Service · Cybersecurity Leadership

Fractional CISO / vCISO — senior leadership, calibrated time.

For scale-ups and SaaS B2B that don't need a full-time CISO but can no longer move forward without structured cybersecurity leadership. From 2 days per month up to half-time. Run directly by the founder.

Book a 20-min scope call

When does a fractional CISO make sense?

Three typical situations:

1. You are a 30-150-person scale-up that needs to demonstrate cybersecurity maturity to enterprise clients, investors, or insurers — without the workload justifying a full-time CISO (total loaded cost: €120-180K/year).

2. You are starting an ISO 27001 or SOC 2 Type II certification and need a senior pilot to structure the ISMS, run the steering committee, prepare for audit, and hold the roadmap.

3. You are a SaaS subject to NIS2 (50+ employees, strategic sector) and need a recognized referent to achieve compliance before October 2026 and respond to incidents.

What the fractional CISO actually does

Typical scope of a WeeSec fractional CISO engagement:

  • Strategy and governance: annual risk analysis, security policy, quarterly steering committee, executive/board reporting.
  • Compliance and certifications: ISO 27001 / SOC 2 / NIS2 / GDPR / DORA / EU AI Act steering depending on your context. Audit preparation and presence.
  • Product security and DevSecOps: architecture review, security integration in SDLC, threat modeling on new features, code audit supervision.
  • Incident management: runbooks, crisis exercises (tabletop exercises), real incident response — on-call availability if needed.
  • Vendor management: tool selection (EDR, SIEM, GRC, scanner), security contract negotiation, SLA tracking, external pentest supervision.
  • Client representation: responses to prospect security DDQ and questionnaires, support for client due diligence, presence in client meetings if necessary.
  • Awareness: simulated phishing campaigns, team training, security onboarding for new hires.

Format and cadence

Discovery package (2 days/month — €4K/month): for an early-stage scale-up, focus on roadmap and 1-2 critical projects. Monthly committee + traceability.

Standard package (4 days/month — €7K/month): the most common. Roadmap steering, quarterly steering committee, project tracking, product support, non-critical incident management.

Certification package (6 to 8 days/month — €10-13K/month): for the active phase of ISO 27001 or SOC 2 Type II certification. Documentation, internal audit, certifier audit preparation and presence.

Extended package (10+ days/month): half-time equivalent. For organizations with multiple challenges (multi-entity, regulated sectors). On quote.

All packages include: direct on-call hotline, unlimited email support, full traceability (Notion or shared tool), monthly reviews.

Comparison with an in-house CISO

CriterionIn-house CISOWeeSec fractional CISO
Annual loaded cost€120-180K€48-120K
Time to deployment4-9 months (recruiting + onboarding)2 weeks
Seniority levelVariable (often less experienced in AI security)15+ years grand-comptes experience
Vendor independenceVariableTotal — no partnerships
Multi-frameworkOften single-frameworkISO 27001, ISO 42001, SOC 2, NIS2, DORA, EU AI Act, CRA
Vacancy / leaveRisk of grey zoneContractual, backup planned

The fractional CISO is not a stopgap. It is the most cost-effective and operational option as long as the organization doesn't have CISO-justifying volume (typically >150 people or heavily regulated sector).

What you get after 6 months

After 6 months of typical fractional CISO support:

  • Operational ISMS: security policy, risk management, incident management, access management — all documented and applied.
  • Tracked compliance: NIS2 achieved, or ISO 27001 stage 2 ready, or SOC 2 Type II under observation.
  • Client-ready documentation: standardized DDQ responses, public security factsheet, auditable traceability.
  • Indicators in place: monthly security dashboard (open vulnerabilities, MFA coverage, training, incidents).
  • Trained team: developers aware, sysadmins equipped, executives up to date on obligations.

Direct scoping, no commitment.

A 20-minute scope call to qualify your need and provide a firm quote.

Book on Calendly
FAQ

Frequently asked questions.

What is the cost of a fractional CISO in Europe?

For a European scale-up or SMB, expect €4-13K/month depending on package: 2 days/month (€4K), 4 days/month (€7K), certification package 6-8 days/month (€10-13K). Compared to a full-time in-house CISO (€120-180K/year loaded), outsourcing saves 40-60% depending on cadence.

What seniority does the WeeSec fractional CISO have?

Founder Aroua Biri runs all engagements directly: doctorate in cybersecurity (Télécom SudParis), MIT Applied AI certified, 15+ years of experience as CISO or security expert with BNP Paribas, Société Générale, Thales, AXA, EDF, L'Oréal, Allianz. No junior intermediary.

From what size do you need a fractional CISO?

From 30-50 people, as soon as an enterprise client asks for a security framework or a certification is at stake. For organizations under 30 people, an ad-hoc audit + on-demand support is generally more economical. For organizations over 150-200 people or in regulated sectors, an in-house CISO becomes relevant.

How does the transition to an in-house CISO happen as the org grows?

WeeSec actively prepares the transition: documentation transmitted, operational ISMS, up-to-date runbooks. Once the in-house CISO is recruited, WeeSec provides 1 to 3 months of transition to transfer institutional memory. The in-house CISO arrives on structured ground and can produce from month 1 — instead of spending 4 to 8 months on mapping.

Is the fractional CISO reachable in case of incident?

Yes. All packages include a direct on-call hotline during business hours + weekend/holiday extension on request. In case of significant incident, WeeSec coordinates response, communication with authorities (CNIL, ANSSI, CERT-FR) if needed, and post-incident retrospective.

Can the fractional CISO sign engagements for my company?

No, by principle. The fractional CISO advises, operates, animates — but legal engagements (regulatory notifications, contractual signatures) remain those of your company's executives. WeeSec prepares documents and secures them technically; you sign them. This is also a NIS2 directive requirement on management body responsibility.