Fractional CISO Engagement Models
Flexible, hour-based packages that scale with your needs. One accountable leader. Framework-driven. Vendor-neutral.
Security Medic provides fractional CISO and CTO leadership through structured monthly engagements. Each package includes strategic direction, governance oversight, and executive reporting — with deeper delivery running through our specialized practices: Hudson Valley CISO for governance, CyberIntelPro for operations, and Privacy Medic for privacy programs.
Starter
Foundation for organizations beginning their security journey
What's Included:
- ✓Initial security posture discovery and gap assessment
- ✓Essential policies and procedures (incident response, acceptable use, data classification)
- ✓Cyber insurance readiness assessment and remediation roadmap
- ✓3-month security roadmap aligned to business priorities
- ✓Monthly executive summary with risk status and recommendations
Standard
Comprehensive leadership for growing security programs
Everything in Starter, plus:
- ✓Incident response playbook development and tabletop exercise
- ✓Security awareness program kickoff and training coordination
- ✓KPI dashboard and metrics reporting for leadership
- ✓Vendor risk assessment framework and third-party oversight
- ✓Quarterly strategic planning sessions with executive team
Comprehensive
Full executive leadership for regulated or high-risk environments
Everything in Standard, plus:
- ✓SOC 2 or ISO 27001 readiness assessment and gap remediation
- ✓Application threat modeling and secure development lifecycle guidance
- ✓Board-level cybersecurity reporting and strategic risk briefings
- ✓M&A cybersecurity due diligence and integration planning
- ✓On-call incident response coordination and breach management
Investment Guidance
Fractional CISO engagements typically range from low-to-mid thousands per month depending on scope, complexity, and deliverables. Pricing is customized based on your specific requirements and risk profile. All packages are billed monthly with transparent hour tracking and no long-term contracts required.
How We Deliver
You engage one firm with one accountable leader. Depending on your needs, deeper program delivery may run through our specialized practices:
Governance, audit program design, policy development, and strategic oversight
Operational security across NIST CSF 2.0 lifecycle functions (Identify, Protect, Detect, Respond, Recover)
Privacy program design, NIST Privacy Framework, HIPAA Privacy Rule, and AI governance
Not Sure Which Package Fits?
Book a free 30-minute assessment. We'll review your current posture, identify gaps, and recommend the right engagement model — no obligation.
Schedule Your Free Assessment