Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security

Virtual CISO for Waterloo Startups

Yes, Waterloo Region startups need a virtual CISO earlier than most because the region's exit path runs through US enterprise and defence contracts, and both demand a named security leader before they'll sign. A virtual CISO gives a Series A or B company that leadership without the seven-figure salary a full-time hire would cost.

Why Waterloo Founders Keep Getting Asked for a CISO

If you've built a product in the Kitchener-Waterloo corridor, you've probably noticed the pattern. A US prospect's procurement team sends over a security questionnaire. A defence-adjacent partner asks who owns your security program. A VC doing diligence for your next round wants to see a named accountable executive, not a shared inbox. None of these asks are unreasonable. They're standard for any company selling into regulated or enterprise buyers, and Waterloo's startup base sells into exactly those buyers more often than most Canadian tech hubs.

The University of Waterloo pipeline, the Communitech network, and the concentration of quantum, cybersecurity, and enterprise software firms in the region mean local companies tend to punch above their headcount when it comes to sophistication of their customers. A twelve-person startup out of the Tannery or Catalyst137 can find itself fielding the same vendor security review as a company ten times its size. The problem is that the founder or the sole engineering lead ends up owning security as an unpaid side job, on top of shipping product. That's the gap a virtual CISO closes.

What a Virtual CISO Actually Does for an Early-Stage Company

A virtual CISO, sometimes called a fractional CISO, is a part-time or contract security executive who sets strategy, owns the security program, and represents the company to customers, auditors, and the board, without sitting on the payroll full-time. For a Waterloo startup this typically means:

  • Building and owning the security roadmap tied to actual deal blockers, not a generic checklist
  • Answering vendor security questionnaires and sitting on customer security calls as the named executive
  • Running vendor and access reviews, incident response planning, and policy sets that hold up to audit
  • Reporting security posture to the board and investors in language they can act on
  • Acting as the accountable owner during a SOC 2 or ISO 27001 audit cycle, working alongside whoever runs the actual audit

It's the leadership layer, not the ticket-closing layer. Most Waterloo startups already have engineers who can implement controls. What they're missing is someone with the title and the judgment to decide what to build first, what to defer, and what to say when a customer's security team pushes back. Our fractional CISO service is built specifically for that gap, sized to a startup's stage rather than a Fortune 500's org chart.

The Canadian Context: PIPEDA, Quebec Law 25, and Cross-Border Sales

Waterloo companies selling into the US still have to get their Canadian obligations right. PIPEDA governs how you handle personal information as a federally regulated business or across provincial lines, and if any part of your customer base touches Quebec, Law 25 brings its own consent and breach notification requirements that catch founders off guard. A virtual CISO who works across Canadian and US frameworks day to day can map your actual control set once, rather than building a US-only program and then bolting Canadian compliance on as an afterthought.

This dual fluency is also where a lot of US-headquartered virtual CISO providers fall short for Canadian founders. They know SOC 2 and US state privacy law well, but PIPEDA and provincial requirements are an afterthought. A Canadian boutique that lives in both worlds catches the gap before a customer's legal team does.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire. Fractional CISO

Why a Local, Boutique Partner Beats a Remote Platform

The market for security leadership-as-a-service has filled up with platforms that bundle a compliance dashboard with rotating advisory hours. That model works fine for a company that just needs a badge on its website. It works less well for a founder who needs someone to actually get on a call with a nervous enterprise customer, understand the specific architecture decisions behind a product built in Waterloo, and speak with authority because they've done the work themselves.

traztech is a Canadian boutique, not a platform with a call centre attached. Jacob Masse, who leads the practice, is a published security researcher with five CVEs to his name, including CVE-2024-45163, a CVSS 9.1 finding that functioned as a kill switch against the Mirai botnet. That's the kind of technical depth that lets a virtual CISO tell the difference between a control that satisfies an auditor on paper and one that would actually hold up against a real attacker, a distinction that matters a great deal to companies building genuinely sensitive technology, which describes a lot of what comes out of Waterloo.

