The message is short and it does not sound like a crisis. Their security team asks: who is your CISO, or who owns security at your company, and can we get them on a call.
You do not have a CISO. You have a founder who reads about security, a senior engineer who set up the VPN, and a Notion page called Security Policies that nobody has opened since last year. The deal is real, it is large, and it is now waiting on an answer you do not have.
This is one of the most common ways an enterprise deal stalls. It is worth being precise about what is actually being asked, because the obvious reading of it is wrong.
What the buyer is actually asking for
They are not asking whether you have a C-level headcount. A twelve-person company obviously does not have a CISO, and the reviewer knows that before they ask.
They are asking three things at once.
- Is there one accountable person. Someone whose name goes next to security, who can make a decision without convening a committee.
- Can that person hold a technical conversation. Their security engineers want to ask about tenant isolation, key management, and your access model, and get real answers rather than a sales deck.
- Will someone still be accountable in a year. They are signing a multi-year contract. They want security to be a function, not a mood.
The subtext is risk transfer. The reviewer needs a name to put in their file. When you answer that the whole team owns security, they hear that nobody owns security, because in their own organization that sentence is precisely how things fall through.
Why we all own security is the wrong answer
It is a fine engineering culture value. It is a bad answer to a vendor security review.
Distributed ownership works when everyone involved is senior and the stakes are internal. In a review, it produces the exact failure the buyer is screening for: an open question with no obvious next step and no one to route it to. When they ask who signs off on a risk exception, the answer that we would discuss it as a team is not something they can write down.
You do not need to hire an executive to fix this. You need a name, a real one, attached to someone who can actually do the job.
What a named security owner does on a blocked deal
On a deal that is stuck, the work is narrower and far more concrete than a job description suggests:
- Takes the buyer call and answers the technical questions directly, in their language
- Completes or corrects the security questionnaire so the answers are accurate and defensible
- Triages the buyer objections into must-fix-before-signing and can-credibly-commit-to
- Closes the blocking control gaps, hands-on
- Owns the SOC 2 path if the contract requires a report
That is a bounded piece of work with a finish line: the deal clears procurement. It is a different shape from running a security program indefinitely, and that difference is where most of the confusion about these engagements lives.
Which engagement you actually want
Fractional CISO, virtual CISO, vCISO, interim CISO, CISO-as-a-Service, fractional head of security. The market has six names for roughly one role, and the naming tells you almost nothing. The useful question is not what it is called. It is what triggered the conversation.
Sort by trigger and it gets simple.
A specific deal is stuck right now
This is the enterprise-deal engagement. The scope is defined by the deal. You get a named CISO the buyer can engage directly, fast questionnaire completion, objection triage, and hands-on remediation of whatever is blocking. It ends when the deal clears. Take this one when there is a contract with a name and a number on it, waiting.
The seat was full and now it is empty
This is an interim CISO. Your security leader left, or you are mid-audit and the owner is gone. You already have a program and it needs continuity: the in-flight audit stays on track, customer reviews still get answered, and your eventual permanent hire inherits an organized handoff instead of wreckage. The trigger is a departure or a crunch, not a deal.
Security keeps coming up and nobody owns it
This is the ongoing fractional CISO engagement, also sold as CISO-as-a-Service. Not one deal, a program: roadmap, board reporting, vendor and third-party risk, policy, and compliance ownership, month over month. The trigger is repetition. When the third questionnaire of the quarter arrives, or the board starts asking, you have outgrown the ad-hoc approach.
You are building the function and making your first hires
This is a fractional head of security. The goal is a security function that eventually does not need us: a strategy, the first security roles defined and hired well, and a transition plan to bring it in-house.
Plenty of teams start at the first and end up at the third, because the deal that forced the conversation is rarely the last deal. But start with the trigger you actually have, not the org chart you imagine.
What it costs
A fractional or virtual CISO typically runs $3,000 to $15,000 per month, against a base salary of $300,000 or more for a full-time CISO before equity and benefits. Our own fractional CISO work runs roughly $3K to $8K per month, and it is an operator engagement rather than advisory, which means someone does the work instead of pointing at it. The full breakdown is in our guide to what a fractional CISO costs.
