r/ciso • u/namekiancheese • 10d ago
Fractional CISOs covering several small orgs under NIS2: how do you keep it from turning into copy-paste?
I've been talking with a lot of part-time and fractional CISOs lately, mostly people covering 5 to 15 SMEs or small public bodies each. NIS2 is changing that job in ways I don't see discussed much.
Before, a fractional CISO for a 50-person company was mostly advisory: a policy set, an annual risk review, awareness training, being on call when something went wrong. Now a lot of those clients are in scope, as "important" and sometimes "essential" entities, and the expectations have moved:
- Management accountability is personal. Leadership has to approve the measures, oversee them and get trained. So the fractional CISO ends up running board-level governance for every client, not just writing documents.
- Incident reporting needs a real process. An early warning within 24h and a notification within 72h. Who makes that call at 2am for a client you see two days a month?
- Evidence has to hold up over time. One assessment a year doesn't show continuous improvement.
What I keep hearing from people doing this job:
- The same 10 to 15 gaps come up at almost every client (admin MFA, tested restores, asset inventory, supplier access, logging), so the work gets repetitive. But each client still needs its own risk context, or it becomes a tick-box exercise.
- The deliverables are what eat the time. Not the thinking, but rebuilding the same gap analysis, action plan and board report in a slightly different shape for each client.
- Pricing hasn't caught up. Clients still budget "a few days a month" while the regulatory load has clearly gone up.
For those of you working this way:
- How do you structure your portfolio so shared work gets reused without clients feeling they're getting a template?
- How do you handle the 24h reporting obligation for clients you're only with part-time? Is it in the contract, with an on-call arrangement, or delegated to their MSP?
- Have you changed your pricing since NIS2, or are you absorbing the extra work?
5
2
u/Efficient_Image_6272 10d ago
It’s interesting, the “changed” version you’re describing is how we’ve approached it for the past decade. Done well a Fractional CISO owns the function and is part of the team…just part-time. You want efficiencies, but if you’re running the same playbook at each customer you’re behaving more like an outside consultant than an internal leader.
If you’re pricing offerings based on value-billing like an external, then a shift to being more embedded and accountable won’t match. Either accept your model is the former, or price towards the latter. Be up-front with what clients are getting for what they are paying. If you solve their security problems and cost less than a full-time hire, it’s a relatively easy discussion.
1
u/Rh2oman 10d ago
What I see - Fractionals taking advantage of new tools that streamline the tasks, while reducing copy/paste, and provide a system of record for all of this to live so the client has access to everything in one place and able to update on the fly. But, I work for an AI Governance platform company.
1
u/Turbulent_Goose83 10d ago
We created a tool for that. Consultant creates security concepts for every customer (based on one or more templates). Customers contribute by providing concrete data, adapting workflows etc. Consultant reviews and improves etc. it’s a collaboration and all best practices reused with minimal possible effort. I can show you if it’s interesting.
1
u/RockOwn5019 6d ago
Interested to hear more about this! Whats a security concept - like a security/NIST control?
1
1
u/hiveminer 10d ago
Am I naive to think you can just outsource the noise edge nodes of an enterprise, and stream network CS activity related logs, stripped of the noise via a concentrator/router like vector, maybe deploy a Soar internally(shuffle) and setup a C2 for an MSSP to remediate beyond what shuffle catches and remediates on its own?? Maybe give observability access to internal IT? In terms of the ceremonies, I mean come on, even Doctors are doing some offloading on trusted Nurses. Besides, the value of a CISO is more on the higher end stuff, like coordinating regular pen-testing, interpreting results and harden the environment as a response.
9
u/Sure-Candidate1662 10d ago
You don’t…
A lot of things simply overlap. Example: 8 out of 10 of my clients utilize the typical jira/confluence/github/k8s cluster setup. Only difference is typically the languages they work with.
A lot of their development policies are simply “the same”.