Board-level security leadership, without the full-time hire

Fractional CISO and Virtual CISO

A fractional CISO, often called a virtual CISO or vCISO, is a senior chief information security officer who works part-time, typically one to three days a week, and owns the security strategy, risk and board reporting for a business that does not yet need a full-time CISO. An interim CISO does the same job full-time for a fixed term, usually to cover a gap, lead a certification or manage the aftermath of an incident.

Intology provides both. Every engagement is led by one named executive who sits on your side of the table. Intology sells no security tooling, monitoring or managed services, so the CISO can oversee your security suppliers rather than being one of them.

No tooling or MSSP revenue One named executive Board and audit committee ready

Fractional, virtual or interim CISO

The three terms are used interchangeably, but the arrangements behind them differ.

Fractional CISOVirtual CISO from an MSSPInterim CISO
Who it isOne named executive on your leadership teamOften a rotating advisory team bundled with a security serviceOne named executive, full-time
CommitmentOne to three days a week, rollingSet by the service contractFull-time for a fixed term, typically three to twelve months
Accountable toYour board and audit committeeThe supplier's service contractYour board and audit committee
Best forOngoing ownership of the security agendaRun-state security operationsA gap, an incident or a certification deadline

Intology's fractional CISO is what many buyers search for as a vCISO, with one difference: it is independent of any security supplier.

When a fractional CISO is the right call

  • Cyber risk is on the board agenda and nobody in the room can answer for it with authority
  • Customers, insurers or regulators are asking for evidence of controls and a named security owner
  • A certification such as ISO 27001, Cyber Essentials Plus or SOC 2 is required and needs executive ownership
  • NIS2, DORA or UK GDPR obligations reach the business directly or through its customers
  • An incident has exposed gaps in governance, response or reporting
  • A sale or investment is coming and the security posture will be examined in due diligence

If a security function is already well led and reporting properly to the board, you probably do not need a CISO engagement. We will say so.

What a fractional or interim CISO owns

Security strategy and risk ownership

A security strategy matched to the business risk appetite, and ownership of cyber risk on the board risk register.

Board and audit committee reporting

Security reported in terms directors can act on, with a named executive who answers the questions.

Certification and compliance

ISO 27001, Cyber Essentials Plus and SOC 2 programmes led, and NIS2, DORA and UK GDPR obligations mapped and managed.

Supplier and MSSP oversight

Managed security providers and tooling held to account against the risks they are paid to manage.

Incident readiness and response

An incident response plan that has been tested, clear decision rights, and executive leadership when something goes wrong.

Security in change and AI

Security built into transformation programmes, cloud migrations and AI adoption from the start.

Fractional CISO for private equity portfolio companies

The security posture of a portfolio company is examined twice: at acquisition and at exit. A fractional CISO puts the governance, evidence and controls in place in between, so security supports the value creation plan rather than eroding it at exit.

Before completion, see technology due diligence. For AI connector risk specifically, see the AI connector and MCP security audit.

Who leads the engagement

Intology's fractional and interim CISO engagements are led by Richard Keenlyside, Intology's founder, who has 34 years of board-level technology leadership across CISO, CIO, CTO and Transformation Director roles. See his board-level cyber security advisory experience and cyber security due diligence work in M&A.

Related leadership roles

Fractional and Interim CIO

Enterprise IT, ERP, data and business systems

Fractional and Interim CTO

Product technology, platform and engineering

Fractional Chief AI Officer

AI strategy, risk and value

Interim Transformation Director

Accountable for the business change outcome

Frequently asked questions

What is a fractional CISO?+
A fractional CISO is a senior chief information security officer who works part-time, typically one to three days a week, on a rolling engagement. They own security strategy, risk and board reporting with the same accountability as a permanent CISO.
Is a fractional CISO the same as a virtual CISO (vCISO)?+
The terms overlap. "Virtual CISO" is often used by managed security providers for an advisory service bundled with their tooling or monitoring. An Intology fractional CISO is one named executive, independent of any security supplier, accountable to your board.
What is the difference between a fractional CISO and an interim CISO?+
A fractional CISO works part-time on an ongoing basis. An interim CISO works full-time for a fixed term to cover a gap, lead a certification or manage the response to an incident.
Does a fractional CISO replace our MSSP?+
No. The MSSP runs security operations. The fractional CISO sets the strategy, owns the risk and holds the MSSP to account.
Can a fractional CISO lead ISO 27001 certification?+
Yes. Leading certification programmes and the ongoing governance that keeps them in place is a core part of the role.
What does a fractional CISO cost?+
The fee depends on days per week, duration and the mandate, and is agreed in writing before any work starts.
Is Intology independent of security vendors?+
Yes. Intology sells no security tooling, monitoring or managed services and holds no reseller agreements or vendor partnerships.

Can your board answer for its cyber risk?

Tell us what is driving the question: a customer, an insurer, a regulator, a certification or an incident. We will tell you honestly whether you need a fractional CISO, an interim CISO or something narrower. The first conversation is confidential.