A trusted adviser in the room.
Senior security leadership input, a few days a month, alongside your CISO. A sounding board for the big calls, a sharper board narrative, and practical help where the program needs it. Your leader stays in charge.
What fractional advisory covers
- A sounding board on material risk calls
- A second pair of eyes on the board paper and the risk narrative
- Practical help where the program is stuck
- Program reviews that end in clear, prioritised actions
- Mentoring so capability stays with your leader and their team
When there is no CISO in the seat
Some organisations have real cyber risk and a board that expects it to be managed, but no one senior enough to own it.
In those cases I can take a fractional CISO seat for an agreed number of hours each month. I'm not an auditor who delivers a report and leaves. I roll my sleeves up and help the organisation get better, month by month.
- A security strategy and roadmap tied to your business priorities
- Practical guidance for your IT team and managed service providers
- Ownership of key policies, the cyber risk register and the incident response plan
- Regular reporting to your executive team and board or risk committee, including attending meetings
- Oversight of security risk in your suppliers and third parties
- Mentoring your people so capability grows inside the organisation
How a fractional CISO engagement runs
- Foundation (first 90 days). I get to know your business, assess where you stand, agree priorities with your executive team, and deliver a first report to your board.
- Ongoing leadership. A monthly arrangement with agreed hours and a steady rhythm: regular check-ins with your leadership, monthly executive updates, and quarterly reporting to the board or risk committee.
- Review. We review progress and priorities together at least annually. Engagements run for a minimum of six months.
When something goes wrong
During a serious incident, I help coordinate the response and keep your executive team and board informed, working alongside specialist incident response providers. We agree how this works up front, so there are no surprises on the day.
Who the fractional CISO seat suits
- Organisations with a board and meaningful cyber risk, but no full-time CISO
- Organisations whose IT is largely outsourced and want an independent senior voice on security
- Leadership teams who want security to be part of how the business runs, not a separate technical project
A small number of organisations at a time
I work with only a few organisations at once, so each gets genuine attention and continuity.
