

I'm Jason Hamilton. I've spent nearly thirty years in security leadership across financial services, healthcare, technology, and defense — building and running programs in regulated environments where the work has to hold up under outside scrutiny.

Most of my work is with small and mid-sized companies facing a requirement they haven't had to meet before. They rarely need a scaled-down enterprise program. They need the parts that carry real weight, documented well enough to defend, and nothing they'll never use.

I've worked across the major regulatory and security frameworks. Whatever standard is in front of you, the conversation starts the same way: what are you actually obligated to do, and what will it take to prove it.

Next step

Ready to talk?

Thirty minutes, no pitch. Bring your deadline and whatever you've got so far, and we'll scope it honestly.