JOEY VICTORINO Independent Technical Judgment

Field Notes · Security Leadership · 9 min read

When a company actually needs a fractional CISO, and when it doesn't.

Fractional security leadership solves a specific problem: consequential security decisions are accumulating faster than anyone in the company is qualified to own them. It does not solve several problems it is commonly sold to solve. This note describes the conditions that create the genuine need, the evidence an executive can observe inside their own company, what the role should and should not own, and seven diagnostic questions to apply before buying anything.

The condition that creates the need

At some point in a technology company's growth, security stops being a set of engineering tasks and becomes a stream of decisions with commercial consequences. The transition is usually driven by forces outside the engineering organization: an enterprise prospect sends a two-hundred-question security review, a customer contract requires SOC 2 or ISO 27001, an investor asks who owns security, a board member asks what happens if there is an incident, or a deal stalls while the buyer's security team evaluates yours.

Each of those events forces a decision. Which compliance framework, if any, and on what timeline. Which security questionnaire answers are true today and which describe a state the company has not reached. Which architectural commitments the company should make before its next stage of growth, and which can wait. What the company will actually do in the first hours of an incident, and who decides.

These decisions share three properties. They are consequential: answering them badly costs revenue, trust, or money. They are cross-functional: they bind sales, legal, engineering, and the board, so no single function can own them cleanly. And they compound: an expedient answer to a security questionnaire becomes a contractual representation; an unexamined architecture choice becomes the foundation everything else is built on.

The genuine case for fractional security leadership exists when decisions with these properties are arriving regularly and nobody in the company is positioned to own them. That is a judgment and accountability deficit. It is different from a labor deficit, and the distinction determines whether fractional leadership will work.

What the evidence looks like inside the company

An executive considering this decision does not need an external assessment to see the early evidence. It is usually visible in the company's own operations:

  • Security questionnaires are answered ad hoc by whoever is available, and nobody reviews the answers as a set of commitments the company is accumulating.
  • Enterprise deals slow down at the security review stage, and the sales team cannot say precisely why or predict which reviews will go badly.
  • Compliance work is underway, often with a compliance automation platform, but nobody senior has decided what the audit is for, what it covers, and what it deliberately does not cover.
  • There is an incident response document, and it was written for the audit rather than for an incident. Nobody has decided who declares an incident, who talks to customers, or when counsel is engaged.
  • Consequential technical decisions with security implications, such as a major vendor commitment, a new data flow, or an AI deployment, are made by whoever is driving the project, without anyone asking what new exposure the company just accepted.
  • When an investor or board member asks about security, the answer is a list of activities rather than a statement of what risks the company has decided to accept, transfer, or reduce.

None of these observations means the company is negligent. They are the normal condition of a company whose security obligations have grown faster than its management structure. Governance frameworks make the same underlying point: NIST's Cybersecurity Framework 2.0 added a dedicated Govern function precisely because risk management depends on established ownership, roles, and oversight, not only on technical controls. The question is not whether the company has security activity. It is whether anyone owns the decisions.

What a fractional CISO should own

Used correctly, fractional security leadership is the ownership layer, sized to the actual decision volume of a growing company. The role should own:

  • The risk position. A defensible, current answer to what the company's material security risks are, which ones leadership has decided to accept, and what is being done about the rest.
  • Prioritization. The ordered list of what gets fixed, built, or bought next, and the reasoning, so that security spending follows risk rather than vendor marketing or the most recent questionnaire.
  • Compliance direction. What the audit scope should be, what evidence the company can honestly stand behind, and where compliance work ends and security work continues.
  • Customer-facing security posture. Security reviews, questionnaire commitments, and the security narrative in enterprise sales, treated as representations the company must be able to honor.
  • Incident readiness and escalation. Who decides what during an incident, rehearsed before it matters, and senior judgment available when it does.
  • Board and investor translation. Reporting that states decisions, consequences, and requests, in the language of business risk.
  • Second opinions on consequential technical decisions. Architecture, vendor, and build-versus-buy choices examined for the exposure they create before they are signed.

Every item on that list is judgment, accountability, or translation. None of it is headcount replacement.

What it should not own

Fractional leadership fails predictably when it is bought to solve a different problem. Three mismatches account for most of these failures, and each is structural rather than personal:

It is not engineering labor. If the company's actual gap is that nobody has time to configure single sign-on, fix cloud permissions, or remediate findings, the company needs engineering capacity: an existing engineer with allocated time, a contractor, or a managed service. A part-time executive who spends their hours doing implementation work is an expensive engineer and an absent leader. The leadership role should specify and verify that work, not perform it.

It is not outsourced compliance production. Compliance platforms and auditors produce audit artifacts efficiently. What they do not produce is the executive decision about what the audit should mean commercially, and a SOC 2 report speaks to defined criteria over a defined period, not to whether leadership is making sound security tradeoffs. Buying fractional leadership purely to push an audit across the line uses a judgment role for a production task, and it typically shows: the company becomes certified and remains undecided.

It is not a title for sales optics. Enterprise security reviewers ask who owns security, and a name on a slide satisfies the question only until the first substantive follow-up. If the person carrying the title does not actually hold decision authority, the arrangement creates a representation the company cannot back, which is worse than an honest statement of where the company is.

