CASE STUDY · FRACTIONAL CISO ENGAGEMENT
No in-house security leadership. A board that needed one anyway.
An ICA Consultancy Fractional CISO was brought in to a mid-sized organisation with no security leadership in place, no board-level view of cyber risk, and a three-year runway to build both. This is that trajectory, phase by phase.
15
risks formally scored across the estate
3
phases developing maturity over time
0
Major risks left by end of year two, down from 2
11
of 15 risks holding at Low by year three
A board that knew it had a gap, and no way to close it
Most organisations that bring in a fractional CISO already know they are exposed.
What they do not yet have is a way to talk about that exposure in a language the board can act on — a scored, benchmarked, prioritised view rather than a list of technical concerns. That was the starting position here: no in-house security leadership, no formal maturity baseline, and a board that needed assurance it could not yet get.
“We knew we had gaps. What we didn't have was a way to show the board which ones mattered most, or a plan they could hold us to.”
CIO
The baseline
Before any strategy was written, the estate was benchmarked against NIST CSF — not a technical audit, a scored maturity position across governance, risk, culture and technical domains.
The baseline put two risks in the Major band and eight at Moderate, with nothing at the Unacceptable tier. That shape matters: the conversation with the board could start from “here is what to prioritise, and in what order”, not “here is an emergency”. What the baseline surfaced was a governance gap rather than a technical one — familiar territory for an organisation without a named security leader, and the reason the first phase buys no risk reduction at all.
Three Phases
Year 1
Establish
Governance stood up: board reporting introduced, ownership assigned, the risk register scored and reviewed on a cadence for the first time. Risk positions barely moved, phase one builds the mechanism, it does not close the gaps.
Year 2
Consolidate & Detect
Detection and response capability built out alongside the governance foundation from phase one. Major risks cleared entirely; the remaining work concentrated in the Moderate band.
Year 3
Optimise & Lead
The organisation moved from reacting to a baseline to maintaining and improving one. Every movement on the register across the three years was downward.
What changed
Board-level reporting became a fixed cadence rather than an ad hoc response to a question. The risk register moved from static and undocumented to scored, tracked, and visibly trending downward over three years. By year three the organisation could show a board, an investor or an auditor not just a maturity position, but a documented history of that position improving on schedule.
How an ICA Consultancy Fractional CISO engagement runs
Four things, in order, from first week to board pack.
What a Fractional CISO is, and what it is not
A Fractional CISO gives strategic security leadership and board-level accountability without a full-time hire. It is not a technical implementation team, and not a substitute for the analysts, engineers and specialist partners who do the underlying work. It changes how risk is governed and communicated. It does not replace the people who fix the risk itself.
