At some point a regulated company needs someone who owns security. Not another tool. An owner. The question is whether that owner is a full-time hire or a fraction of one.

What a CISO actually does

Not firewall configuration. That’s IT. A CISO sets priorities from risk, gets budgets approved, keeps policies real, manages vendors, faces auditors and underwriters, and reports to leadership in leadership’s language. It’s a program job, not a keyboard job.

The math

A full-time security executive is a six-figure commitment before benefits, tooling, and retention risk. And at 25–200 employees, there usually isn’t 40 hours a week of true CISO work to do. There is, however, absolutely 8–25 hours a month of it, and skipping those hours is how roadmaps die.

Fractional pricing matches the actual workload. Retainers are scoped custom (roughly 8 to 25+ hours a month depending on whether you need direction over existing IT, active remediation management, or multi-site and audit load) and the rate is fixed in writing. Every retainer includes an annual reassessment, leadership reporting, and incident response leadership.

When fractional fits

  • You have IT or an MSP that executes well but nobody sets security priorities
  • An insurer, customer, or regulator started asking program-level questions
  • A risk assessment produced a roadmap that needs an owner
  • You need the function now, not after a six-month executive search

When full-time wins

  • Security is your product, or a breach ends the company
  • Compliance workload is genuinely full-time: several concurrent audits, hundreds of vendors
  • You’re past ~200 employees and the program needs a daily presence

The middle path most companies take

Start fractional. Let the program mature: assessment, remediation, reassessment. If the workload grows into a seat, hire into a running program with clean documentation, and let the fractional advisor hand over (or stay on for audits). Nothing about starting fractional forecloses hiring later. It usually makes the hire better.