Watch DemoRead About It
Browse ServicesService Provider InfoSign In / Up
IT & Cyber SecurityAll statesComing soon

Virtual / Fractional CISO

Service description

A Fractional or Virtual CISO is a cybersecurity expert who, rather than being a full-time employee, is hired on a part-time or project basis. They offer expertise, guidance, and strategic leadership for developing and implementing tailored information security practices based on an organization’s unique needs. Fractional CISOs most often refer to on-site Chief Information Security Officers. Most fractional CISOs are part-time cybersecurity experts and maintain other IT roles within or outside the company. Virtual CISOs most often refer to outsourced cybersecurity teams. Instead of maintaining cybersecurity personnel as payroll employees, you can hire an outside agency whose primary role is to build and maintain IT security. As the name implies, virtual CISOs work off-site and provide vCISO services to a portfolio of clients.

Common industries

Applies to small and mid-size companies, especially those whose customers ask about security.

ROI

Executive security guidance at a fraction of a full-time CISO's cost, accelerating deals that hinge on security maturity.

Benefit

Part-time senior security leadership to build your security program, policies, and roadmap and to answer customer security questionnaires — without a full-time hire.

Why get it

Security decisions need senior judgment, but a full-time executive is out of reach for many businesses. A fractional leader sets the program and answers customer and insurer questions.

When you benefit

Ongoing part-time, often a set number of hours monthly, or a project to build the first program.

What it costs

Typically a monthly retainer.

When you pay

Providers usually charge a monthly retainer sized to the hours or scope agreed, such as program oversight and customer questionnaires. Project work, like writing policies or a roadmap, may be priced as a fixed fee.

Other costs

Security tools and any testing, audit or certification the program calls for, plus staff time to carry out the recommendations.

Risks to know

The business stays accountable for its security and for any breach, whatever the contract says. Under the FTC Safeguards Rule, a covered financial institution may use an outside provider as its Qualified Individual but keeps responsibility for compliance and must oversee that provider. A part-time leader can also be stretched thin during an incident.

When risks arise

Gaps in coverage show up during an incident or when a customer's security review arrives. Policies written but not carried out are usually found at an audit or after a breach.

The process

The provider assesses current security, then sets priorities in a roadmap and writes or updates policies. The business approves the plan and carries out the work, with the provider guiding progress, reporting to leadership and answering customer questionnaires on an agreed schedule.

Your commitment

The business gives the provider access to its systems, vendors and current policies, and names an executive sponsor. It should set how many hours the provider works, who can call on them in an incident, and who carries out the actions they recommend.

Documents to gather

Helpful reading

Further research

Suggest an edit to this page →

Not open yet

Virtual / Fractional CISO isn’t taking requests yet. Join the waitlist. It is listed in your requests tray.