Back to trustpartners.sg MOM-licensed employment agency, EA licence 22C0912 contactus@trustpartners.sg WhatsApp +65 8992 2786
Trust PartnersBusiness
Book a consult
CISO

Fractional CISO

Chief Information Security Officer, part-time

A Fractional CISO is a senior security leader who works with your company part-time to assess cyber risk, set security policy, prepare you for audits and certifications, and lead the response if something goes wrong. They treat security as a business risk, not just an IT task.

Book a consult

What is a Fractional CISO?

Companies of 200 to 500 people hold valuable customer, payment and employee data, but rarely have a dedicated security leader. Meanwhile, large clients, insurers and regulators increasingly ask for evidence of security controls before they sign, renew or pay out.

A Fractional CISO turns security into a managed programme: a clear picture of your risks, a ranked list of fixes, policies people follow, a plan for incidents, and evidence ready when someone asks for it.

What a Fractional CISO does

Risk and strategy

  • Runs a cyber risk assessment and keeps the risk register
  • Sets the security roadmap and budget
  • Reports cyber risk to the CEO and board

Policies and controls

  • Writes information security policies
  • Sets rules for access, passwords and multi-factor authentication
  • Defines backup and recovery requirements
  • Checks the security of suppliers and partners

Compliance and certification

  • Checks data protection compliance in each market
  • Prepares you for CSA Cyber Essentials, Cyber Trust or ISO/IEC 27001
  • Answers client security questionnaires with evidence
  • Supports cyber insurance applications

Incident readiness

  • Writes the incident response plan
  • Runs tabletop exercises with your leadership team
  • Leads the response during a live incident, with forensic, legal and regulator contacts

People and awareness

  • Runs phishing simulations
  • Sets up security awareness training
  • Secures how staff join, move and leave

How your company benefits

  • Win and keep larger clients

    Ready answers and recognised certifications shorten security reviews during sales and renewals.

  • Fewer successful attacks

    Closing common gaps such as weak access controls, missing updates and untested backups blocks many everyday attacks.

  • A faster, calmer response

    A tested incident plan means people know who to call and what to do in the first hours.

  • Legal duties met

    Data protection laws in Singapore, Malaysia and Indonesia require reasonable security and, for serious breaches, notifying regulators within set deadlines.

  • Easier insurance

    Insurers ask about controls such as multi-factor authentication and backups. Having them in place makes cover easier to get.

  • Security leadership, sized to you

    You pay for the days you need instead of a full-time CISO package.

Signs you need a Fractional CISO

Tick the ones that sound like your company.

0 of 7

Tick the statements that sound like your company.

How it works

Your first 90 days

  1. Days 1 to 30

    Assess

    Review systems, access, data flows and suppliers, run a phishing test, and build a ranked risk register.

  2. Days 31 to 60

    Fix

    Close the highest risks such as multi-factor authentication, backups and admin access, publish core policies and draft the incident plan.

  3. Days 61 to 90

    Prove

    Run a tabletop exercise, prepare evidence for questionnaires, plan the certification path and report to the board.

A typical month

  1. Week 1Security steering meeting with leadership
  2. Week 2Control checks and supplier reviews
  3. Week 3Questionnaires, audits and awareness
  4. Week 4Risk report and board update

Example for an Embedded CISO at 4 days a month. In an incident, your CISO steps in immediately.

What you receive

  • Cyber risk register with ranked fixes
  • Security roadmap and budget
  • Information security policy set
  • Incident response plan and exercise report
  • Data protection compliance review
  • Library of answers for security questionnaires
  • Phishing test results and awareness plan
  • Quarterly cyber risk report for the board

Frameworks and certifications

The standards clients, insurers and regulators ask about most, and how a Fractional CISO gets you there.

