Skip to main content

Service

Fractional CISO (vCISO) Services for Your Organization

A named CISO, a few days a month, at your leadership table.

Security sits on your desk, the board is asking questions, and there is no one senior to answer them. A fractional CISO takes on that role: a named executive who owns the priorities, the board conversations, and a security program your team can actually run.

For you if

  • Your board asks cybersecurity questions and no one at the table can answer with confidence.
  • You are accountable for incidents, without the authority or the budget to prevent them.
  • Law 25 (Quebec) landed on your desk, on top of everything else you already manage.
  • A client or an insurer is asking for a security program, and you do not know where to start.
  • Security is slowing a critical project and no one knows how to unblock it.

What you get

  • A clear picture of where you stand. The risks that matter, ranked, in business terms.
  • A security program your team can run. Priorities, owners, budget, and a roadmap your board can read.
  • A CISO in the room. Leadership meetings, board briefings, and the questions from your auditor, your clients, and your insurer.
  • Compliance handled inside the program. Law 25 (Quebec), ISO 27001, NIST CSF, SOC 2, or client questionnaires, without a separate effort.
  • Independent advice on tools and vendors. Based on your context and your budget only.
  • An incident response plan your team has rehearsed. So the first call follows a procedure.

How it works: the first 90 days

  1. Days 1 to 30

    Assess

    We meet your leaders and your IT team, read what exists, and name the risks that matter. You leave the month with a plain-language picture and a short list of what comes first.

  2. Days 31 to 60

    Build

    With your team, we turn that list into a twelve-month roadmap your board can read, put the quick wins in place, and set up governance.

  3. Days 61 to 90

    Operate

    The program runs with its indicators, compliance work starts, risk reporting has a cadence, and your team is being coached to carry more of it.

Engagement options

Three ways to engage. All are monthly, six months minimum, and all start with the same first month of assessment.

  1. Essential

    2 days a month

    For the leader who carries security on top of everything else.

    Monthly advisory session, quarterly board-ready report, priorities kept current, Law 25 (Quebec) guidance.

  2. Strategic

    4 to 6 days a month

    For the CISO or VP who has the title and needs a peer at their side.

    Full program leadership, board advisory with quarterly presentations, compliance management, vendor guidance, incident response planning, team coaching.

  3. Embedded

    Scoped to your program

    For the VP Transformation or CTO whose critical program needs security inside it. This tier covers the whole security function, the program included; for a single program on its own calendar, see the Security inside your transformation mandate.

    Everything in Strategic, plus a seat in transformation governance, security built into your delivery method, cross-team coaching, and a reporting dashboard for your steering committee.

Discuss your situation

Every engagement starts with a conversation about where you stand.

Frequently asked questions

What is a fractional CISO?

An experienced security executive who leads your security function a few days a month, on a recurring basis, and owns its priorities and outcomes. The cadence is sized to your situation. Also called a vCISO. You get the leadership, the board presence, and the program without a full-time hire.

Fractional CISO or vCISO: what is the difference?

None in what you get. Both terms describe a part-time CISO. “Virtual” emphasizes the delivery model, often remote. “Fractional” emphasizes the time of a named executive, like a fractional CFO. At InfoSec, your fractional CISO is a named person, present at your leadership meetings, on site or remotely as your situation requires.

How much does a fractional CISO cost?

Engagements are monthly, in three tiers, from two days a month to a scope sized to your program, six months minimum. Three factors set the fee: the number of days a month, the scope of the program, and the cadence of your leadership meetings and your board. We give you a figure in the first conversation, once we know your situation.

What is the difference between a fractional CISO and a consultant?

A fractional CISO stays with you: leadership meetings, board briefings, the program, the follow-through. Think of a physician who knows your file rather than a specialist you see once.

Why a six-month minimum?

Because the first month is an assessment, the next two build the program, and the rest is where results show. Shorter than that, you get a report. Six months, you get a running program.

What if an incident happens?

Your CISO stays with leadership and the team through the incident: decisions, notifications, communication with clients, the insurer and the regulator, then lessons learned. We are neither a monitoring centre nor a 24-hour emergency line: the technical response stays with your team or your provider, and the response plan we build with you says who to call.

Do you replace our IT team?

No. Your IT team executes; the fractional CISO sets direction, prioritizes, and coaches. The goal is a team that carries more of the security work itself over time.

Can a fractional CISO handle Law 25 (Quebec)?

Yes. Privacy officer support, impact assessments, incident process, policies, all inside the security program.

Which framework do you use?

The one that fits your obligations and your clients: NIST CSF, ISO 27001, CIS Controls. We choose the one that serves your business.

How fast do we see results?

The first month ends with a clear picture and a short list of priorities. Quick wins go in during month two. By month three the program is running.

Want clarity on where you stand? Let's talk.

Tell us where you stand. We'll help you see which risks matter and where to start.

Discuss your situation