Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

Virtual CISO for B2B SaaS

Somewhere between your first enterprise deal and your tenth, a prospect's procurement team sends over a security questionnaire that nobody on your team knows how to answer. A few weeks later, another deal stalls because legal wants to see your incident response plan. By the time a third prospect asks who owns security at your company, the pattern is clear: engineering leadership can build the product, but nobody owns the security program. That gap is exactly what a virtual CISO, also called a fractional CISO, is built to close.

Why B2B SaaS hits this wall earlier than other sectors

B2B SaaS companies face a specific set of pressures that other businesses don't feel until much later, if ever. You are asking enterprise buyers to trust you with their customer data, their financial records, or their operational systems, often before you have the headcount to justify a full-time security executive. A 40-person SaaS company selling into US enterprise or mid-market accounts can face the same due diligence bar as a 400-person company, just without the budget for a $250,000-plus salaried CISO.

The stakes compound quickly. A single unanswered security questionnaire can freeze a six-figure deal. A missed SOC 2 renewal can trigger a churn clause. A vague answer to "who is your security lead" in a vendor risk review can knock you out of a shortlist before a human even reads your pitch. These aren't hypothetical friction points, they're recurring, predictable checkpoints in every enterprise sales cycle, and they show up long before most SaaS companies are ready to hire security leadership internally.

There's also a talent problem. Experienced CISOs are expensive and hard to hire, and most SaaS companies at Series A through C don't have five days a week of CISO-level work to justify the cost. What they have is a real, ongoing need for someone senior enough to own the program, sign off on vendor risk, sit in the room for board and customer conversations, and make security decisions that hold up under scrutiny, just not enough of that work to fill a full calendar.

What a virtual CISO actually owns

A fractional CISO engagement isn't a consultant who shows up for a quarterly audit and disappears. Done properly, it's ongoing ownership of the parts of a security program that don't run themselves: the security questionnaires that show up every time a deal reaches procurement, the vendor risk assessments your own vendors need to submit, the policies and controls that back your compliance posture, and the board and executive reporting that tells leadership where the real risk sits, not just what's on a checklist.

Our fractional CISO service is built around that reality. It's not a project with an end date, it's ongoing security leadership scoped to what a growth-stage SaaS company actually needs: someone who owns the program, represents you credibly in front of enterprise buyers and auditors, and makes the judgment calls that a checklist can't make for you. For a company still building its security function, that's the difference between reacting to each new questionnaire as a fire drill and having a program that answers most of those questions before they're asked.

The credibility piece matters more than most SaaS founders expect. Enterprise security teams and auditors can tell the difference between a policy document assembled from a template and a program run by someone who actually understands the threat landscape. Jacob Masse, who leads security work at traztech, is a published security researcher with five CVEs to his name, including CVE-2024-45163, a critical (CVSS 9.1) vulnerability that functioned as a kill-switch against the Mirai botnet. When your virtual CISO can speak to real vulnerability research in a customer security review, that's a different conversation than one led by someone reciting framework language.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire. Fractional CISO

How traztech scopes a virtual CISO engagement

We start by figuring out where your company actually is, not where a generic framework assumes you are. A pre-Series A SaaS company answering its first enterprise questionnaires needs something different from a Series C company renewing SOC 2 for the third time while expanding into a new region. Scoping starts with three questions: what commitments are already on the table (a signed customer contract with a security clause, a target SOC 2 audit date, an upcoming funding round with security diligence attached), what your current security posture actually looks like versus what it's assumed to look like, and how much of the work your internal team can execute once someone senior is directing it.

From there, the engagement is scoped around a cadence, not a fixed list of deliverables. That typically includes a recurring block of hours each month for questionnaire response and vendor risk review, a standing seat in customer and board-facing security conversations, ownership of policy and control documentation, and a direct line for the fire drills that don't wait for a scheduled call, an incident, an urgent customer ask, an audit finding that needs an answer in 48 hours. The point isn't to sell you a bundle of hours. It's to make sure someone with real authority is accountable for the program, so security stops being a shared responsibility that nobody actually owns.

Many of the SaaS companies we work with are also mid-way through a compliance push, most often SOC 2, sometimes with ISO 27001 or PIPEDA obligations layered on top. Where that's the case, the virtual CISO engagement runs alongside our broader compliance work, so the same person directing your security program is also the one accountable for getting you audit-ready, rather than handing that off to a separate team that has to relearn your environment from scratch.

What to look for before you commit

If you're evaluating fractional CISO options, ask a few direct questions. Who is actually doing the work, and what's their background beyond a certification list? How is the engagement scoped, hours per month, specific deliverables, or something vaguer? What happens when an enterprise customer wants a live conversation with your security lead, not a written response? And can this person credibly represent your security posture to a skeptical enterprise buyer, or are they going to read from a template in that meeting? The answers separate a real security leadership function from a compliance paperwork service wearing a CISO title.

If your SaaS company is fielding security questionnaires you can't confidently answer, facing an enterprise deal that's stalled on security diligence, or simply doesn't have anyone accountable for the security program yet, get in touch and we'll walk through what a fractional CISO engagement would look like for where you are today.

What the first ninety days should produce

A fractional CISO engagement that has not produced anything tangible by day ninety is drifting, and you should say so out loud in the first month rather than discovering it in month five. The early work is unglamorous and mostly consists of finding out what is actually true. Someone has to pull the full list of production admins from your identity provider and compare it against your current payroll, read the security clauses in the three or four customer contracts you have already signed, inventory which third parties hold customer data, and work out whether your logging retention would actually let you reconstruct an incident from four months ago. Most SaaS teams believe they know the answers to those questions. In practice the admin list has two contractors who left last year, one of the signed contracts commits you to a 24 hour breach notification window nobody has told the on-call team about, and log retention is seven days because that was the default.