The monthly rate is usually not what decides it. The calendar is. Hiring a senior security leader takes three to six months, and a strong candidate may not exist in your market at all. Your deal does not have three to six months. That timing gap, more than the salary, is why this path exists.
When you should not do this
Two cases worth naming.
If your buyer literally requires a full-time employee in the CISO seat, which is rare outside certain regulated environments, a fractional engagement will not satisfy the contract. Ask your champion to confirm that requirement in writing before you assume it, because it is more often an assumption on your side than a rule on theirs.
And if you genuinely have someone internal who owns security, can hold the technical call, and simply has no time this month, you may not need leadership at all. You may just need the review taken off their plate. That is a smaller and cheaper problem, and we would tell you so.
Where we come in
We do the enterprise-deal version of this constantly, because it is the trigger that brings most people to us in the first place. You get a named security leader your buyer can engage directly, the questionnaire handled, and the blocking gaps closed. Our founder is a published security researcher with five CVEs who has taken a product through SOC 2 Type II covering 76 controls, so the person on your buyer call has built the thing rather than only advised on it.
We are the prep partner, not the auditor. If the contract requires a SOC 2 report, we get you audit-ready and coordinate the independent CPA firm that signs it, because that signature can only come from a licensed firm that is separate from whoever prepared you.
Is a deal waiting on a security owner you do not have?
Tell us who is asking and what they need to see. We will tell you straight whether this is a deal engagement, an ongoing program, or something your team can handle without us.
Talk to usHow to Introduce a Fractional Security Owner Without Losing the Room
The mechanics of this matter more than founders expect, because the reviewer's first instinct when they hear the word fractional is that security has been outsourced to a firm that will disappear when the invoice stops. That instinct is reasonable and you have to answer it before it hardens.
Say it plainly in the introduction email. Something close to this works: our security program is led by a fractional CISO, engaged on a continuing basis, and they are the accountable owner for security decisions including risk acceptance. Then give them a real address at your domain, put them on the call, and let them answer without a founder interrupting to add context. The single fastest way to undo the position is for the buyer to ask a direct technical question and watch the founder answer it first. That tells the reviewer the CISO is decorative.
What does not work is concealment. Do not present a contractor as an employee, and do not give them a title in the deal that they do not hold in your own records. Enterprise buyers run background checks, read LinkedIn, and occasionally ask for an org chart during vendor onboarding. Being caught overstating the arrangement costs you more than the arrangement itself ever would have. This is the same principle that governs questionnaire answers generally, and we go through it in detail in the piece on what to do when an enterprise security review blocks a deal.
The First Two Weeks of a Deal Engagement
A deal-triggered engagement is not a discovery exercise followed by a strategy document. The clock is the constraint, so the order of work is set by what unblocks the buyer soonest.
Days one to three. Get the full ask in writing from the buyer, not from your account executive's summary of it. That means the questionnaire itself, the list of evidence requests, whether there is a live technical call, and who signs off at the end. In parallel, inventory what already exists: policies in whatever state they are in, the identity provider configuration, the last penetration test if there is one, the cloud account structure, and the subprocessor list. Most companies have more than they think and it is scattered across four tools.
Days four to seven. Draft the questionnaire response and split every answer into three buckets. Answers that are true today and evidenced. Answers that are true today but have no artifact, which is a documentation job rather than an engineering job. And answers that are honestly no. The third bucket is the deal risk, and it is usually much shorter than the founder feared.
Days eight to fourteen. Triage the no answers by whether the buyer will actually hold the contract on them. Mandatory MFA on production access, a documented incident response process, encryption at rest, and offboarding evidence are close to non-negotiable at any enterprise. A formal internal audit function, a 24/7 monitoring capability, or a specific data residency guarantee are frequently negotiable, and the right move is to ask rather than to build. Close the non-negotiable gaps, put credible dates on the rest, and send the response with the live call booked.
