When do you need a fractional CISO?
Almost nobody hires a fractional CISO because they woke up feeling exposed. They hire one because something specific happened, usually in the last three weeks, and usually because somebody outside the company asked a question nobody inside
Almost nobody hires a fractional CISO because they woke up feeling exposed. They hire one because something specific happened, usually in the last three weeks, and usually because somebody outside the company asked a question nobody inside it could answer with a straight face.
That distinction matters, because it tells you what to buy. A company with a stalled enterprise deal needs something different from one recovering from a ransomware scare, and both need something different from one that signed up for ISO 27001 and then discovered nobody owns it. All three will be quoted by people using the same job title.
This page covers the triggers, the week to week work, the three different services sold under the fractional CISO label, and the contract terms that decide whether the arrangement works.
The six triggers that actually start the search
An enterprise buyer wants a named security owner. The most common one. A procurement or vendor risk team asks who is accountable for security, and wants a name, a title, and usually a short biography. "Our CTO handles it alongside product" works until it does not. Larger buyers, banks, insurers and health systems in particular, have policies requiring a designated security function at suppliers handling their data. That requirement is often satisfied by a fractional or part time officer, provided the person is named, reachable, and demonstrably doing the work.
A vendor security review went badly. A questionnaire or a full assessment came in and the answers went out thin. Policies written the week they were requested. An architecture question that came back with three follow ups you could not close. Painful reviews repeat, because the same buyer type asks the same things. The instinct is to hire someone to answer questionnaires. The better instinct is to hire someone to make the answers true.
A funding round brought security diligence. Series A and later rounds increasingly include a technical and security diligence pass, sometimes light, sometimes a full assessment with a report the investment committee reads. The findings become conditions. A company that closed a round with security conditions attached has a defined list of work, a board deadline, and nobody senior enough to own it.
A framework commitment with no owner. Someone promised SOC 2 or ISO 27001 to a customer, a board, or a partner. A tool was bought. A timeline was announced. Then the work landed on an engineering lead who has a roadmap to ship, and it stopped. Frameworks fail far more often from lack of ownership than from lack of knowledge.
An incident. A real one, or a near miss that felt real. Business email compromise, a credential stuffing wave, an exposed bucket found by a researcher, a phishing email that got a wire out the door. Afterwards the questions come from everywhere at once: the board, the insurer, affected customers, sometimes a regulator. Under PIPEDA, a breach of security safeguards creating a real risk of significant harm must be reported to the Privacy Commissioner and to affected individuals, and a record of every breach must be kept for 24 months from the day the organization determines the breach occurred. Quebec has its own obligations under Law 25. Someone has to make those calls and document the reasoning.
A regulator or insurer asked who is accountable. Cyber insurance applications and renewals ask direct questions about security governance, MFA coverage, backup testing and incident response planning, and the answers are warranties. OSFI B-13 expectations flow downhill from federally regulated financial institutions to their suppliers. Health custodians in Ontario push PHIPA duties to vendors. In each case the question is not "are you secure" but "who is responsible, and what evidence do you have."
If none of these has happened, you may not need the role yet. Twenty people, no enterprise customers, no regulated data and no framework commitment is usually better served by fixing specific technical things than by buying leadership.
What a fractional CISO does in a normal week
The abstract answer, aligning security with business objectives, is useless when you are comparing quotes. Here is what the calendar looks like.
Customer and buyer facing work. Joining a call with a prospect's security team to walk through your architecture and controls. Completing or reviewing a security questionnaire, and pushing back on questions that do not apply to your service. Reviewing a customer contract's security schedule before legal signs it, because that schedule creates obligations that outlive the deal. Writing the short security overview that answers most inbound questions without a call.
Risk and decision work. Maintaining a risk register that is actually used, meaning risks have owners, dates and decisions rather than colours. Accepting a risk and writing down why, so the acceptance is a decision rather than an oversight. Reviewing new vendors before they get production data.
Program work. Running the weekly or biweekly working session where remediation items get unblocked. Chasing evidence. Deciding what goes in scope and what stays out, the decision that shapes the whole project and the one most often made badly.
Engineering facing work. Reviewing a design before it is built, which is far cheaper than reviewing it after. Setting the standard for access control, logging, secrets handling and code review, then checking it holds. Triaging penetration test findings into fix now, roadmap, and acceptable with a compensating control.
