Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Board-ready security leadership without the $300K salary. Strategy, risk management, and compliance oversight on your terms.
Your fractional CISO builds and runs your security program as if they were full-time.
A 12-month security plan aligned to your business goals, funding stage, and regulatory environment. Prioritized by actual risk, not vendor FUD.
Monthly security posture reports, risk registers, and executive briefings. When your board asks about security, you have a clear, honest answer ready.
Security reviews of every SaaS vendor, contractor, and integration partner. We assess their controls so a breach in their environment does not become a breach in yours.
Acceptable use, data classification, incident response, access control. We write the policies, train your team, and keep everything current for SOC 2, HIPAA, or ISO 27001.
A fractional CISO often runs alongside a broader SOC 2 readiness engagement, auditor management and advocacy once the audit starts, and CPCSC readiness for teams selling into defence supply chains. See pricing for how these bundle.
Security leadership from day one.
We audit your current security posture, identify the critical gaps, and produce a risk-ranked remediation plan within the first two weeks.
Policies, tooling, training, and incident response procedures. We implement the security program piece by piece, starting with whatever unblocks your next enterprise deal.
Monthly risk reviews, quarterly board reports, annual policy updates, and continuous compliance monitoring. Your CISO stays engaged as long as you need them.
Tell us about your security needs and we will match you with the right CISO.
Book a CallA fractional CISO owns your security program part-time: risk decisions, policy, vendor and customer security reviews, compliance roadmaps, and incident oversight. You get executive-level security leadership without a full-time hire. It suits companies that need a security owner but do not yet have the headcount or budget for a salaried CISO.
SOC 2 readiness is a defined project with a finish line. A fractional CISO is ongoing leadership that governs the program after the audit and across frameworks. Many clients start with SOC 2 readiness, then keep us on as fractional CISO to maintain controls, handle questionnaires, and steer the roadmap.
Engagements are scoped to your needs rather than sold as fixed hour blocks. Some clients need a few hours a week for governance and questionnaire support, others need heavier involvement during an audit or a deal cycle. We set scope up front and adjust as your requirements change.
Yes. Answering enterprise security questionnaires, joining customer security calls, and representing your security posture to prospects is a core part of the role. This is often what unblocks stalled enterprise deals.
Our founder is a published security researcher (5 CVEs, including a CVSS 9.1 finding) who has taken a product through SOC 2 Type II covering 76 controls. You get someone who has actually built and operated a compliant security program, not just advised on one.
Track record
We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.
Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.
The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.
At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.
The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.
For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.
For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.
Before you go
Short, practical notes on Fractional CISO. Unsubscribe in one click, and replies reach me directly.
From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.