What a fractional security leader is actually for
The title suggests a part-time version of a full-time job, and that framing
sets the wrong expectation on both sides.
A full-time CISO in a small organisation spends most of their week on things
that do not need a CISO: chasing suppliers for questionnaires, updating a risk
register nobody reads, sitting in project meetings as an observer. The value
is concentrated in a small number of decisions, and those decisions are where
this arrangement puts the time.
Which decisions to make, in what order, and what evidence to keep so the next
customer questionnaire is answered from a file rather than from memory. What
to say to a board that has read one headline and wants reassurance. Which
findings to argue with and which to accept. What not to buy.
The rest of the work is better done by the people who already hold it, once
somebody has told them what good looks like.
Where most engagements go wrong
The role is used as an escalation queue. If every security question routes
here, the arrangement becomes expensive triage and the decisions that needed
attention do not get it. The useful shape is a standing session, a written
decision record, and an agreed route for anything urgent.
Nobody internal owns anything. External leadership works when it makes
decisions and internal people carry them out. Where there is nobody to carry
them out, the output is documents, and documents are not a security posture.
It is bought to satisfy a customer rather than to change anything. That is
a legitimate reason to start, and it is a poor reason to continue. A
questionnaire answered by somebody who did not build the thing being described
is a risk rather than a control.
What the first ninety days usually establish
An inventory of what is actually running, because scope is the thing most
often assumed and least often written down. A short list of decisions that
have been deferred, with owners and dates. And an honest read on which
compliance obligations genuinely apply, which is frequently fewer than feared
and sooner than expected.
That last one matters commercially. Organisations routinely start an ISO 27001
programme when the customer asking for assurance would have accepted Cyber
Essentials Plus and a documented supplier process, at a fraction of the cost
and in a quarter of the time.
How it works in practice
Personally, by one practitioner, with a fixed rhythm rather than an open
retainer. The commitment is a stated number of days, a standing session, and a
written record of what was decided and why, so the reasoning survives a change
of staff on either side.
No product is resold and no tooling is bundled. Nothing here makes one
recommendation more profitable than another, which is the part a client cannot
verify from the outside and the reason it is stated here.