PDPA (Singapore)SG
What it is
Singapore's Personal Data Protection Act 2012, enforced by the Personal Data Protection Commission (PDPC).
Why it matters
It requires reasonable security for personal data, and notifying the PDPC and affected people of significant breaches.
How we help
We map your personal data, close the security gaps and set up the breach notification process.
CSA Cyber EssentialsSG
What it is
A certification mark from the Cyber Security Agency of Singapore for basic cyber hygiene.
Why it matters
A recognised, practical first step that shows clients you have the basics in place.
How we help
We assess the gaps, fix them with your IT team and prepare you for assessment.
CSA Cyber Trust markSG
What it is
A risk-based CSA certification with five tiers, from Supporter (10 domains) to Advocate (all 22), plus cloud, AI and OT security.
Why it matters
From 2026 it is being phased in as a requirement for CII owners, their auditors, licensed security providers and government vendors handling sensitive data.
How we help
We find your tier, build the controls and prepare the evidence for the certification body.
ISO/IEC 27001All
What it is
The international standard for running an information security management system.
Why it matters
Multinational clients and tenders often require it.
How we help
We build the management system, policies and evidence, and support you through the certification audit.
PDPA 2010 (Malaysia)MY
What it is
Malaysia's Personal Data Protection Act, amended in 2024.
Why it matters
The amendments add mandatory breach notification and the appointment of a data protection officer.
How we help
We review your data handling, support your data protection officer and set up breach reporting.
UU PDP (Indonesia)ID
What it is
Indonesia's Personal Data Protection Law (Law 27 of 2022), fully in force since October 2024.
Why it matters
It sets duties for handling personal data, including breach notification.
How we help
We assess your data processing, update policies and prepare breach procedures.

Ways to engage

  • Advisory

    2 days a month

    Risk decisions, policy, questionnaires and board reporting.

    Best when IT can carry out the fixes.

  • Embedded

    4 to 6 days a month

    Runs the security programme with your IT team and providers.

    Best when you need a programme built from scratch.

  • Project

    Fixed scope and price

    A security assessment, certification readiness or incident response planning.

    Best for a deadline such as an audit or a client request.

How success is measured

  • Open high risks
  • Phishing test click rate
  • Staff using multi-factor authentication
  • Questionnaire turnaround time
  • Time to detect and respond to incidents

When a full-time hire makes more sense

  • You are a regulated financial institution or critical infrastructure operator.
  • Security is part of what you sell, for example managed IT or software.
  • You run a security operations team that needs daily leadership.

A Fractional CISO can build the programme first, then hand it to a full-time hire.

What it looks like in practice

  • Professional services

    Builds an answer library so client security questionnaires take days, not weeks.

  • Manufacturing

    Separates factory systems from the office network after a customer audit flags the risk.

  • Healthcare

    Tightens access to patient records and prepares a breach plan that meets notification rules.

Typical engagements by industry.

Local rules we work with

Showing Singapore. Compare all three markets

Data protection

The Personal Data Protection Act (PDPA), enforced by the PDPC, including mandatory notification of significant data breaches.

Cybersecurity

The Cybersecurity Act covers critical sectors. CSA runs the Cyber Essentials and Cyber Trust marks, and from 2026 is phasing in the Cyber Trust mark as a requirement for CII owners, their auditors and licensed security providers. GovTech will require it of vendors that manage critical systems or sensitive government data.

Questions about Fractional CISO

Do we need a CISO at our size?

You need someone accountable for security. At 200 to 500 people that is rarely a full-time job, which is why a few days a month works.

Do you do penetration testing?

We scope the tests, select a specialist testing firm and make sure the findings get fixed. Keeping the CISO separate from the testers keeps the results honest.

Can you help us get ISO 27001 or Cyber Essentials?

Yes. We measure the gap, build the policies and controls, prepare the evidence and support you through the external audit.

What happens if we have a breach?

Your Fractional CISO leads the response: containing the incident, bringing in forensic and legal help, and preparing notices to regulators and customers where required.

Our IT provider already does security. Is this different?

Your IT provider runs tools and systems. The CISO sets the policy, checks the provider's work and reports risk to you independently.

Pairs well with

Not sure which seats you need?

The fit check takes about two minutes and suggests a starting bench, with reasons.