Marco BrondaniSecurity, AI risk and platform strategyBook a call
  • Ongoing engagement
  • Monthly retainer
  • NIS2
  • DORA
  • EU AI Act

Fractional CISO Retainer

Senior security leadership for organizations that need CISO-level judgment without a full-time hire, and for the ones now working through what an assessment found.

Book a call

Why now

Under NIS2 the management body approves and oversees the cybersecurity measures, and the accountability is personal rather than institutional. That obligation does not wait for a hire to complete, and it does not pause while a remediation programme runs.

What you get

  • Oversight: governance framework, board reporting and regulatory readiness
  • Programme: everything in Oversight, plus ownership of the remediation programme
  • Embedded: everything in Programme, plus incident leadership and running the function
  • Translation of technical risk into decisions leadership can act on, at every tier

An assessment tells you where the exposure is. Somebody then has to carry it: sequence the remediation, argue for the budget, answer the supervisor, and decide what to do on the morning the monitoring goes quiet. Organizations that already have that person do not need this. Organizations that need CISO-level judgment without a full-time hire do. Where the question is what gets built rather than what protects it, the CTO advisory work is the closer fit, and the two are often held together.

The work is security posture assessment, governance framework development, board reporting, regulatory readiness, and the translation of technical risk into decisions leadership can actually act on. The cadence is agreed at the start and holds, because a retainer that only activates during incidents is not leadership.

Three tiers

Oversight. Governance framework development, board and audit committee reporting, and regulatory readiness across NIS2, DORA and the EU AI Act. For organizations that have people running security and need someone accountable for whether the account given upward is true.

Programme. Everything in Oversight, plus ownership of the remediation programme: sequencing the work, holding the owners to it, and reporting progress in terms a board can act on. This is the tier most organizations land in after an assessment.

Embedded. Everything in Programme, plus incident leadership and day-to-day direction of the security function. For organizations carrying the obligations of a security leader without one in post.

The tier is chosen on the call and can move as the work changes. What moves the fee within the band is the size of the estate and the regulatory regime you report under, and the number is fixed in writing before the first month runs.

What it costs

Four figures per month (indicative)

Set by the tier, the size of the estate and the regulatory regime you report under.

Next step

Book a call

A thirty minute call to establish what you are exposed to and whether an engagement is worth running.

Book a call