---
title: "Fractional chief information security officer"
description: "One person owns security: risks, written policies, questionnaires, insurance, board report. From $2,500 a month, $21,600 for the entry programme."
locale: en
canonical: https://finleadgen.com/en/services/fractional-ciso
source: https://finleadgen.com/en/services/fractional-ciso.md
price_reviewed: 2026-08-06
---

# Fractional chief information security officer

One person keeps the requirements closed all year.

**From $2,500 per month · $21,600 for the onboarding programme.**

## Who decides what to do about security this year?

Nobody. Decisions get made one at a time, whenever the next piece of paper lands. A questionnaire closed. A policy renewed. An auditor survived. A year later it turns out you did the same thing three times and never built the one thing that would have covered it all at once.

## A year's plan instead of answering the next email

Security gets an owner. You get a list of risks and a year's plan of work sized to your budget, and every new requirement fits into that plan instead of breaking it. This is a role, not a block of hours.

The work runs every month, not from one form to the next: policies get updated, client questionnaires are answered as they arrive, and the insurance renewal is prepared on a calendar rather than in the last week. If you are breached, we run the response.

Once a quarter you get a report for management or the board: what is done, what is left, what costs money next quarter and why.

## What the role covers

| What | State | Price |
| --- | --- | --- |
| A list of risks and a plan of work in order — sized to your budget | included |  |
| Written policies: we write them, update them and get them to your people | included |  |
| Client questionnaires — we answer them all year | included |  |
| The insurance renewal prepared on a calendar, not in the last week | included |  |
| A report to management or the board once a quarter | included |  |
| If you are breached, we run the response and talk to your clients | included |  |
| The time we take to answer you is written into the contract | included |  |
| Platform licences and auditor or assessor fees — at their own invoices | paid to the vendor |  |

## Your price

| Plan | Price | Note |
| --- | --- | --- |
| Up to fifty employees | $2,500 a month | A company with no security team of its own. |
| Several standards at once | $4,900 a month | A company that has outgrown a single standard. |
| Inside your team | from $10,800 a month | A company where security needs attention every day. |
| Entry programme | $21,600 for 90 days | One-off work with an end date. |
**Up to fifty employees**
- Risks, written policies, questionnaires, a report each quarter
**Several standards at once**
- Everything above, plus work across several standards at once
- We join the talks with your clients and your insurer
**Inside your team**
- Everything above, plus working inside the team with a budget line of its own
**Entry programme**
- Ninety days: kit inventory, access, recovery, a plan, a drill
- A final pack of documents for your insurer and your clients

## Extras

| What | State | Price |
| --- | --- | --- |
| Questionnaires your client has sent | not included | $1,350 per questionnaire |
| SOC 2 readiness and keeping Type 2 | not included | from $2,250 |
| CMMC readiness for defense contractors | not included | from $3,360 |
| External penetration test of network and applications | not included | from $4,480 |
| We watch for attacks around the clock | not included | $18 per endpoint a month |
| If you are breached, we investigate — monthly | not included | $670 a month |
| Preparing for a cyber policy renewal | not included | $2,250 one-off |
| Patient records kept protected | not included | +$40 per seat a month |

### How is this different from hiring someone in-house?

You have to find, pay, train and keep that person, and a forty-person company does not have a full-time job's worth of the work. Here the role costs a fixed sum each month, starts next week and ends when you say so.

### We already have an IT provider. Do they handle this?

Usually not. He keeps the machines and the accounts running — that is a different job. The role answers for which requirements will land on you, what to do first and how to prove it. Who owns what goes on paper before we start, including the line with your provider.

### How many hours a month do we get?

We do not sell hours. The role is measured by the work and by the time we take to answer, which is written into the contract. You will still see the hours in the quarterly report, so you know where the work went, but the invoice is for the role, not for them.

### Can we start with something short?

Yes. That is what the ninety-day entry programme is for: it has an end date, and it ends with a pack of documents for your insurer and your clients. After that the role either continues month by month or it does not — you are under no obligation to renew.

## Where to send the quote

Tell us which requirements are landing on you and who handles them today — we will send a quote by email.
