Virtual CISO · Fractional CISO

A virtual CISO for companies that need security leadership now.

Senior security leadership on retainer: the roadmap, the compliance work, the vendor reviews, and the customer questions, owned by one accountable person instead of spread across your team.

  • CISSP
  • CISA
  • GSLC
  • CISO and vCISO
  • USMC veteran
  • 29 years in the field
01 — The role

What a virtual CISO actually does

A virtual chief information security officer carries the same responsibilities as a full-time CISO, on the fraction of the schedule your company actually needs.

Owns the security roadmap

One prioritized plan tied to your business risk and your deadlines, reviewed and updated on a set cadence instead of rebuilt every time something breaks.

Runs the compliance program

Framework selection, gap assessment, policies, controls, and evidence. Whether the driver is a customer, an auditor, an insurer, or a regulator, the program is built to survive the review.

SOC 2 · ISO 27001 · HIPAA · CMMC · PCI DSS · NIST · GLBA

Answers your customers

Security questionnaires, diligence requests, and enterprise vendor reviews handled by someone who can speak to the controls with authority, so deals stop stalling in procurement.

Manages vendor and third-party risk

A defensible process for reviewing the vendors you depend on, sized for a small team rather than copied from an enterprise playbook.

Prepares you for incidents

Incident response plan, roles, and tabletop exercises, plus the reporting obligations that come with your frameworks and your cyber insurance policy.

Reports to your board and your buyers

Plain-language reporting on where the program stands, what changed, and what needs funding next, in a form your board, investors, or largest customer will accept.

02 — Pricing

What it costs

Fixed monthly retainers, billed monthly, scoped on a discovery call before anything is signed. Each tier states what it includes, so you know where the line is before we start.

Advisory

Small teams with a specific driver and internal hands to do the work.

$2,000 / month

  • One working session each month
  • Security roadmap and risk register, kept current
  • Review of policies and documents you send over
  • Email and Slack access between sessions

Embedded

Regulated or high-scrutiny companies that need a named security executive.

$12,000 / month

  • Everything in Core Program
  • Named CISO of record for customers and auditors
  • Weekly cadence with your leadership team
  • Audit and examination support, up to 40 hours per audit cycle
  • Incident response leadership
  • Unlimited questionnaires and vendor reviews

Not sure which fits? Most companies start in Core Program during a certification push and step down to Advisory once the program is running. Project work such as an ISO 27001 implementation or a risk assessment is quoted as a fixed fee instead of a retainer.

Beyond what's included: work past the limits in your tier, and one-off requests outside an active retainer, are quoted and agreed in writing before anything starts. Retainer clients are billed at a reduced rate for that work. Security team hiring and mentoring is available as an add-on.

03 — The alternatives

Virtual CISO, fractional CISO, or a full-time hire

The terms get used interchangeably. What matters is how much senior attention you need and what you're willing to carry.

A full-time CISO

Right when security is core to your product or your regulator expects a named executive on staff. It's also a six-figure salary plus benefits and equity, and a hiring process that takes months you may not have.

A virtual or fractional CISO

The same seniority on a set monthly commitment, starting in weeks rather than months. You get the judgment of someone who has built these programs before without the fixed cost of an executive hire.

A consulting firm

Useful for a defined project, less so for continuity. You often get a senior name in the pitch and junior staff on the work. Here, the person on the call is the person doing the work.

Your IT provider or MSP

They keep systems running, which is a different job from owning risk decisions, answering an auditor, or signing off on what a customer is told. Most MSPs will say the same thing.

04 — Getting started

How an engagement begins

No procurement marathon. From first call to work starting is usually about two weeks.

01

Discovery call

Thirty minutes on what's driving this, what you've already got, and what your deadline looks like. You leave with a straight answer on whether I can help.

02

Scope and proposal

A written scope of services with the tier, the deliverables, and the fee. Nothing open-ended, and no hourly meter running.

03

First 90 days

A prioritized plan in the first weeks, then execution against it. You'll know what's being worked on and what's coming next at every point.

Next step

Ready to talk?

Thirty minutes, no pitch. Bring your deadline and whatever you've got so far, and we'll scope it honestly.