By the end of the first quarter you should have a written control set that maps to whatever framework your buyers are asking about, a security questionnaire answer library that covers the eighty or so recurring questions, a named owner for each control who is not the fractional CISO, and a risk register that a board member can read without a translator. The answer library is the piece that pays for itself fastest. Once it exists, a questionnaire that used to consume two engineering days becomes a two hour editing job, and your sales team stops treating security review as an unplanned emergency.

What a fractional CISO does not do

This is where engagements go wrong most often, and it is worth being blunt about it before anyone signs. A fractional CISO is not a pair of hands. If your SSO rollout needs configuring, your Terraform needs a policy module written, or your alerting needs tuning, that is engineering work and it belongs to your engineers. A senior security leader charging leadership rates to do implementation work is an expensive way to buy implementation, and any provider willing to bill it that way is optimizing for their own utilization rather than your outcome.

Nor is a fractional CISO your incident responder in the first hour of a live compromise. They should own the incident response plan, run the tabletop exercises, make the call on customer and regulator notification, and be the person who talks to the affected customer's security team. But if you need forensics, containment, and log analysis at three in the morning, that is a different capability with a different retainer, which is why incident response tends to sit as a separate line in an ongoing engagement rather than as an assumed part of the leadership scope. Ask directly what happens on a Saturday. If the answer is vague, assume the answer is nothing.

They also cannot manufacture authority you have not granted. A fractional CISO with no ability to block a release, no standing invitation to the engineering leadership meeting, and no direct line to the CEO becomes a very well qualified writer of documents nobody reads. The single strongest predictor of a successful engagement is whether the founder actually backs the security decisions when they are inconvenient, for example when a customer wants a feature that would weaken tenant isolation, or when a deal team wants to answer a questionnaire more generously than the evidence supports.

What enterprise buyers ask in a live security call

Written questionnaires are the easy part. The harder moment is the thirty minute call where a buyer's security architect wants to speak to your security lead, and that call is where a templated program comes apart. The questions are rarely framework recitations. They are things like: walk me through what happens when an engineer needs production access to debug a customer issue, and show me the log of the last three times that happened. How is one tenant's data separated from another at the database level, and what stops a query bug from crossing that boundary. Who has access to your CI system's deployment credentials, and what would we see if those credentials were used at two in the morning. When did you last restore from backup as a test rather than as an emergency.

Buyers ask these because they reveal whether a control exists in operation or only in a policy document. A security lead who can answer with specifics, including the parts that are still weak, generally clears the review. One who answers every question by describing intent rather than mechanism gets a follow-up list and a delayed deal. The uncomfortable truth is that admitting a gap with a dated remediation plan almost always lands better than claiming a maturity you cannot evidence, because the reviewer will find the gap during the technical follow-up anyway and will then discount everything else you said.

Cost drivers, and where the money actually goes

Fractional CISO work at traztech starts from $3,000 per month, and the variables that move a scope up from there are reasonably predictable. Volume of enterprise deals is the biggest one, because every deal in procurement generates questionnaire work, a vendor risk review, sometimes a live call, and often a redline negotiation on the security schedule of the contract. Number of frameworks is the second: running SOC 2 alone is a different workload from running SOC 2 while a European buyer asks about ISO 27001 and a Quebec customer asks about Law 25. Regulated data raises the floor because the control set widens and the evidence burden goes up. So does an audit window that is already in progress, since you are then paying for leadership and remediation pressure at the same time.

Things that quietly reduce cost are worth naming too. A team that already has SSO with enforced MFA, a real offboarding checklist, infrastructure defined as code, and centralized logging can skip months of foundational work. A single internal owner who can execute what the CISO directs is worth more than an extra day per month of external time. And a founder who is willing to say no to a customer's unreasonable security demand occasionally saves more money than any tooling decision.

When you should not hire a fractional CISO

Several situations call for something cheaper or simply for nothing at all. If you have exactly one enterprise prospect asking one questionnaire and no compliance deadline behind it, buy help with that questionnaire and stop there. A month of leadership retainer to answer a document you will not see again for a year is poor value. If you already have a staff engineer who genuinely enjoys this work, has the trust of the founders, and can be given twenty percent of their time and a budget, that person plus a few days of external advice will usually outperform an external leader with no internal standing. Growing your own security owner is slower and better, and a good external partner will tell you that.

If your real problem is that a fixed, known piece of work needs finishing, a fixed-scope engagement is the honest answer. Readiness for a specific audit, a defined assessment, a scoped test: these have a beginning and an end, and our published fixed-scope pricing exists precisely so you can buy the defined thing without also buying a retainer. Pre-revenue companies with no customer data, no signed security commitments, and no imminent audit are better served by spending the money on the product and setting up the boring hygiene basics themselves.

There is also a size ceiling. Once you are past roughly a hundred and fifty people, or once security work occupies more than about two days a week on a sustained basis, fractional leadership stops being the efficient shape. At that point the engagement should convert into helping you write the job description, interview candidates, and hand over a documented program to a full-time hire. An external partner who resists that conversation, or who has arranged the program so that only they can run it, has a conflict of interest you should take seriously.

Making the handover survivable

Assume from day one that the engagement ends. That assumption changes how the work is built: control documentation lives in your systems rather than the consultant's laptop, the risk register is a live artifact your team edits, evidence collection runs on a calendar your team can see, and every recurring task has an internal deputy who has done it at least once. We keep client-facing program artifacts inside the free traztech Workspace for exactly this reason, so that the register, the evidence, and the open items remain yours whether or not the relationship continues. If your incoming full-time CISO has to reconstruct the program from scratch, the previous engagement failed regardless of how good the reports looked at the time.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.

Fractional CISOOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.