There is a fourth boundary that matters more than it first appears: management cannot outsource ownership of risk. A fractional CISO can frame decisions, provide judgment, and be accountable for the security program. The decision to accept a material risk belongs to the executives and the board. An arrangement in which leadership stops engaging with security because "we have someone for that" has replaced an ownership gap with an ownership illusion.

When you do not need one

The honest boundary conditions, stated plainly:

  • Nothing consequential is arriving yet. A pre-revenue product with no sensitive data, no enterprise pipeline, and no regulatory exposure usually needs good engineering defaults and founder attention, not an executive. Buying leadership before there are decisions to lead wastes money and creates process without purpose.
  • The gap is purely implementation. If the company already knows what needs to be done and simply lacks hands, buy hands. Revisit leadership when the question changes from how to do the known work to what the company should do next and why.
  • The scale already justifies full-time. A company operating at meaningful regulatory depth, in healthcare, financial services, or critical infrastructure, or with a security team that needs daily management, has usually passed the point where part-time attention is adequate. Fractional leadership at that scale becomes a bottleneck with a title.
  • Leadership wants a scapegoat, not an adviser. If the unstated goal is to have someone to blame after an incident, no engagement structure fixes that, and a competent adviser will decline the role as scoped.

When the role should become full-time

Fractional arrangements have a natural end state, and a good adviser names it early. The signals that the company has outgrown part-time leadership are observable: security decisions need attention most days rather than most weeks; there is a security team that needs management rather than direction; customer security commitments have become continuous operational obligations; the regulatory environment requires a named accountable executive with full-time attention; or incident readiness has moved from planning to frequent live operation. At that point the fractional role's remaining value is to define the full-time role, help hire it, and hand over a program the new executive can run rather than rebuild.

Seven questions before you buy

A diagnostic an executive team can apply in one meeting, without a vendor in the room:

  1. List the security-relevant decisions made in the last two quarters: questionnaire commitments, compliance scope, vendor and architecture choices, incident planning. Who owned each one, and would they say so?
  2. Which decisions are currently stalled or being made by default because nobody is positioned to make them deliberately?
  3. Is security now inside the revenue path? Are enterprise reviews, contractual security terms, or customer audits affecting deal velocity?
  4. If a serious incident began tonight, who would declare it, who would run it, who would inform customers, and when would counsel be engaged? Are those answers written down and known, or reconstructed on demand?
  5. Can leadership state, in one paragraph, the company's material security risks and which of them it has knowingly accepted? If the board asked tomorrow, would the answer be a position or a list of tools?
  6. Is the gap you are trying to close a judgment gap (what should we do and why), a labor gap (we know what to do and lack hands), or a production gap (we need audit evidence assembled)? Only the first is a leadership purchase.
  7. Is the executive team prepared to keep owning risk acceptance itself, with the fractional leader framing decisions rather than absorbing them?

If the answers to questions one through five reveal unowned, commercially significant decisions, and question six identifies a judgment gap, fractional security leadership is likely the correct instrument. If question six identifies a labor or production gap, buy the cheaper, correct thing instead.

The strongest objection

The most credible counterargument is that a strong VP of Engineering or CTO can cover this. Sometimes that is true, and when it is, the company should not buy anything. The claim deserves an honest test rather than reflexive dismissal: does that leader have the time, does the security domain knowledge extend to compliance scoping, customer security reviews, and incident governance, and can they give the board an independent view of risks created by their own organization's decisions?

The last point is the structural one. An engineering leader who owns delivery has delivery incentives, and security tradeoffs frequently price delivery against exposure. That does not make the person untrustworthy; it makes their position a difficult place from which to argue against their own roadmap. Boards and buyers discount self-assessment for the same reason auditors exist. Separation of the security judgment from the delivery incentive is a governance feature, not a comment on anyone's integrity.

What good looks like

A company using fractional security leadership well shows observable characteristics within the first quarter: a written, current risk position that leadership can state without preparation; an ordered security roadmap with reasoning attached; questionnaire and contractual security commitments tracked as obligations; an incident escalation path with named decision-makers; compliance scope chosen deliberately, with its limits understood; and board reporting that requests decisions rather than presenting dashboards. If those artifacts are not appearing, the engagement is drifting toward one of the failure modes above and should be corrected or ended.

Conclusion

The fractional CISO question is not whether the title is fashionable or whether peers have one. It is whether consequential security decisions are accumulating without an owner. Where they are, a part-time senior owner of judgment, prioritization, and translation is a rational structure: the company buys the decision-making layer it needs at the volume it actually has. Where the real gap is labor, audit production, or optics, the same purchase fails, because the thing bought does not match the thing missing. The diagnostic is inexpensive: inventory the decisions, identify their owners, and classify the gap before signing anything.

Related: SOC 2 Is Not a Security Strategy, on the audit those unowned decisions are often mistaken for.

Facing this decision now?

The Security Leadership Sprint is a fixed-scope review built for exactly this question: 7 to 10 business days, ending in an assessment of the security program, compliance and customer pressure, incident readiness, and unowned risks, a prioritized 90-day plan, and a direct recommendation on whether fractional leadership is warranted at all. $7,500 fixed.

Know a founder whose enterprise deals are starting to hinge on security questions? Send them this note.

Sources

← All Field Notes