Cyber strategy and a 12-month roadmap
Where the security money goes and why, ranked by the risks that would actually hurt you, not by what a vendor wants to sell.
A fractional CISO is an experienced Chief Information Security Officer who works with your business part time while carrying full ownership of cyber strategy, risk and compliance. Some providers call it a vCISO or virtual CISO. Same role. You get a named security leader your board, regulator, insurer and biggest client can point to, for a fraction of the cost of hiring one.
The difference worth paying attention to is not the name. It is whether the CISO only writes the plan, or also has the engineers to carry it out. Ours does both. The rest of this page covers what that looks like, what it costs and how to tell whether you need one.
The honest trigger: hire a fractional CISO when security has become a board question and nobody at board level owns the answer. Not the IT manager, not the MSP, not the FD who ended up with it.
For a UK business with 50–1,000 staff that usually looks like:
A regulator, insurer or enterprise client has asked who your CISO is and the honest answer is "nobody"
Security questionnaires land on the FD's desk and take a week of guesswork to answer
Cyber insurance renewal wants MFA everywhere, tested backups and an incident plan you don't have
Your MSP says you're secure. Nobody senior has checked what that actually means
A tender or client contract now requires Cyber Essentials Plus or ISO 27001
You've had the near-miss: the phishing click, the invoice fraud attempt, the laptop left on a train
If two or more of those land, you don't need another security tool. You need someone whose job is to own the risk and be accountable for it.
Direct answer first: a security strategy the board understands, a risk register someone owns and a named person your regulator and insurer can hold to account.
Month by month it looks like this:
Where the security money goes and why, ranked by the risks that would actually hurt you, not by what a vendor wants to sell.
Owned, reviewed and reported. The document your insurer, auditor and regulator will ask for first.
The CISO holds the programme, we deliver it. Gap assessment, remediation, auditor liaison, certificate.
SM&CR cyber lead where you're FCA-regulated. The person who answers the questionnaire and signs the evidence.
A plan that exists, a tabletop exercise that tests it and a named person who runs containment when it happens.
A quarterly security report the board can challenge. Risk, spend, progress, no acronyms without translation.
A roadmap nobody implements is a liability with a date on it. Your fractional CISO sets the direction and holds the risk. Behind them sits the AssurePath engineering bench that runs cyber operations for clients every day. One firm, both halves, no handover between the person who decided and the people who do.
Already have an MSP you like? Keep them. The CISO sets the standard and holds them to it. Nothing on this page requires you to move your IT to us.
Most of the market bills vCISO time by the hour or the day, which quietly punishes you for asking questions. We price the role instead: one monthly figure, agreed with you before anything starts.
Delivery work is separate and quoted separately. Tabletop exercises start at £550 + VAT, Cyber Essentials Plus and ISO 27001 programmes are priced on our compliance page, and managed security runs per user per month on the cyber operations page. The CISO fee never hides a delivery bill inside it.
Part time and ongoing. Owns the risk register, the roadmap and the regulator conversation, and has engineers to carry out the plan. Our model.
Same title, narrower job. Most vCISO services advise by the hour and hand you a list. Fine if you have a team to execute it. Most 50–1,000 person firms don't.
Right when security is a full-time job. Below about 1,000 staff it rarely is, and a good one takes months and a recruiter fee to find.
Not sure you need a CISO at all? That's what the free call is for. If the honest answer is "a Cyber Essentials Plus programme and a DPO from £950/month", we'll say so and quote that instead.
Book a free strategy callOur CISOs have held the named role for FCA-regulated firms and led ISO 27001 programmes from zero to certificate. We specialise in UK professional services with 50–1,000 users:
Client data, AML evidence, practice systems (IRIS, CCH, Sage, Xero) and the questionnaires your larger clients now send.
Client confidentiality, SRA expectations, iManage and NetDocuments estates, on-prem AI sign-off, ISO 27001 for panel work.