Board and executive work. A quarterly update saying what changed, what the top risks are, and what is being asked for. Incident escalation, which means being the person called at an odd hour who decides whether to activate the response plan.
Policy and evidence work. Policies that reflect what the company does, reviewed annually, approved by someone with authority. Access reviews. Training that people finish. Tabletops that surface a real gap rather than confirming everyone feels prepared.
Most months the bulk of the time goes to the customer facing, program and engineering categories. The policy work is visible and finite. The customer facing work is what unblocks revenue.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
Three different jobs are sold under one title
This is the part that makes quotes incomparable.
Security leadership and accountability. A named senior person who owns the posture, represents it externally, makes risk decisions, and answers to the board. The most expensive per hour and typically the fewest hours. The deliverable is judgement, direction and a name on the org chart, staffed by one individual who does not change.
Program delivery. Running a framework readiness or remediation program to a deadline. Project management with security expertise: scope, control mapping, gap closure, evidence collection, auditor coordination. More hours, more predictable hours, and often staffed by a small team with a lead consultant and analysts doing the evidence work. Priced per month against a defined end state, or per phase.
Hands on technical work. Configuring the identity provider, hardening cloud accounts, deploying endpoint tooling, writing detection rules, reviewing infrastructure as code. Engineering, billed as engineering, and the right person for it is usually not the right person for the board conversation.
A single provider may sell all three, which is fine. The problem is a proposal saying "fractional CISO, $X per month" without saying which of the three you are buying, at what seniority, and how many hours.
Why a quote that does not name the job cannot be compared
Two quotes at the same monthly figure can differ enormously in value depending on who does the work and what it covers. Before comparing anything, get every quote to answer the same four questions. Who is the named individual, and what is their background, not the firm's. How many hours per month, committed or best effort. Which of the three jobs is included, and which is excluded. What happens when the work exceeds the hours.
A proposal that cannot answer those is not a low quote or a high quote. It is an unpriced one.
How the role differs from a compliance consultant
A compliance consultant is measured by a certificate or a report. The engagement has a defined end, the scope is the framework, and things outside it are out of scope by design.
A fractional CISO is measured by the posture and by the decisions made along the way. The engagement is ongoing, and the scope includes what no framework asks about: the design flaw in the new product, the vendor nobody reviewed, the customer contract clause committing you to a four hour breach notification you cannot meet.
There is real overlap. A readiness engagement often needs an accountable owner, and a fractional CISO often ends up running a framework project. The useful test is what happens after the report is issued. If your need ends when the certificate arrives, you want the consulting engagement. If the questions keep coming, you want the role.
Because the two get quoted against each other constantly, fractional CISO against compliance consultant goes through the contract shapes, the pricing, what happens at the end of each, and how to tell from a proposal which one you are actually being sold.
One buying note that applies to both: remediation cannot be honestly priced before someone has looked. A proposal that quotes a fixed remediation price before any gap assessment has been done is pricing a guess. Expect a gap assessment first that produces a findings register, then a scoped remediation price built from those findings.
How the role differs from an MSSP
A managed security service provider operates things. Monitoring, alerting, endpoint management, log collection, sometimes incident response retainers. They are staffed for coverage, often around the clock, with analysts working a queue. Strong at the operational layer, and not a substitute for an owner.
An MSSP does not decide whether you accept a risk, sit with your enterprise buyer, tell your board the roadmap needs three weeks of security work before the next release, or choose your framework scope. It reports to somebody, and if there is nobody to report to, alerts get acknowledged and nothing changes.
Many companies need both. If you have tooling and alerts with nobody interpreting them, hire the leadership. If you have a competent technical leader and no operational coverage, buy the coverage. Either way, be able to say which problem each one solves.
Hours, cadence, and what a realistic month looks like
Common arrangements in the Canadian market run from roughly half a day a week up to two days a week, sometimes more during a framework push or after an incident.
A workable cadence at the lower end: a standing weekly call with the internal owner, a monthly working session with engineering, a quarterly executive update, and availability for customer calls and escalations in between. At the higher end, add a second weekly session, participation in design reviews, and real presence in the engineering channels.
What matters more than the number is whether the time is committed or leftover. Ask when the recurring meetings are, in which time zone, what the response expectation is for an urgent message, and how many other clients the named person carries. A senior practitioner with few clients and firm meeting slots delivers more in eight hours than someone with a long roster delivers in twenty.
