Security

Real offensive depth

Testing and defence led by a published security researcher with five CVEs, including a CVSS 9.1 Mirai botnet kill-switch.

All security →
Compliance

Audit-ready, fixed scope

SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.

All frameworks →
Resources

Learn the space

Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.

Read the blog →
Fractional Leadership

Fractional CISO

Board-ready security leadership without the $300K salary. Strategy, risk management, and compliance oversight on your terms.

What you get on the call. Someone with five published CVEs who has also run a SOC 2 Type II end to end in-house, 76 controls and zero exceptions: the case study.
Get started
From $3,000 CAD · per month · month to month, no lock-in See full pricing →

A real security program, not a checkbox

Your fractional CISO builds and runs your security program as if they were full-time.

01

Security strategy and roadmap

A 12-month security plan aligned to your business goals, funding stage, and regulatory environment. Prioritized by actual risk, not vendor FUD.

02

Board and investor reporting

Monthly security posture reports, risk registers, and executive briefings. When your board asks about security, you have a clear, honest answer ready.

03

Vendor and third-party risk

Security reviews of every SaaS vendor, contractor, and integration partner. We assess their controls so a breach in their environment does not become a breach in yours.

04

Policy and compliance management

Acceptable use, data classification, incident response, access control. We write the policies, train your team, and keep everything current for SOC 2, HIPAA, or ISO 27001.

A fractional CISO often runs alongside a broader SOC 2 readiness engagement, auditor management and advocacy once the audit starts, and CPCSC readiness for teams selling into defence supply chains. See pricing for how these bundle.

70%
Cost savings vs. full-time CISO
20+
Years avg CISO experience
100%
Compliance audit pass rate

How we work

Security leadership from day one.

01

Baseline assessment

We audit your current security posture, identify the critical gaps, and produce a risk-ranked remediation plan within the first two weeks.

02

Build the program

Policies, tooling, training, and incident response procedures. We implement the security program piece by piece, starting with whatever unblocks your next enterprise deal.

03

Ongoing governance

Monthly risk reviews, quarterly board reports, annual policy updates, and continuous compliance monitoring. Your CISO stays engaged as long as you need them.

Works well with

Fixed-scope security leadership offers

Get security leadership now

Tell us about your security needs and we will match you with the right CISO.

Book a Call

Frequently asked questions

What does a fractional CISO actually do?

A fractional CISO owns your security program part-time: risk decisions, policy, vendor and customer security reviews, compliance roadmaps, and incident oversight. You get executive-level security leadership without a full-time hire. It suits companies that need a security owner but do not yet have the headcount or budget for a salaried CISO.

How is this different from your SOC 2 service?

SOC 2 readiness is a defined project with a finish line. A fractional CISO is ongoing leadership that governs the program after the audit and across frameworks. Many clients start with SOC 2 readiness, then keep us on as fractional CISO to maintain controls, handle questionnaires, and steer the roadmap.

How many hours per month do I get?

Engagements are scoped to your needs rather than sold as fixed hour blocks. Some clients need a few hours a week for governance and questionnaire support, others need heavier involvement during an audit or a deal cycle. We set scope up front and adjust as your requirements change.

Can you sign security questionnaires and represent us to customers?

Yes. Answering enterprise security questionnaires, joining customer security calls, and representing your security posture to prospects is a core part of the role. This is often what unblocks stalled enterprise deals.

What credentials back the role?

Our founder is a published security researcher (5 CVEs, including a CVSS 9.1 finding) who has taken a product through SOC 2 Type II covering 76 controls. You get someone who has actually built and operated a compliant security program, not just advised on one.

Track record

Who is actually doing the work

We are deliberately not a large firm, and we would rather show you the work than a wall of logos. Here is what is behind the advice.

5
Published CVEs, including a CVSS 9.1
76
Controls taken from nothing to a passed SOC 2 Type II
Zero
Exceptions on that Type II report
75 days
Readiness window we have hit every time we have run it
20+
Penetration testing engagements delivered

Published vulnerability research

Five published CVEs. CVE-2024-45163 (CVSS 9.1) is a flaw in the Mirai botnet itself, which gave defenders a way to shut down attacker infrastructure. CVE-2026-42626 takes HP ENVY 5000 printers offline from any unauthenticated device on the same network.

The printer is the one that matters on a compliance page: an asset nobody counts as a computer, on a flat network, downed by a device that never had to log in. Auditors ask how controls fail. We have found out first-hand.

A SOC 2 Type II built from nothing

At Humera, a venture-backed US security company, Jacob built the compliance programme in-house from nothing: no report, no policies, no documented controls. It ended in a Type II attestation across 76 controls with zero exceptions, on a team of 15.

The platform held 99.9% uptime throughout, which is the part most readiness projects get wrong: controls are easy to design and hard to retrofit onto a system people already depend on.

Recent engagements

For a Waterloo data centre operator we ran SOC 2 Type II and ISO 27001:2022 together rather than one after the other, across a production campus, an AI compute platform and a self-hosted collaboration stack. Scoped so further Ontario and Quebec sites enter as they reach production. Findings delivered and remediated.

For an Ontario medtech company putting an AI clinical assistant in front of practitioners, we ran the gap analysis and built the evidence programme behind their SOC 2.

Before you go

Want a few notes on this by email?

Short, practical notes on Fractional CISO. Unsubscribe in one click, and replies reach me directly.

From Jacob Masse, founder of traztech. No spam, unsubscribe in one click.

Want it done for you?

Fractional CISO

Explore Fractional CISO →