Candidate data at volume, GDPR posture, Bullhorn and Vincere access control, invoice fraud that targets agencies specifically.
One CISO framework across the portfolio: risk register per portco, group rollup for the fund, exit-ready evidence packs.
FCA-regulated? The CISO acts as your named cyber lead under SM&CR, supports Consumer Duty submissions and is the audit point of contact. That is the job, not an add-on.
Your CISO has built and run security programmes, not just audited them. CISSP and CISM on the bench, ISO 27001 lead auditor experience, named CISO on FCA permissions.
Most UK vCISO providers won't put a number on the page. Ours starts at £1,350 a month, and we'll tell you on the first call where your scope actually lands.
Security hires are scarce and slow. Executive search takes months and a fat fee. We don't.
Including security tools. Often the first finding is a licence you already pay for that nobody switched on. Sometimes the answer is a DPO or a compliance programme, not a CISO, and we'll say so.
Term is agreed with you, not imposed on you. The risk register, policies and evidence pack are yours and stay with you either way.
The questions we get asked most about the fractional CISO role. We answer them again, properly, on the call.
A fractional CISO is a senior Chief Information Security Officer who works with your business part time while owning cyber strategy, the risk register, compliance and the conversation with your regulator, insurer and clients. You get a named, accountable security leader without the six-figure salary a permanent CISO costs.
Mostly the name. vCISO (virtual CISO) is the same part-time role, usually delivered remotely and billed by the hour. The difference that matters is scope: most vCISO services advise and hand you a list. An AssurePath fractional CISO owns the plan and has engineers to deliver it, so the risk register turns into closed risks rather than a longer document.
Most of the UK market bills vCISO time by the hour or day, so the cost moves with how much you ask. AssurePath prices the role instead: from £1,350 a month, with the actual figure agreed with you before anything is signed. Regulated firms and ISO 27001 programmes usually sit above the starting point because the role needs more of the month. Delivery work such as tabletop exercises, Cyber Essentials Plus or managed security is quoted separately and never hidden inside the CISO fee.
It depends on the sector, the regulator and what is in flight. The work concentrates on a weekly slot with leadership, risk reviews, vendor and MSP oversight, questionnaires and board reporting rather than hands-on configuration, which the engineers handle. We agree the cover on the first call and re-scope it each quarter. If you genuinely need close to full-time attention, we'll tell you to hire.
Yes. The fractional CISO service is built for FCA-regulated firms, IFAs, wealth managers and EMIs. We provide named CISO cover under SM&CR, act as the cyber lead on Consumer Duty submissions, hold Cyber Essentials Plus oversight, support ISO 27001 certification and maintain audit-ready evidence trails. The CISO is your audit point of contact.
Both, which is the point. The CISO sets the strategy, owns the risk register and makes the calls. The AssurePath engineering bench then delivers: identity and MFA, EDR rollout, vulnerability management, backup drills and incident containment. If you'd rather your existing MSP does the hands-on work, the CISO sets the standard and holds them to it.
Yes. The CISO owns the programme and our compliance team delivers it: gap assessment, remediation, auditor liaison and certificate. Cyber Essentials Plus typically takes 6–10 weeks, ISO 27001 4–6 months. Programme pricing is on the compliance page.
Your CISO runs containment, forensics co-ordination and stakeholder communications, including the ICO notification decision within the 72-hour window if personal data is involved. If you take the optional 24/7 managed SOC through our UK partner, detection and first response happen round the clock and the CISO leads from there.
Yes – fractional CIO (from £1,250/month), CTO (from £1,950/month), DPO (from £950/month) and IT Director (from £995/month). CISO plus DPO is a common pairing for regulated and data-heavy firms. See fractional leadership for the full line-up.
No. Most clients are, because a risk register and a board rhythm compound over quarters. If what you need is bounded, such as answering one enterprise client's security questionnaire, a pre-insurance gap assessment or a single tabletop exercise, we will scope and price that on its own and tell you honestly whether it needs to become ongoing.