top of page

CASE STUDY · FRACTIONAL CISO ENGAGEMENT

No in-house security leadership. A board that needed one anyway.

An ICA Consultancy Fractional CISO was brought in to a mid-sized organisation with no security leadership in place, no board-level view of cyber risk, and a three-year runway to build both. This is that trajectory, phase by phase.

15

risks formally scored across the estate

3

phases developing maturity over time

0

Major risks left by end of year two, down from 2 

11

of 15 risks holding at Low by year three

A board that knew it had a gap, and no way to close it

Most organisations that bring in a fractional CISO already know they are exposed.

What they do not yet have is a way to talk about that exposure in a language the board can act on — a scored, benchmarked, prioritised view rather than a list of technical concerns. That was the starting position here: no in-house security leadership, no formal maturity baseline, and a board that needed assurance it could not yet get.

“We knew we had gaps. What we didn't have was a way to show the board which ones mattered most, or a plan they could hold us to.”

CIO

The baseline

Before any strategy was written, the estate was benchmarked against NIST CSF — not a technical audit, a scored maturity position across governance, risk, culture and technical domains.

 

The baseline put two risks in the Major band and eight at Moderate, with nothing at the Unacceptable tier. That shape matters: the conversation with the board could start from “here is what to prioritise, and in what order”, not “here is an emergency”. What the baseline surfaced was a governance gap rather than a technical one — familiar territory for an organisation without a named security leader, and the reason the first phase buys no risk reduction at all.

Three Phases

Year 1

Establish

Governance stood up: board reporting introduced, ownership assigned, the risk register scored and reviewed on a cadence for the first time. Risk positions barely moved, phase one builds the mechanism, it does not close the gaps.

Year 2

Consolidate & Detect

Detection and response capability built out alongside the governance foundation from phase one. Major risks cleared entirely; the remaining work concentrated in the Moderate band.

Year 3

Optimise & Lead

The organisation moved from reacting to a baseline to maintaining and improving one. Every movement on the register across the three years was downward.

What changed

Board-level reporting became a fixed cadence rather than an ad hoc response to a question. The risk register moved from static and undocumented to scored, tracked, and visibly trending downward over three years. By year three the organisation could show a board, an investor or an auditor not just a maturity position, but a documented history of that position improving on schedule.

How an ICA Consultancy Fractional CISO engagement runs

Four things, in order, from first week to board pack.

What a Fractional CISO is, and what it is not

A Fractional CISO gives strategic security leadership and board-level accountability without a full-time hire. It is not a technical implementation team, and not a substitute for the analysts, engineers and specialist partners who do the underlying work. It changes how risk is governed and communicated. It does not replace the people who fix the risk itself.

Considering how a Fractional CISO would work for your organisation?

ICA Consultancy provides Fractional CISO services to organisations that need board-level security leadership without a full-time hire.

bottom of page