Call us

Fractional CISO leadership — without the $250,000 salary

A fixed 90-day engagement that gives your organisation genuine executive security leadership — strategy, policy, and audit-readiness — delivered by a named senior practitioner, not handed off to a junior bench.

I'll reply personally within 4 business hours — no sales pitch, just a clear read on your options.

Former NSW Government Chief Risk Officer and vCISO. ISO 27001 Lead Auditor & Implementer. Federal Government Baseline Security Clearance.

SEC. 01 — THE PROBLEM

You need a CISO. You don't need a $250K hire.

A full-time CISO in Australia typically costs $250,000–$400,000+ before recruitment and on-costs — hard to justify unless you're already at real scale. But a board that's asked "who owns our cyber risk?" and gets no clear answer has a genuine governance gap. A fractional CISO closes that gap at a fraction of the cost, without diluting seniority or accountability.

SEC. 02 — THE PROGRAM

What happens in your 90-day sprint

WEEKS 1–2

Assessment

A structured review of your current security posture, controls, policies, and risk landscape against ISO 27001, NIST CSF, and the ASD's incoming Essentials framework.
WEEKS 3–4

Strategy & roadmap

A prioritised security strategy and roadmap, written for your board and executive team — not a 100-page technical document nobody reads.
WEEKS 5–10

Policy framework build

Core governance and security policies drafted or updated, mapped to your chosen standard.
WEEKS 11–12

Audit-readiness & handover

A clear picture of where you stand, what's left to do, and a board-ready summary presentation.
At the end of 90 days, you own the strategy, the policy set, and the roadmap outright. If you want ongoing fractional leadership, we move to a standard monthly retainer — no obligation, no penalty either way.
SEC. 03 — WHY IT MATTERS

Who actually does the work matters more than the invoice

Many larger providers price a vCISO engagement attractively, then deliver it through a rotating junior bench. A retainer delivered by a genuinely senior practitioner is worth materially more than one quietly delegated down.

With Secure Konnect, you work directly with Dr Edward Phelps — former Chief Risk Officer for a 26-division NSW Government department, with 15+ years advising boards, Ministers, and executive teams. One accountable person your board can call.

SEC. 03 — WHY IT MATTERS

Who actually does the work matters more than the invoice

Many larger providers price a vCISO engagement attractively, then deliver it through a rotating junior bench. A retainer delivered by a genuinely senior practitioner is worth materially more than one quietly delegated down.With Secure Konnect, you work directly with Dr Edward Phelps — former Chief Risk Officer for a 26-division NSW Government department, with 15+ years advising boards, Ministers, and executive teams. One accountable person your board can call.

vCISO, virtual CISO, independent cyber advisor — what's actually different

Searching for part-time security leadership turns up a lot of overlapping terms — vCISO, virtual CISO, fractional CISO, independent cyber advisor, CISO advisory — and in practice, most of them describe the same underlying idea: senior security leadership engaged part-time or project-based, rather than hired full-time. What genuinely differs between providers isn't the label, it's how the engagement is actually structured and who's behind it.

A few things worth knowing before you compare options:

  • Some "vCISO" services are really CISO advisory in name only — a monthly call and a document template, with no real accountability if a board or auditor asks hard questions.
  • A genuine virtual CISO engagement should include named, senior ownership — not a rotating analyst, and not a generic playbook copied across every client regardless of sector.
  • An independent cyber advisor should have no product or vendor incentive — recommendations should be about what your organisation actually needs, not what a parent MSSP is trying to upsell.

The 90-day sprint above is structured deliberately around those distinctions: fixed scope, senior and named delivery, and independence from any technology or managed-services sale — genuine CISO advisory, not a subscription with a security-sounding name attached to it.

SEC. 04 — COMMON QUESTIONS

Common questions

Is 90 days really enough to matter?

It's enough to give you a genuine strategy, a policy framework, and a clear audit-readiness picture — the foundational work most organisations have been putting off.

What happens after the 90 days?

You keep everything produced. Many clients move to an ongoing monthly retainer to execute the roadmap; others take it in-house or to another provider.

Do you cover ISO 27001 and Essential Eight/ASD Essentials?

Yes — framework-agnostic by design, covering ISO 27001, NIST CSF, and mapping your work forward through the Essential Eight to ASD Essentials transition.

How is this different from a pen-testing firm or MSSP?

We don't sell security products or technical delivery — this is governance and leadership. We can help you scope and manage a provider for those services if needed.

Get executive security leadership, without the executive price tag

Start your 90-day sprint

Three quick fields — I'll come back to you personally within 4 business hours.

No sales pitch. Just a clear read on your options.

Prefer to talk now? Call us
Secure Konnect · ABN 226990594329 · Cairns, QLD · privacy policy