Fractional CISO leadership — without the $250,000 salary
A fixed 90-day engagement that gives your organisation genuine executive security leadership — strategy, policy, and audit-readiness — delivered by a named senior practitioner, not handed off to a junior bench.
I'll reply personally within 4 business hours — no sales pitch, just a clear read on your options.
Former NSW Government Chief Risk Officer and vCISO. ISO 27001 Lead Auditor & Implementer. Federal Government Baseline Security Clearance.
You need a CISO. You don't need a $250K hire.
A full-time CISO in Australia typically costs $250,000–$400,000+ before recruitment and on-costs — hard to justify unless you're already at real scale. But a board that's asked "who owns our cyber risk?" and gets no clear answer has a genuine governance gap. A fractional CISO closes that gap at a fraction of the cost, without diluting seniority or accountability.
What happens in your 90-day sprint
Assessment
A structured review of your current security posture, controls, policies, and risk landscape against ISO 27001, NIST CSF, and the ASD's incoming Essentials framework.Strategy & roadmap
A prioritised security strategy and roadmap, written for your board and executive team — not a 100-page technical document nobody reads.Policy framework build
Core governance and security policies drafted or updated, mapped to your chosen standard.Audit-readiness & handover
A clear picture of where you stand, what's left to do, and a board-ready summary presentation.Who actually does the work matters more than the invoice
With Secure Konnect, you work directly with Dr Edward Phelps — former Chief Risk Officer for a 26-division NSW Government department, with 15+ years advising boards, Ministers, and executive teams. One accountable person your board can call.
Who actually does the work matters more than the invoice
vCISO, virtual CISO, independent cyber advisor — what's actually different
Searching for part-time security leadership turns up a lot of overlapping terms — vCISO, virtual CISO, fractional CISO, independent cyber advisor, CISO advisory — and in practice, most of them describe the same underlying idea: senior security leadership engaged part-time or project-based, rather than hired full-time. What genuinely differs between providers isn't the label, it's how the engagement is actually structured and who's behind it.
A few things worth knowing before you compare options:
- Some "vCISO" services are really CISO advisory in name only — a monthly call and a document template, with no real accountability if a board or auditor asks hard questions.
- A genuine virtual CISO engagement should include named, senior ownership — not a rotating analyst, and not a generic playbook copied across every client regardless of sector.
- An independent cyber advisor should have no product or vendor incentive — recommendations should be about what your organisation actually needs, not what a parent MSSP is trying to upsell.
The 90-day sprint above is structured deliberately around those distinctions: fixed scope, senior and named delivery, and independence from any technology or managed-services sale — genuine CISO advisory, not a subscription with a security-sounding name attached to it.
Common questions
Is 90 days really enough to matter?
It's enough to give you a genuine strategy, a policy framework, and a clear audit-readiness picture — the foundational work most organisations have been putting off.What happens after the 90 days?
You keep everything produced. Many clients move to an ongoing monthly retainer to execute the roadmap; others take it in-house or to another provider.Do you cover ISO 27001 and Essential Eight/ASD Essentials?
Yes — framework-agnostic by design, covering ISO 27001, NIST CSF, and mapping your work forward through the Essential Eight to ASD Essentials transition.How is this different from a pen-testing firm or MSSP?
We don't sell security products or technical delivery — this is governance and leadership. We can help you scope and manage a provider for those services if needed.Get executive security leadership, without the executive price tag
Start your 90-day sprint
Three quick fields — I'll come back to you personally within 4 business hours.
No sales pitch. Just a clear read on your options.