At some point a regulated company needs someone who owns security. Not another tool. An owner. The question is whether that owner is a full-time hire or a fraction of one.
What a CISO actually does
Not firewall configuration. That’s IT. A CISO sets priorities from risk, gets budgets approved, keeps policies real, manages vendors, faces auditors and underwriters, and reports to leadership in leadership’s language. It’s a program job, not a keyboard job.
The math
A full-time security executive is a six-figure commitment before benefits, tooling, and retention risk. And at 25–200 employees, there usually isn’t 40 hours a week of true CISO work to do. There is, however, absolutely 8–25 hours a month of it, and skipping those hours is how roadmaps die.
Fractional pricing matches the actual workload. Retainers are scoped custom (roughly 8 to 25+ hours a month depending on whether you need direction over existing IT, active remediation management, or multi-site and audit load) and the rate is fixed in writing. Every retainer includes an annual reassessment, leadership reporting, and incident response leadership.
When fractional fits
- You have IT or an MSP that executes well but nobody sets security priorities
- An insurer, customer, or regulator started asking program-level questions
- A risk assessment produced a roadmap that needs an owner
- You need the function now, not after a six-month executive search
When full-time wins
- Security is your product, or a breach ends the company
- Compliance workload is genuinely full-time: several concurrent audits, hundreds of vendors
- You’re past ~200 employees and the program needs a daily presence
The middle path most companies take
Start fractional. Let the program mature: assessment, remediation, reassessment. If the workload grows into a seat, hire into a running program with clean documentation, and let the fractional advisor hand over (or stay on for audits). Nothing about starting fractional forecloses hiring later. It usually makes the hire better.