How Engagements Typically Start

Most Waterloo engagements begin with one of three triggers: a customer security questionnaire the team can't confidently answer, a funding round where diligence flagged security as a gap, or a push into the US or federal market that suddenly requires a named security executive. From there, the work usually starts with a gap assessment against whatever framework the deal or the round actually requires, whether that's SOC 2, ISO 27001, or a lighter internal baseline for a company not yet audit-ready. If compliance certification is the near-term goal rather than ongoing leadership, our broader compliance advisory work covers the audit path itself, with the virtual CISO role often continuing afterward to keep the program alive between audits.

What doesn't work well is treating the virtual CISO engagement as a one-time project. Security posture decays the moment nobody owns it, and a startup's risk profile changes every few months as headcount, customers, and infrastructure grow. The value of a fractional arrangement is continuity: the same person tracking your program quarter over quarter, showing up for the board update, and being the one your enterprise customer's security team already knows by name.

Serving the Broader Ontario Tech Corridor

While this piece speaks to Waterloo specifically, the same pressures show up across the Toronto-Waterloo corridor and beyond, including Ottawa's government-adjacent tech sector, Vancouver's cross-border SaaS companies, Calgary's energy-tech firms, and Montreal's AI and fintech scene. traztech works directly with founders across these hubs, not through a remote support queue, because the questions a Waterloo founder asks about SOC 2 timelines or PIPEDA scope are rarely generic, and they deserve an answer from someone who has actually sat across from the customer asking them.

If your team is fielding security questionnaires it can't confidently answer, or a funding round just flagged security leadership as a gap, get in touch through our contact page and we'll walk through what a virtual CISO engagement would look like for your stage and your customers.

What the Engagement Looks Like on a Normal Week

Founders imagine either a strategy document or a full-time employee, and the reality sits between them. A typical Series A arrangement runs somewhere between two and six days a month, and the shape matters more than the total. A recurring weekly working call with whoever owns infrastructure keeps the roadmap moving. A standing slot for buyer security calls, booked reactively, because those requests arrive with two days of notice and a deal attached. A monthly written posture update that goes to the founders and, quarterly, to the board. Then the batched work: questionnaire responses, vendor reviews, policy revisions, access review sign-off, evidence checks before an audit window. Ask any provider to describe their month in those terms before you sign. If the answer is a number of advisory hours with no named recurring commitments, you are buying availability rather than ownership, and availability does not answer a procurement team at four on a Friday.

What Drives the Price Up or Down

Fractional CISO work starts at $3,000 a month and moves with a small number of factors. Headcount matters less than the number of distinct environments: one product on one cloud account is cheap to own, and three products across two clouds plus an acquired on-premise system is not. Sales pressure matters most of all: a company fielding two questionnaires a quarter needs a fraction of the attention of one fielding two a week. Watch for the pricing pattern where a low monthly retainer excludes everything that actually happens, so questionnaires, audit support and incident response all bill separately at a day rate. Get the inclusions in the statement of work. Our published pricing exists so you can compare against something specific rather than a discovery call.

The Questions to Ask Before You Sign

Ask who the named person is and whether that name appears in the contract, because plenty of firms sell you a principal and staff you with an associate. Ask what happens when that person is on leave or leaves the firm, and what the handover looks like. Ask for the exact language they will let you put in front of a customer describing their role, since some providers will happily be called your CISO in a sales meeting and then decline to be named in a contractual security schedule. Ask about professional liability cover and its limit, and read the limitation of liability clause, which in this market is often capped at fees paid. Ask who owns the artifacts: your policies, risk register and evidence should be yours in a portable format at the end, not locked inside the provider's tooling. Ask for the notice period, and prefer thirty days over annual lock-in, because a fractional relationship that is not working should be cheap to exit. Finally, ask them to describe an engagement that went badly. Anyone who has done twenty of these has one, and the answer tells you more than the case studies.

Can a Fractional Person Honestly Be Your Named CISO

This comes up in vendor security reviews and it deserves a straight answer. Most enterprise questionnaires ask whether there is an individual accountable for information security and who they are. Naming a fractional executive is legitimate and common, provided two things are true: the arrangement is documented with a defined scope of authority, and the person is genuinely reachable by that customer's security team. What is not legitimate is naming someone who has never seen your architecture, or implying a full-time employment relationship that does not exist. If a questionnaire asks specifically for a full-time employee in the role, say so and describe the arrangement you actually have. In our experience buyers accept a well-documented fractional arrangement far more often than founders expect, and they react badly to discovering an overstatement later. The same honesty rule applies to residency and clearance questions on defence-adjacent work, where getting it wrong is not merely embarrassing.

