Skip to content
CISO Marketplace Services

Virtual & Fractional CISO Services

Expert security leadership for organizations that need executive-level cybersecurity guidance without the cost of a full-time CISO. Our Virtual/Fractional CISO service provides experienced security executives who integrate with your team to develop and manage your security program, guide strategic initiatives, communicate with your board, and ensure security aligns with business objectives.

In scope

  • Security program development and oversight
  • Board and executive reporting
  • Security strategy development
  • Budget planning and management
  • Security team leadership
  • Risk assessment and management
  • Vendor security management
  • Regulatory compliance guidance
  • Policy and standards development
  • Security architecture review
  • Security metrics program
  • Incident response leadership
  • Security awareness program oversight
  • Technology selection advisory

You receive

  • Monthly security status reports
  • Executive briefing materials
  • Board presentations
  • Security roadmap development
  • Budget recommendations
  • Security policies and procedures
  • Risk register and analysis
  • Vendor security requirements
  • Compliance tracking dashboard
  • Security metrics reporting
  • Security architecture guidance
  • Incident response coordination
  • Strategic technology planning

Tiers

Choose the depth.

CISO Advisory Services

$9.5K / mo

Strategic security guidance and advisory support for organizations with existing security teams that need executive expertise

employees
250
  • — Presenting to the board
  • — Managing the security team day to day
  • — Incident response leadership
  • — Vendor security reviews
Scope CISO Advisory Services

Fractional CISO Program

$17.5K / mo

Dedicated part-time CISO providing hands-on security leadership, board reporting, and program management on a regular cadence

employees
1000
  • — Supporting architect or governance specialists
  • — Hands-on engineering
Scope Fractional CISO Program

Enterprise Security Leadership Program

$28K / mo

Comprehensive security leadership with dedicated CISO and supporting team, providing full executive security function for complex organizations

  • — Hands-on engineering and tool deployment
  • — SOC monitoring
  • — Hours beyond the monthly allotment
Scope Enterprise Security Leadership Program

Members: engagement coupons from the CISO Marketplace coupon book apply to services. There is no blanket discount.

What's inside this engagement

Phase by phase.

How a advisory & fractional leadership engagement runs, what happens in each phase and what you see. Exact scope, tier and timeline are fixed in your proposal and SOW.

  1. 01Onboarding & baseline

    Current program, risks, commitments and stakeholders reviewed.

    You see · Access to leadership and existing documents.

  2. 02Priorities & roadmap

    A risk-ranked roadmap agreed with leadership.

    You see · Decisions on priorities and budget.

  3. 03Ongoing cadence

    Regular working sessions, decisions and deliverables to the agreed scope.

    You see · A named advisor and a standing rhythm.

  4. 04Reporting to leadership

    Board and executive reporting in business terms.

    You see · Board-ready updates.

Commercials

From first call to final report.

  1. 01

    Scoping call

    A practitioner, not a salesperson, walks through targets, constraints and what a good outcome looks like for you.

  2. 02

    Proposal & rules of engagement

    A fixed-scope proposal with tier, price and deliverables. Rules of engagement, contacts and out-of-bounds systems are agreed in writing.

  3. 03

    Sign, then start

    MSA and SOW are signed electronically and the deposit is paid. Only then does testing begin.

  4. 04

    Execution

    Testing runs to the agreed plan. Critical findings are escalated as they are found; you don't wait for the report.

  5. 05

    Report & debrief

    An executive summary plus technical findings with evidence, reproduction steps and fixes, walked through with your team.

  6. 06

    Retest

    Where the tier includes it, we verify your fixes and reissue the report, so auditors and customers see the issues closed.

Timelines are set per engagement in the SOW.

Related

Research

Latest from the blog

All posts on cisomarketplace.com →
Talk to an advisor
Advisor