Fractional CISO
Chief Information Security Officer, part-time
A Fractional CISO is a senior security leader who works with your company part-time to assess cyber risk, set security policy, prepare you for audits and certifications, and lead the response if something goes wrong. They treat security as a business risk, not just an IT task.
What is a Fractional CISO?
Companies of 200 to 500 people hold valuable customer, payment and employee data, but rarely have a dedicated security leader. Meanwhile, large clients, insurers and regulators increasingly ask for evidence of security controls before they sign, renew or pay out.
A Fractional CISO turns security into a managed programme: a clear picture of your risks, a ranked list of fixes, policies people follow, a plan for incidents, and evidence ready when someone asks for it.
What a Fractional CISO does
Risk and strategy
- Runs a cyber risk assessment and keeps the risk register
- Sets the security roadmap and budget
- Reports cyber risk to the CEO and board
Policies and controls
- Writes information security policies
- Sets rules for access, passwords and multi-factor authentication
- Defines backup and recovery requirements
- Checks the security of suppliers and partners
Compliance and certification
- Checks data protection compliance in each market
- Prepares you for CSA Cyber Essentials, Cyber Trust or ISO/IEC 27001
- Answers client security questionnaires with evidence
- Supports cyber insurance applications
Incident readiness
- Writes the incident response plan
- Runs tabletop exercises with your leadership team
- Leads the response during a live incident, with forensic, legal and regulator contacts
People and awareness
- Runs phishing simulations
- Sets up security awareness training
- Secures how staff join, move and leave
How your company benefits
Win and keep larger clients
Ready answers and recognised certifications shorten security reviews during sales and renewals.
Fewer successful attacks
Closing common gaps such as weak access controls, missing updates and untested backups blocks many everyday attacks.
A faster, calmer response
A tested incident plan means people know who to call and what to do in the first hours.
Legal duties met
Data protection laws in Singapore, Malaysia and Indonesia require reasonable security and, for serious breaches, notifying regulators within set deadlines.
Easier insurance
Insurers ask about controls such as multi-factor authentication and backups. Having them in place makes cover easier to get.
Security leadership, sized to you
You pay for the days you need instead of a full-time CISO package.
Signs you need a Fractional CISO
Tick the ones that sound like your company.
How it works
Your first 90 days
- Days 1 to 30
Assess
Review systems, access, data flows and suppliers, run a phishing test, and build a ranked risk register.
- Days 31 to 60
Fix
Close the highest risks such as multi-factor authentication, backups and admin access, publish core policies and draft the incident plan.
- Days 61 to 90
Prove
Run a tabletop exercise, prepare evidence for questionnaires, plan the certification path and report to the board.
A typical month
- Week 1Security steering meeting with leadership
- Week 2Control checks and supplier reviews
- Week 3Questionnaires, audits and awareness
- Week 4Risk report and board update
Example for an Embedded CISO at 4 days a month. In an incident, your CISO steps in immediately.
What you receive
- Cyber risk register with ranked fixes
- Security roadmap and budget
- Information security policy set
- Incident response plan and exercise report
- Data protection compliance review
- Library of answers for security questionnaires
- Phishing test results and awareness plan
- Quarterly cyber risk report for the board
Frameworks and certifications
The standards clients, insurers and regulators ask about most, and how a Fractional CISO gets you there.
PDPA (Singapore)SG
- What it is
- Singapore's Personal Data Protection Act 2012, enforced by the Personal Data Protection Commission (PDPC).
- Why it matters
- It requires reasonable security for personal data, and notifying the PDPC and affected people of significant breaches.
- How we help
- We map your personal data, close the security gaps and set up the breach notification process.
CSA Cyber EssentialsSG
- What it is
- A certification mark from the Cyber Security Agency of Singapore for basic cyber hygiene.
- Why it matters
- A recognised, practical first step that shows clients you have the basics in place.
- How we help
- We assess the gaps, fix them with your IT team and prepare you for assessment.
CSA Cyber Trust markSG
- What it is
- A risk-based CSA certification with five tiers, from Supporter (10 domains) to Advocate (all 22), plus cloud, AI and OT security.
- Why it matters
- From 2026 it is being phased in as a requirement for CII owners, their auditors, licensed security providers and government vendors handling sensitive data.
- How we help
- We find your tier, build the controls and prepare the evidence for the certification body.
- Learn more
- See the Cyber Trust mark programme
ISO/IEC 27001All
- What it is
- The international standard for running an information security management system.
- Why it matters
- Multinational clients and tenders often require it.
- How we help
- We build the management system, policies and evidence, and support you through the certification audit.
PDPA 2010 (Malaysia)MY
- What it is
- Malaysia's Personal Data Protection Act, amended in 2024.
- Why it matters
- The amendments add mandatory breach notification and the appointment of a data protection officer.
- How we help
- We review your data handling, support your data protection officer and set up breach reporting.
UU PDP (Indonesia)ID
- What it is
- Indonesia's Personal Data Protection Law (Law 27 of 2022), fully in force since October 2024.
- Why it matters
- It sets duties for handling personal data, including breach notification.
- How we help
- We assess your data processing, update policies and prepare breach procedures.
Ways to engage
Advisory
Risk decisions, policy, questionnaires and board reporting.
Best when IT can carry out the fixes.
Embedded
Runs the security programme with your IT team and providers.
Best when you need a programme built from scratch.
Project
A security assessment, certification readiness or incident response planning.
Best for a deadline such as an audit or a client request.
How success is measured
- Open high risks
- Phishing test click rate
- Staff using multi-factor authentication
- Questionnaire turnaround time
- Time to detect and respond to incidents
When a full-time hire makes more sense
- You are a regulated financial institution or critical infrastructure operator.
- Security is part of what you sell, for example managed IT or software.
- You run a security operations team that needs daily leadership.
A Fractional CISO can build the programme first, then hand it to a full-time hire.
What it looks like in practice
- Professional services
Builds an answer library so client security questionnaires take days, not weeks.
- Manufacturing
Separates factory systems from the office network after a customer audit flags the risk.
- Healthcare
Tightens access to patient records and prepares a breach plan that meets notification rules.
Typical engagements by industry.
Local rules we work with
Showing Singapore. Compare all three markets
Data protection
The Personal Data Protection Act (PDPA), enforced by the PDPC, including mandatory notification of significant data breaches.
Cybersecurity
The Cybersecurity Act covers critical sectors. CSA runs the Cyber Essentials and Cyber Trust marks, and from 2026 is phasing in the Cyber Trust mark as a requirement for CII owners, their auditors and licensed security providers. GovTech will require it of vendors that manage critical systems or sensitive government data.
Questions about Fractional CISO
Do we need a CISO at our size?
You need someone accountable for security. At 200 to 500 people that is rarely a full-time job, which is why a few days a month works.
Do you do penetration testing?
We scope the tests, select a specialist testing firm and make sure the findings get fixed. Keeping the CISO separate from the testers keeps the results honest.
Can you help us get ISO 27001 or Cyber Essentials?
Yes. We measure the gap, build the policies and controls, prepare the evidence and support you through the external audit.
What happens if we have a breach?
Your Fractional CISO leads the response: containing the incident, bringing in forensic and legal help, and preparing notices to regulators and customers where required.
Our IT provider already does security. Is this different?
Your IT provider runs tools and systems. The CISO sets the policy, checks the provider's work and reports risk to you independently.
Pairs well with
Not sure which seats you need?
The fit check takes about two minutes and suggests a starting bench, with reasons.