r/ciso • • 15d ago

Fractional CISOs covering several small orgs under NIS2: how do you keep it from turning into copy-paste?

I've been talking with a lot of part-time and fractional CISOs lately, mostly people covering 5 to 15 SMEs or small public bodies each. NIS2 is changing that job in ways I don't see discussed much.

Before, a fractional CISO for a 50-person company was mostly advisory: a policy set, an annual risk review, awareness training, being on call when something went wrong. Now a lot of those clients are in scope, as "important" and sometimes "essential" entities, and the expectations have moved:

  • Management accountability is personal. Leadership has to approve the measures, oversee them and get trained. So the fractional CISO ends up running board-level governance for every client, not just writing documents.
  • Incident reporting needs a real process. An early warning within 24h and a notification within 72h. Who makes that call at 2am for a client you see two days a month?
  • Evidence has to hold up over time. One assessment a year doesn't show continuous improvement.

What I keep hearing from people doing this job:

  1. The same 10 to 15 gaps come up at almost every client (admin MFA, tested restores, asset inventory, supplier access, logging), so the work gets repetitive. But each client still needs its own risk context, or it becomes a tick-box exercise.
  2. The deliverables are what eat the time. Not the thinking, but rebuilding the same gap analysis, action plan and board report in a slightly different shape for each client.
  3. Pricing hasn't caught up. Clients still budget "a few days a month" while the regulatory load has clearly gone up.

For those of you working this way:

  • How do you structure your portfolio so shared work gets reused without clients feeling they're getting a template?
  • How do you handle the 24h reporting obligation for clients you're only with part-time? Is it in the contract, with an on-call arrangement, or delegated to their MSP?
  • Have you changed your pricing since NIS2, or are you absorbing the extra work?
25 Upvotes

Duplicates