Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Security & Compliance Glossary

vCISO (Fractional CISO)

A vCISO, or virtual or fractional Chief Information Security Officer, is an experienced security executive who runs your security program on a part-time or contract basis instead of as a full-time hire. The vCISO owns policies, controls, risk decisions, audits, and board reporting. It gives a company executive security leadership without a six-figure salary.

In practice

A vCISO is the named person on customer security questionnaires, in regulator correspondence, and in the board deck. That accountability is often the actual deliverable buyers and auditors care about.

The model fits companies that have outgrown ad hoc security but cannot justify a full-time CISO yet. The vCISO sets the program direction and cadence, then hands day-to-day execution to internal staff or specialist partners.

// how traztech helps

traztech delivers fractional CISO leadership for startups and growth-stage companies, led by a published security researcher.

Book a call

For a broader look at getting audit-ready, see our SOC 2 readiness work, or talk to a fractional CISO about building a program around it.

Where it comes up

A vCISO usually enters at one of three moments: an enterprise deal has stalled on security questions, an investor has asked who owns security, or an incident has made the absence of an owner obvious.

The work in the first ninety days is rarely technical. It is establishing what you actually have, deciding what the next two quarters should cover, and putting a name against every control so that things run on a schedule rather than when somebody remembers.

vCISO (Fractional CISO): common questions

How is a vCISO different from a security consultant?

A consultant delivers a piece of work and leaves. A vCISO holds the role: they are accountable for the programme, attend the buyer calls, own the roadmap and answer for it over time.

How many days a month does a vCISO need?

For most companies below a hundred people, a few days a month is enough to hold the programme together, with more during an audit or after an incident.

Track record

Who is actually doing the work

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

Before you go

Want the practical version by email?

Definitions only get you so far. I send a few short notes on how this plays out in practice. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, principal of traztech. No spam, unsubscribe in one click.