Fractional leadership 

Virtual CISO and Virtual DPO,
the role without the headcount

A security or data protection director with agreed dedication, committed deliverables and reporting to top management. Packages of 15 to 20 hours a month, quoted in UF.

Why this service

The problem is not a shortage of people to operate: it is a shortage of people to decide

Most mid-sized organisations have someone to administer servers, networks and backups. What they do not have is someone to decides which risk is accepted and which is not, to answer to the board and to keep the management system running between one audit and the next. That role exists; the full-time post, for a company of that size, is not justified.

Fractional leadership solves exactly that: you contract the role and not the headcount, with an agreed monthly dedication, a written scope and deliverables that are reviewed. It is invoiced as a service, not as a salary, and starts within weeks.

And there is a reason to contract it with us and not with just anyone: our consultancy builds the management system, and this service is what steers it afterwards. An implemented system that nobody directs degrades within a year, and arrives at the next audit with evidence from eleven months ago.

Contracting the role versus creating the post

What you are contracting

Agreed monthly commitment
Scope and deliverables in writing
A service invoice, not a salary
Up and running in weeks

What you avoid

A months-long recruitment process
A fixed executive salary
Dependence on a single person
The hole the role leaves when that person goes

What you contract

Two Roles, Available Separately

Each with its own rate and its own dedication. Contracted together, the base work is not duplicated —context, information asset inventory and risk analysis are built once— which is why taking both at once carries a 10% discount.

Virtual CISO

Information security direction

For anyone who already has, or is about to have, a security management system and needs someone to steer it.

  • Steers the risk treatment plan and decides what is accepted, mitigated or transferred
  • Chairs the security committee and leaves minutes with agreements and owners
  • Reports to top management or to the board in business language, not technical
  • Keeps the Statement of Applicability, the policies and the indicators alive
  • Assesses the security of critical suppliers before signing and during the relationship
  • Directs the response when there is an incident and puts the evidence in order afterwards
  • Prepares and supports the internal and certification audits
15 to 20 hours a month of dedication, with committed deliverables

Virtual DPO

Personal data protection direction

For anyone who processes personal data as part of the business and needs to answer for it.

  • Handles data subject requests within the deadline and leaves proof of every reply
  • Keeps the record of processing activities up to date as the business changes
  • Runs the impact assessments before high-risk processing starts
  • Reviews the contracts with processors and the sub-processing chain
  • Acts as the counterpart before the authority and before the data subjects
  • Directs the handling of a breach: reporting, communication and recording
  • Keeps the processing policy published and up to date
15 to 20 hours a month of dedication, with committed deliverables
Offer

Both roles together

A single point of contact for security and privacy, with the baseline discovery done only once. The same commitment for each role, added together.

−10% Build my quote Quoted in UF plus VAT and billed monthly
How the hours are used

A Typical Month

A typical split of the 15 to 20 hours per month. It is not a rigid template: the month of an audit looks little like the month of an incident, and the actual split is agreed in the proposal.

Committee and reporting to top management 2 – 3 h
Follow-up of the risk plan 3 – 4 h
Document review and update 3 – 4 h
Queries from the team and from suppliers 2 – 3 h
Evidence and audit preparation 3 – 4 h
Reserve for incidents and requests 2 – 3 h
If your organisation runs any of the platforms of our partner Forensic, the role uses them as its working tool: the file, the risks and the evidence live where they already are, not in a separate spreadsheet.
Scope

What It Is Not

Saying this before signing avoids the awkward conversation in month three. These three things are contracted separately, and we will tell you when that applies.

It is not a SOC or continuous monitoring

There is no 24/7 monitoring of your systems. The role directs and decides; continuous detection is another service and another infrastructure.

It does not replace the IT department

It leads on security matters, it does not operate them. It does not administer servers, apply patches or configure firewalls.

It is not a block of technical hours

The hours are for direction and judgement. A full regulatory implementation is contracted as a project, under Consulting.

Your quote

Build yours in a minute

Choose the roles you need, the hours package and how many months. You will see the estimated value before sending anything, and the formal proposal reaches you with the detail.

  • One role or both, with the 10% applied automatically
  • A package of 15 or 20 hours per month
  • Length of the engagement, with the total for the period
or write to us directly
Basket 0 products

Your basket is empty

Add regulatory documentation packs or plans
Complete purchase
Contact and payment details
1Contact
2Summary
3Payment
Add to basket?