Expect the first sixty to ninety days to be heavier: an assessment of where things stand, a prioritised plan, and the first visible fixes. After that the work settles into a rhythm, with spikes around audits, renewals, incidents and large deals.
Signs you have outgrown the arrangement
The role is a stage, not a permanent structure. Move to a full time hire when several of these are true at once.
Security work generates more than one full time equivalent of activity, and the fractional person is managing a queue rather than making decisions. You have security staff who need day to day management and direction. Escalations are frequent enough that part time availability creates real delay. Your customers or regulators are asking for a full time officer by name. Security has become a standing board item with its own budget line. Or the company has grown past roughly a hundred and fifty to two hundred people, where the coordination load alone fills a role.
A good arrangement anticipates this. Often the best outcome is that the fractional officer writes the job description, sits on the hiring panel, and hands over to the person they helped select. Discuss that at the start rather than treating it as a loss.
What belongs in the contract
Six terms decide whether this works.
The named individual. Name the person who holds the role, not only the firm, and include a substitution clause requiring your written consent before anyone else takes it on. The most important term in the agreement, because the value of the role is that a specific experienced person is accountable.
Hours and what they cover. State the monthly hours, whether unused hours roll over, the rate beyond the commitment, and the standing meeting cadence. Vague availability language turns into a dispute in month four.
Escalation and response. Define what counts as urgent, the channel for reaching the person outside business hours, and the response time expectation. Say whether incident response is included, capped, or billed separately. Incident work is unbounded by nature, and both sides benefit from knowing where the line sits.
What is out of scope. Write down what the engagement does not include: hands on engineering implementation, tool administration, monitoring coverage, audit fieldwork, legal advice, breach notification decisions if those sit with counsel. An explicit exclusions list prevents the drift where a leadership retainer quietly becomes unpaid implementation work.
Notice period. Thirty to sixty days in either direction is normal. Shorter leaves you exposed during a framework project, and much longer is hard to justify.
Handover. Specify what you receive on exit and in what format: the risk register, policies, evidence, vendor assessments, open findings with status, administrative access, and a written handover document. All of it should live in your systems throughout the engagement rather than in the provider's.
Two more worth including: confidentiality that survives termination, and a clause confirming the individual acts as your designated security contact for customer and regulatory purposes, since that is often the reason you are hiring.
Questions to ask before you sign
Who specifically holds the role, and what have they run before. Can you show completed engagements in Canada, and can any be referenced. Is remediation priced before or after a gap assessment. What credentials does the practitioner hold beyond a baseline certification, and have they published or researched anything. Which entity signs, and under which province's law. Where does our engagement data live. Which of the three jobs are we buying, and what is excluded. How many hours, and when are the meetings.
Any provider worth engaging answers all of these in one conversation.
Next step
If a specific trigger has already happened, start there. Write down the event, the deadline it created, and who is asking. That paragraph turns a vague search into a scope, and it is what lets you compare quotes on the same terms.
Use the quote flow on this directory to put it in front of Canadian fractional CISO providers at once, TrazTech among them.
Common questions
How many hours a month is a typical arrangement?
It varies with what you bought. Leadership and accountability can run on half a day a week; program delivery against a framework deadline needs considerably more. The number matters less than whether the contract names the hours and the person.
What is the difference between a fractional CISO and a compliance consultant?
A compliance consultant delivers a framework outcome and leaves. A fractional CISO carries ongoing accountability for security decisions, including the ones no framework asks about. Some engagements need one, some need the other, and plenty of quotes blur them.
When have we outgrown a fractional arrangement?
When the work stops fitting the hours, when the decisions need someone in the room daily, or when a regulator or large buyer expects a named full-time owner. The article above sets out the thresholds in more detail.
Find out what it would cost in your situation
The honest answer depends on your size, your frameworks and what is already in place. Send the details and compare scoped proposals rather than rate cards.
Get matchedWhere to go from here
- Fractional CISO cost in Canada, CAD benchmarks. What the role costs at each size, with the hours attached.
- vCISO engagement models and hours by size. The shapes these engagements come in and which fits your situation.
- CISO vs vCISO vs security manager vs CTO. The three roles this is usually confused with, and when each is right.
- Your first security hire, or not a hire. If the answer turns out to be a hire rather than a retainer.