Skip to content

Fractional CISO

Security leadership your board can rely on, without a full-time CISO.

Boards, insurers and customers now expect someone to own security. Most mid-market organisations don't need a full-time CISO, but they do need the strategy, the reporting and the decisions. Our fractional CISO provides them on a monthly retainer, with engineers behind every recommendation.

Start with a cyber risk assessment
Locked steel server cabinet door, with blue light through the perforated mesh.

What the role covers

  • Security strategy and a roadmap tied to your budget cycle
  • Board and executive reporting in plain language
  • A security policy set that matches how you work
  • Ownership of the security risk register, with decisions escalated to the right people
  • Vendor security questionnaires and customer due diligence
  • Cyber insurance applications and renewals
  • Alignment with the Essential Eight, NIST CSF 2.0, ISO 27001, APRA CPS 234 or the SOCI Act, as your obligations require
  • Incident leadership: decisions, communications and regulator notifications

Who does it

The fractional CISO role is held by our founder, David Goulding, who has spent more than 13 years in infrastructure, cloud and security, including Microsoft Sentinel and security operations engineering and Defender for Endpoint implementations. He works with North Ark's engineers, so recommendations come with a plan to implement them.

How it runs

  1. Start: a cyber risk assessment, or a review of the one you have, to set the baseline and the roadmap.
  2. Monthly: time with your leadership, progress on the roadmap, the risk register reviewed and questionnaires handled.
  3. Quarterly: a board report on posture, risks, incidents and decisions needed.
  4. Annually: the roadmap refreshed, policies reviewed and a tabletop exercise run.

Advice connected to engineering

Security advice only reduces risk once someone implements it. Here, the same organisation that sets the direction can do the work: Essential Eight uplift, Defender and Sentinel, vulnerability management and incident response.

Questions buyers ask

How much time does a fractional CISO spend with us?

A set number of days each month, agreed in the retainer, with more available around board meetings, audits or incidents.

Can the fractional CISO present to our board?

Yes. Board reporting is a core part of the role, including attending board or risk committee meetings.

Will you take over our security questionnaires?

Yes. We maintain a standard evidence pack and answer questionnaires from customers, partners and insurers.

Do we need a fractional CISO if we have an IT manager?

Often yes. Security leadership is a different job from running IT, and boards increasingly want a named person accountable for it.

How is it priced?

A fixed monthly retainer based on the time and scope agreed, usually for 12 months.

Can we combine it with a fractional architect?

Yes. Security and architecture advice can be combined in one advisory retainer.

Start a conversation

Give security an owner your board can talk to.

Tell us what your board, insurer or customers are asking for.

Talk to an Engineer