GRC / GRC-06
Fractional CISO and cybersecurity governance
Recurring executive support to manage security risks, priorities, projects and decisions without immediately hiring a full-time CISO.

WHEN IT HELPS
A focused response
to a defined need.
SME, mid-market company or subsidiary; no security lead, rapid growth or a need for a customer-facing security contact.
SCOPE & OUTCOMES
What the engagement covers.
Scope
- Steering meetings
- risk register
- action tracking, project-security advice and decision preparation
Deliverables
- Executive dashboard
- maintained roadmap
- meeting records and documented decisions
Acceptance evidence
A cadence, decision-makers and indicators are defined; actions progress with evidence and recorded decisions.
DELIVERY
How the work is structured.
Approach
Scope context; engage business owners and decision-makers; assess risks or gaps; decide controls; organise follow-up and evidence.
Prerequisites & responsibilities
Customer: sponsor, available business owners, risk decisions and legal advice where needed. Provider: methodology, facilitation, analysis and decision file.
Scope factors
Entities, processes, stakeholders, regulatory scope, document maturity and workshops. Project, periodic support or fractional CISO depending on need.
Questions to clarify
What decision authority is delegated? How frequent is support? Who implements changes and operates systems?
IMPORTANT BOUNDARIES
This service is not automatically a SOC, an on-call response service or a general transfer of responsibility.
The work supports decisions and evidence for the agreed framework. Legal advice, independent certification and the decisions of regulators or assessors remain separate responsibilities.
IN PRACTICE
Illustrative situations.
These examples describe possible engagements and target outcomes. They are not customer references or achieved results.
Scenario 01
An 80-person SME’s IT manager handles every security issue. Project: introduce monthly governance and track priority risks. Target outcome: earlier decisions and organised workstreams without implicitly transferring operations to the external CISO.
Scenario 02
A subsidiary faces many group security requirements. Project: translate them into a local plan and prepare decisions. Target outcome: visibility over resources, gaps and exceptions; authorised management accepts risks.
Technology and reference context
Existing governance tools, a risk register and tailored dashboards.
The final technology set is agreed during scoping, based on interoperability, licensing, access rights and operating requirements.
CONNECTED SERVICES
Build the next step.
These services can complement the engagement. They are not automatically included.
START A CONVERSATION
Make the scope clear.
We will clarify the objective, dependencies and responsibilities of this service before proposing delivery.
