P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Security leadership

vCISO Advisory

Embedded security leadership one to three days a week: board reporting, programme direction, and decisions taken with accountability, without a full-time hire.

Mid-sized organisations need security leadership that can face a board, direct a programme, and own a risk decision. A full-time hire is expensive and hard to retain; an occasional consultant lacks the standing to decide anything. This engagement puts accountable leadership in the room one to three days a week.

What the role covers

Board and audit committee

Risk posture reporting and investment cases directors can act on

Programme direction

Priorities, sequencing, and direction for your existing security staff

Risk ownership

Decisions taken and documented, with accountability that holds

Assurance and audit

Customer security questionnaires, audits, and regulator engagement

How the engagement runs

  1. 1

    Posture assessment

    Four weeks to establish what exists: controls, people, obligations, and the risks nobody has written down. No tooling purchase, no framework imposed before the picture is clear.

  2. 2

    Priorities and mandate

    An agreed set of priorities for the next two quarters, the decisions the role is authorised to take, and the reporting line into the board.

  3. 3

    Embedded delivery

    One to three days a week directing the programme, unblocking the team, and handling the security conversations that reach executives and customers.

  4. 4

    Board reporting cycle

    Quarterly reporting in board language: what changed, what it cost, what the residual risk is, and what the next investment buys.

  5. 5

    Handover and independence

    The engagement is built to end. Documented decisions, a running programme, and where appropriate an internal successor coached into the role.

What you walk away with

  • Security posture assessment and risk register
  • Two-quarter prioritised programme plan
  • Board reporting pack, refreshed each quarter
  • Policy set and decision log maintained throughout
  • Customer and regulator assurance responses handled
  • Handover documentation and successor coaching

How this plays out

Example scenario

A scaling software company kept losing enterprise deals at the security review stage, with no one able to answer buyer questionnaires with authority.

The work: Two days a week: assurance pack built, control gaps closed in deal-blocking order, and the security conversation taken directly with prospects.

Security review stopped being a blocker; the assurance pack now answers most questionnaires without engineering time.

Example scenario

A regulated firm had a capable security team with no senior voice at board level, so investment requests kept being deferred.

The work: Quarterly board reporting that translated technical risk into financial exposure, with costed options rather than requests.

The programme was funded for the first time in three years, and the internal lead was coached into presenting it directly.

Start the conversation

A short call to understand your situation; a clear scope if the engagement fits, and a straight answer if it does not.

Discuss vCISO support

Share this

Send it to whoever owns the budget or the risk.

← All services

What a fractional security leader is actually for

The title suggests a part-time version of a full-time job, and that framing sets the wrong expectation on both sides.

A full-time CISO in a small organisation spends most of their week on things that do not need a CISO: chasing suppliers for questionnaires, updating a risk register nobody reads, sitting in project meetings as an observer. The value is concentrated in a small number of decisions, and those decisions are where this arrangement puts the time.

Which decisions to make, in what order, and what evidence to keep so the next customer questionnaire is answered from a file rather than from memory. What to say to a board that has read one headline and wants reassurance. Which findings to argue with and which to accept. What not to buy.

The rest of the work is better done by the people who already hold it, once somebody has told them what good looks like.

Where most engagements go wrong

The role is used as an escalation queue. If every security question routes here, the arrangement becomes expensive triage and the decisions that needed attention do not get it. The useful shape is a standing session, a written decision record, and an agreed route for anything urgent.

Nobody internal owns anything. External leadership works when it makes decisions and internal people carry them out. Where there is nobody to carry them out, the output is documents, and documents are not a security posture.

It is bought to satisfy a customer rather than to change anything. That is a legitimate reason to start, and it is a poor reason to continue. A questionnaire answered by somebody who did not build the thing being described is a risk rather than a control.

What the first ninety days usually establish

An inventory of what is actually running, because scope is the thing most often assumed and least often written down. A short list of decisions that have been deferred, with owners and dates. And an honest read on which compliance obligations genuinely apply, which is frequently fewer than feared and sooner than expected.

That last one matters commercially. Organisations routinely start an ISO 27001 programme when the customer asking for assurance would have accepted Cyber Essentials Plus and a documented supplier process, at a fraction of the cost and in a quarter of the time.

How it works in practice

Personally, by one practitioner, with a fixed rhythm rather than an open retainer. The commitment is a stated number of days, a standing session, and a written record of what was decided and why, so the reasoning survives a change of staff on either side.

No product is resold and no tooling is bundled. Nothing here makes one recommendation more profitable than another, which is the part a client cannot verify from the outside and the reason it is stated here.