Fractional chief information security officer

One person keeps the requirements closed all year.

From $2,500 per month · $21,600 for the onboarding programme.

Get a quote

Who decides what to do about security this year?

Nobody. Decisions get made one at a time, whenever the next piece of paper lands. A questionnaire closed. A policy renewed. An auditor survived. A year later it turns out you did the same thing three times and never built the one thing that would have covered it all at once.

A year's plan instead of answering the next email

Security gets an owner. You get a list of risks and a year's plan of work sized to your budget, and every new requirement fits into that plan instead of breaking it. This is a role, not a block of hours.

The work runs every month, not from one form to the next: policies get updated, client questionnaires are answered as they arrive, and the insurance renewal is prepared on a calendar rather than in the last week. If you are breached, we run the response.

Once a quarter you get a report for management or the board: what is done, what is left, what costs money next quarter and why.

What the role covers

  • included: A list of risks and a plan of work in order — sized to your budget
  • included: Written policies: we write them, update them and get them to your people
  • included: Client questionnaires — we answer them all year
  • included: The insurance renewal prepared on a calendar, not in the last week
  • included: A report to management or the board once a quarter
  • included: If you are breached, we run the response and talk to your clients
  • included: The time we take to answer you is written into the contract
  • paid to the vendor: Platform licences and auditor or assessor fees — at their own invoices

Your price

Up to fifty employees

$2,500 a month

A company with no security team of its own.

What the tier includes

  • included: Risks, written policies, questionnaires, a report each quarter

Several standards at once

$4,900 a month

A company that has outgrown a single standard.

What the tier includes

  • included: Everything above, plus work across several standards at once
  • included: We join the talks with your clients and your insurer

Inside your team

from $10,800 a month

A company where security needs attention every day.

What the tier includes

  • included: Everything above, plus working inside the team with a budget line of its own

Entry programme

$21,600 for 90 days

One-off work with an end date.

What the tier includes

  • included: Ninety days: kit inventory, access, recovery, a plan, a drill
  • included: A final pack of documents for your insurer and your clients

Extras

  • not included: Questionnaires your client has sent$1,350 per questionnaire
  • not included: SOC 2 readiness and keeping Type 2from $2,250
  • not included: CMMC readiness for defense contractorsfrom $3,360
  • not included: External penetration test of network and applicationsfrom $4,480
  • not included: We watch for attacks around the clock$18 per endpoint a month
  • not included: If you are breached, we investigate — monthly$670 a month
  • not included: Preparing for a cyber policy renewal$2,250 one-off
  • not included: Patient records kept protected+$40 per seat a month

Questions

How is this different from hiring someone in-house?

You have to find, pay, train and keep that person, and a forty-person company does not have a full-time job's worth of the work. Here the role costs a fixed sum each month, starts next week and ends when you say so.

We already have an IT provider. Do they handle this?

Usually not. He keeps the machines and the accounts running — that is a different job. The role answers for which requirements will land on you, what to do first and how to prove it. Who owns what goes on paper before we start, including the line with your provider.

How many hours a month do we get?

We do not sell hours. The role is measured by the work and by the time we take to answer, which is written into the contract. You will still see the hours in the quarterly report, so you know where the work went, but the invoice is for the role, not for them.

Can we start with something short?

Yes. That is what the ninety-day entry programme is for: it has an end date, and it ends with a pack of documents for your insurer and your clients. After that the role either continues month by month or it does not — you are under no obligation to renew.

Where to send the quote

Tell us which requirements are landing on you and who handles them today — we will send a quote by email.

When to start
Which requirements are landing on you