Board-level security leadership, without the full-time hire
Fractional CISO and Virtual CISO
A fractional CISO, often called a virtual CISO or vCISO, is a senior chief information security officer who works part-time, typically one to three days a week, and owns the security strategy, risk and board reporting for a business that does not yet need a full-time CISO. An interim CISO does the same job full-time for a fixed term, usually to cover a gap, lead a certification or manage the aftermath of an incident.
Intology provides both. Every engagement is led by one named executive who sits on your side of the table. Intology sells no security tooling, monitoring or managed services, so the CISO can oversee your security suppliers rather than being one of them.
Fractional, virtual or interim CISO
The three terms are used interchangeably, but the arrangements behind them differ.
| Fractional CISO | Virtual CISO from an MSSP | Interim CISO | |
|---|---|---|---|
| Who it is | One named executive on your leadership team | Often a rotating advisory team bundled with a security service | One named executive, full-time |
| Commitment | One to three days a week, rolling | Set by the service contract | Full-time for a fixed term, typically three to twelve months |
| Accountable to | Your board and audit committee | The supplier's service contract | Your board and audit committee |
| Best for | Ongoing ownership of the security agenda | Run-state security operations | A gap, an incident or a certification deadline |
Intology's fractional CISO is what many buyers search for as a vCISO, with one difference: it is independent of any security supplier.
When a fractional CISO is the right call
- Cyber risk is on the board agenda and nobody in the room can answer for it with authority
- Customers, insurers or regulators are asking for evidence of controls and a named security owner
- A certification such as ISO 27001, Cyber Essentials Plus or SOC 2 is required and needs executive ownership
- NIS2, DORA or UK GDPR obligations reach the business directly or through its customers
- An incident has exposed gaps in governance, response or reporting
- A sale or investment is coming and the security posture will be examined in due diligence
If a security function is already well led and reporting properly to the board, you probably do not need a CISO engagement. We will say so.
What a fractional or interim CISO owns
Security strategy and risk ownership
A security strategy matched to the business risk appetite, and ownership of cyber risk on the board risk register.
Board and audit committee reporting
Security reported in terms directors can act on, with a named executive who answers the questions.
Certification and compliance
ISO 27001, Cyber Essentials Plus and SOC 2 programmes led, and NIS2, DORA and UK GDPR obligations mapped and managed.
Supplier and MSSP oversight
Managed security providers and tooling held to account against the risks they are paid to manage.
Incident readiness and response
An incident response plan that has been tested, clear decision rights, and executive leadership when something goes wrong.
Security in change and AI
Security built into transformation programmes, cloud migrations and AI adoption from the start.
Fractional CISO for private equity portfolio companies
The security posture of a portfolio company is examined twice: at acquisition and at exit. A fractional CISO puts the governance, evidence and controls in place in between, so security supports the value creation plan rather than eroding it at exit.
Before completion, see technology due diligence. For AI connector risk specifically, see the AI connector and MCP security audit.
Who leads the engagement
Intology's fractional and interim CISO engagements are led by Richard Keenlyside, Intology's founder, who has 34 years of board-level technology leadership across CISO, CIO, CTO and Transformation Director roles. See his board-level cyber security advisory experience and cyber security due diligence work in M&A.
Related leadership roles
Fractional and Interim CIO
Enterprise IT, ERP, data and business systems
Fractional and Interim CTO
Product technology, platform and engineering
Fractional Chief AI Officer
AI strategy, risk and value
Interim Transformation Director
Accountable for the business change outcome
Frequently asked questions
What is a fractional CISO?+
Is a fractional CISO the same as a virtual CISO (vCISO)?+
What is the difference between a fractional CISO and an interim CISO?+
Does a fractional CISO replace our MSSP?+
Can a fractional CISO lead ISO 27001 certification?+
What does a fractional CISO cost?+
Is Intology independent of security vendors?+
Can your board answer for its cyber risk?
Tell us what is driving the question: a customer, an insurer, a regulator, a certification or an incident. We will tell you honestly whether you need a fractional CISO, an interim CISO or something narrower. The first conversation is confidential.