Fractional CISO and security leadership

Security leadership on a part-time basis. Someone who owns the risk, gets you through Cyber Essentials and ISO 27001, and answers the questionnaires from insurers and clients honestly.

Why businesses bring in a fractional CISO

The trigger is rarely a breach. More often it's a client's supplier questionnaire, a cyber insurance renewal with forty questions nobody can answer, or a board that has read one too many headlines. Security has become a leadership responsibility, but a full-time Chief Information Security Officer is out of reach for most SMEs.

A fractional CISO gives you that leadership for a few days a month. You get a clear view of where you stand, a plan to close the gaps that matter and someone accountable for keeping it on track.

What's included

  • Risk assessment. A plain-English view of your real exposure, ranked by likelihood and impact rather than by what a vendor is selling this quarter.
  • Security roadmap. Prioritised actions with owners and dates, most of which use the Microsoft 365 licences you already pay for.
  • Cyber Essentials and Cyber Essentials Plus. Scoping, remediation and getting you through the assessment.
  • ISO 27001 readiness. Gap analysis, policies that reflect how you actually work, and support up to certification audit.
  • Insurance and client questionnaires. Accurate answers, and fixes where the honest answer is currently "no".
  • Policies and incident response. An acceptable use policy people will read, an AI policy, and an incident plan that has been rehearsed at least once.
  • Board and audit reporting. Regular, short reports on security posture that a non-technical board can understand.

Microsoft-first, not tool-first

Most SMEs already own good security tooling through Microsoft 365 Business Premium: Entra ID Conditional Access, Intune, Defender for Business and Purview. The problem is usually configuration, not missing products. We start there before recommending anything new, and we're independent of resellers, so there's no incentive to add another subscription.

Security cleared

Our consultants hold UK SC and DV clearance and are used to working in secure, regulated and sensitive environments. That matters if you handle sensitive data, work in the public sector supply chain or simply want someone who treats discretion as normal.

How it works

We begin with a short security review, then agree a fixed monthly retainer, typically one to three days a month. Some clients start with a fixed-scope project, such as Cyber Essentials Plus, and move to a retainer afterwards. One utilities broker started with us on a fractional basis and the role grew into an ongoing, full-time engagement.

If you also need wider technology leadership, the CISO role can sit alongside a fractional CTO engagement.

Common questions

What is a fractional CISO?

A fractional CISO is a senior security leader who works with your business part time, usually a few days a month, and takes on the responsibilities of a Chief Information Security Officer: security strategy, risk, compliance and reporting to the board.

Is a vCISO the same as a fractional CISO?

Broadly, yes. Virtual CISO and vCISO are common names for the same service. Some providers use vCISO for a lighter, remote advisory service, so it is worth checking how much time and accountability is actually included.

Can you help us get Cyber Essentials?

Yes. We scope the assessment, fix what needs fixing and prepare you for Cyber Essentials or Cyber Essentials Plus. For most Microsoft 365 businesses the work is mainly configuration of tools you already own.

Do you sell security products?

No. We are independent of vendors and resellers, so recommendations are based on your risk rather than on margin.

Clouds gathering? Book a call.

Tell us a little about your business and what's on your mind. We reply personally, usually within one working day.

Book a call