The First Ninety Days, and How to Tell It Is Working

A good opening quarter is boringly concrete. Weeks one to three: an architecture and data-flow walkthrough with engineering, an access inventory covering the identity provider, cloud accounts, code repositories and production databases, and a read of every security commitment already made in signed customer contracts, because founders routinely sign obligations nobody tracked. Weeks four to eight: a written risk position with owners and dates, the policy set that matches how the company actually works rather than a template, and the first questionnaire answered from a maintained source rather than improvised. Weeks nine to twelve: a tested incident response plan including who declares an incident, the first access review completed on evidence, and a board-ready summary. The measures that tell you it is working are not maturity scores. They are the time it takes to return a completed questionnaire, the number of open commitments in customer contracts you cannot evidence, the age of your oldest unremediated critical finding, and whether the security answer in your last deal was given by the founder or by someone else. Somewhere to keep those artifacts matters more than it sounds, which is why we give clients the traztech Workspace at no cost.

Waterloo-Specific: Use the Talent Pipeline for Implementation

The region's co-op programme is an underused asset in this exact context. The leadership layer is what you cannot hire cheaply, but a good deal of the implementation work under it is well suited to a strong co-op student with supervision: building the asset inventory, wiring log shipping into a central store, cleaning up the vendor list, gathering evidence on a schedule, running the tooling that produces access review data. A fractional CISO who refuses to work that way and insists on billing their own rate for inventory building is not acting in your interest. The pattern that works is the executive owning decisions and quality, a co-op or junior engineer owning execution, and a monthly review where the work gets checked. It also builds internal capability, which is what you want if the plan is eventually to hire the role in.

Planning the Handover to a Full-Time Hire

The end state for most companies past Series B is an employed security leader, and a fractional engagement should be built to make that transition easy rather than to prevent it. That means the risk register, policy set, evidence and vendor records live in your systems, the customer relationships are introduced rather than owned, and the roadmap is written so an incoming hire can read the last four quarters of decisions and understand why. A useful signal that it is time: when the security work generates enough weekly decisions that your fractional executive is consistently at the top of their days, or when a regulated customer contract requires an employee in the role. A decent provider will tell you when that point has arrived and will help you write the job description and sit on the interview panel. That is also the moment to keep something smaller in place, because a new CISO in their first ninety days benefits from a second opinion, which is the shape a lot of our ongoing retainers take.

When a Virtual CISO Is the Wrong Purchase

There are several situations where we will tell you not to buy this. If you are pre-product-market-fit with no customers asking security questions, a vCISO is premature and the correct spend is turning on MFA, enforcing least privilege on your cloud accounts, and writing down how you handle secrets. If a single named audit is the whole problem, buy the audit readiness work as a fixed-scope piece rather than an open-ended leadership retainer, since a defined compliance engagement with a start and an end will cost less and finish sooner. If what you actually lack is someone to do the work, you need a security engineer, and hiring a strategist to supervise nobody produces documents nobody implements. If your problem is one specific technical question, such as whether your architecture holds up under attack, a penetration test starting at $1,000 answers it better than a monthly retainer would. And if your board asked for a CISO purely as a governance box, say that plainly to your board first, because the honest fix might be a quarterly security report from your CTO rather than an outside executive. We would rather scope you into the smaller piece of work and be there when the bigger one is genuinely warranted, and if you are unsure which of these you are, that is a fifteen-minute conversation through our contact page rather than a proposal.

Need a named security owner? A fractional CISO owns the program, answers the questionnaires and sits in the buyer security calls, without the full-time hire.

Fractional CISOOr talk about a retainer

Before you go

Want the rest of this by email?

If this was useful, I send a few short notes on security posture. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.

Want a second opinion on where you stand?

We run SOC 2, ISO 27001 and the rest of the compliance stack for startups and SMEs, and the security testing that sits behind it. The first call is free, and we will tell you if you are not ready to start yet.

Book a free call

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.