Objection Triage, Worked Through
Here is the shape of a real triage on a stalled deal. The buyer returns eleven concerns. Four are answered by evidence that already exists and was simply never attached, so they close within a day. Three are documentation gaps: a written access control policy, a retention schedule, and a subprocessor list that has never been formalized. Those cost a few days of writing, not engineering time. Two are genuine technical gaps, typically shared administrative credentials on a legacy system and no centralized logging for production access, which need engineering hours and cannot be talked away. The last two are architectural, something like single-tenant isolation the buyer wants and your product does not have, and those cannot be fixed inside a deal cycle at all.
The value of the triage is that it separates the two architectural items from the other nine early enough to negotiate them. You go back to the champion with nine items closing on a dated plan and a direct conversation about the remaining two: here is our current isolation model, here is the compensating control, here is our roadmap position and whether it moves depends on this contract. Buyers say yes to that far more often than they say yes to silence followed by a hopeful yes.
The Failure Modes Worth Screening For
The advisor who will not touch the keyboard. Some engagements deliver a maturity assessment, a roadmap, and a monthly steering call. That is a legitimate product and it is the wrong product for a blocked deal, because nothing in it closes a control gap. Ask directly whether the engagement includes hands-on remediation or only direction, and get the answer before you sign.
No engineering capacity behind the plan. A fractional CISO can write the policy, configure the identity provider, and answer the buyer. They cannot rebuild your tenancy model. If the blocking gaps are deep in your product, you need engineering time allocated in the same weeks, and that is a founder decision nobody else can make for you.
The person who will not take the buyer call. The entire point of the engagement is that a named human answers the reviewer's engineers directly. If the arrangement routes buyer questions back through you to be relayed, you have bought a consultant, not an owner.
Rotating faces. If the firm assigns whoever is free that month, the buyer notices at the second review. Ask who specifically will hold the seat and what happens if they leave.
What Happens When the Engagement Ends
A deal engagement has a finish line, which is good, but it creates a question the buyer will eventually ask on renewal: who owns security now. Plan the answer before you need it.
The clean version is a documented handover: the risk register, the open remediation items with owners and dates, the evidence library, the vendor register, and the questionnaire response set with sources for every answer. If a permanent hire arrives, they inherit a working program instead of archaeology. If nobody arrives, you either extend into an ongoing arrangement or you accept that the next questionnaire will be answered by whoever has time, which is the position you started in. Naming that choice openly is better than drifting into it. Continuing coverage is what a retainer is for, and the honest test of whether you need one is simply how many security reviews you expect in the next twelve months.
One contractual detail catches people out. Enterprise master services agreements sometimes require notification when your security leadership changes, and occasionally require that a named individual remain accountable for the term. If your fractional owner rotates out six months into a three-year contract and you never told the buyer, you have a contractual problem alongside a trust problem. Read that clause before you sign it, not after.
A Second Case Where the Answer Is Not a Fractional CISO
The article above names two situations where this engagement is wrong. There is a third that comes up more often than either, and it is worth being blunt about.
Sometimes the deal is not actually blocked on security. It is blocked on a data processing agreement your legal counsel has not returned, on a cyber insurance certificate with the wrong limit, on a data residency requirement that is a hosting decision rather than a security one, or on a procurement queue that has nothing to do with you. Founders hear the word security in a stalled deal and buy security leadership, when a two-line question to the champion asking what specifically is outstanding would have identified a $2,000 insurance endorsement or a lawyer's afternoon. Ask that question first. It costs nothing and it occasionally saves the entire engagement fee.
There is also a version where the honest answer is that the buyer's requirement cannot be met in the deal timeline no matter who you hire. If they require a completed SOC 2 Type II report and you have not started, no amount of security leadership produces an observation window that has not happened. The useful move there is renegotiation: a signed readiness engagement, a dated commitment, and a contractual security addendum in the interim. Plenty of enterprises accept that. A firm that tells you otherwise and sells you a retainer anyway is selling you the wrong month of work. If you want a straight read on which of these your situation is, tell us what the buyer actually asked for and we will say so, including when the answer is that you do not need us.
Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.
Fractional CISOOr talk about a retainer