Fractional CISO

Security leadership, without the $300k hire.

Most Australian companies between 50 and 500 people are in the same position.

Security has become a board-level question, a customer question, and an insurance question, but a full-time CISO is a $300,000+ salary, a three month search, and another ninety days before anything changes.

What you get

  • A prioritised roadmap you can act on. Sequenced and costed, so you know exactly what you're fixing first and why it earns its place at the top.

  • Confident answers for everyone who asks the hard questions. Security questionnaires completed, board papers written in plain business language, insurer and auditor requests handled cleanly.

  • A living risk register that grows with your business and stays genuinely useful.

  • Certification that follows naturally - ISO 27001, SOC 2, Essential Eight, APRA CPS 234 and CPS 230, Privacy Act obligations. Build a strong program and compliance comes along with it.

  • Vendor and third-party risk under control, including the due diligence your own customers are increasingly asking you to demonstrate.

How it works

  • Month one โ€” we get oriented. I learn your environment, your obligations, your history, and what your leadership genuinely cares about. You finish the month with a clear view of where you stand and a roadmap you can start on immediately.

  • Every month โ€” dedicated time you can count on. A fixed block of hours: standing time with you, standing time with your engineering or IT lead, and a written update polished enough to forward straight to your board.

  • Every quarter โ€” we take stock together. What's moved, what's next, and where to push harder. Momentum is the thing worth protecting, and the quarterly review is how we protect it.

My commitments to you

  • The same trusted advisor, every single month. You build context once, and it compounds from there. If I ever need to hand over, you get a full documented handover and the final say on who takes it.

  • Completely independent advice. No margins, no referral fees, no vendor commissions. When I recommend a tool, it's because it's the right tool for you. When I tell you that you don't need one, that advice is worth just as much.

  • Your success is the goal, even when it means less work for me. Most clients are building toward a program strong enough to hand to a full-time hire. When that day comes, I'd rather help you recruit them than quietly bill a retainer for years.

Offerings

CISO (Foundational)

16 hours a month. Security leadership for companies getting serious for the first time.

You've won a customer who sends security questionnaires. Or you're chasing SOC 2. Or your first enterprise deal stalled at procurement and you realised nobody here owns this.

Foundation gives you one accountable security leader without the overhead of a hire. We'll pick one framework and go after it properly, answer the questions your customers and insurers are asking, and build a roadmap you can actually work through.

Included: a prioritised security roadmap, one framework program (SOC 2, ISO 27001 or Essential Eight), customer security questionnaires answered, a maintained risk register, monthly written update, and direct access when something happens.

Best for: pre-revenue through to around 50 staff.

CISO (Standard)

32 hours a month. For companies where security has become a board conversation.

You're being audited, questioned by customers, and asked for updates by your board, often in the same week. Standard is built for the point where security stops being a project and becomes a function.

You get enough time to run a real program: framework work progressing, third-party risk under control, board papers written in language your directors will actually engage with, and a quarterly review that tracks momentum rather than activity.

Included: everything in Foundation, plus quarterly board reporting, vendor and third-party risk management, incident response plan development, multi-framework support, and standing time with your engineering or IT lead.

Best for: 50โ€“250 staff with an active compliance program.

CISO (Enterprise)

48 hours a month. For regulated businesses and companies with real exposure.

APRA CPS 234 and CPS 230. The SOCI Act. Essential Eight against government contracts. Multiple entities, multiple clouds, a vendor ecosystem that keeps growing. This is where security leadership becomes a genuinely executive job.

Enterprise means I'm in your committee meetings, in front of your regulators and auditors, and close enough to your business to make calls in real time rather than at the next scheduled catch-up.

Included: everything in Standard, plus regulator and auditor representation, board and committee attendance, multi-entity governance, security program ownership, and priority availability during incidents.

Best for: 250+ staff, or any organisation carrying formal regulatory obligations.

Victoria

BASED

AUSTRALIA

WIDE