Security leadership
Fractional CISO services in Australia: cost, scope, and when the model works
What a fractional CISO actually does, what the role costs in Australia, the failure modes nobody advertises, and where the always-on digital CISO fits next. A straight guide for mid-market boards weighing their security leadership options.
The Australian Signals Directorate received over 84,700 cybercrime reports last financial year, one every six minutes, and the average self-reported cost of an incident for a small business rose 14 per cent to $56,600, per the ACSC Annual Cyber Threat Report 2024-25. Those numbers appear in every vendor deck in the country, usually two slides before a pitch for another detection product.
Here is the less quotable part. Most organisations that wear those losses did not lack tools. They lacked an owner: a person whose actual job was to decide which risks mattered, in what order, with what budget, and what the board should be told about the ones left over. Industry research puts the share of small and mid-sized businesses operating without any CISO at around 64 per cent. The reason is arithmetic, not negligence. A credible full-time CISO in Australia costs well north of AUD 300,000 once superannuation and on-costs land, and offshore markets have pushed total packages higher still. For a 150-person organisation, the role does not exist at that price. So it goes unfilled, and the risk stays unowned.
The fractional CISO model exists to fix the ownership gap, not the tooling gap. This piece is what we tell mid-market organisations (50 to 500 staff) when they ask: what does a fractional CISO actually do, what should it cost, and how do we tell a real one from a retainer with a title attached?
What a fractional CISO actually is
A fractional CISO is a senior security executive who holds the role part time: a named person, on a standing cadence, carrying personal accountability for your security posture. The market uses several labels for adjacent things. vCISO and CISO-as-a-service usually describe a service delivered by a firm, sometimes through a rotating bench of consultants. Fractional, used honestly, means something narrower: one named individual who attends your risk and audit committee, signs governance documents in their own name, and is the person a regulator, insurer, or enterprise customer can put on the phone.
That distinction is the whole game. Advice is abundant and cheap. Accountability is scarce and expensive, and it is the thing your board is actually short of.
Our version of the role is the fractional AI and information risk officer, because at board level in 2026 information risk and AI risk are the same conversation. The engagement is not advisory work. It is a role, held by a person, with their name on it.
What the role covers, and what it does not
The substantive work of a fractional CISO in a mid-market organisation:
- A security strategy and a costed roadmap. Not a maturity heatmap. A sequence of decisions the executive team can fund, with the trade-offs stated.
- Risk assessment and remediation priority. What is actually exposed, what gets fixed first, and what the organisation is consciously accepting.
- Policies and standards people follow. Acceptable use, data classification, vendor risk, AI usage. Short enough to be read, specific enough to be enforced.
- Framework alignment proportionate to your obligations. Essential Eight and NIST CSF 2.0 as the baseline, ISO 27001 where certification has commercial value, CPS 234 and CPS 230 where APRA reaches you directly or through a customer, and the Privacy Act everywhere. Our post on what CPS 234 auditors actually look for covers the regulated end of that spectrum.
- Vendor and third-party risk review. Every proposed tool assessed against your data classification and contractual posture before procurement signs, not after.
- Incident readiness and response leadership. Playbooks that name people, and a senior hand on the wheel when one fires.
- Outward-facing assurance. Board reporting, insurer questionnaires, and the enterprise customer security reviews that increasingly gate mid-market revenue.
And what the role does not do, which matters just as much:
- Run a 24/7 SOC. A fractional CISO decides what gets monitored and by whom. They are not your overnight analyst.
- Absorb your engineering backlog. Patching, identity cleanup, and configuration work belong to your team or your MSP. The fractional CISO sets the priority and verifies the result.
- Perform the penetration test. They scope it, commission it, and translate the findings into decisions. Independence is the point; the person who owns the controls should not be the person marking them. When testing is due, that is a separate engagement.
- Guarantee compliance. Anyone who promises certification or regulator sign-off as an outcome is selling something other than security leadership.
- Take accountability off your directors. Under Australian law it does not move. A good fractional CISO makes that accountability exercisable. They do not make it disappear.
The economics, honestly
The cost argument is real, but it is usually made lazily, so here it is with the caveats attached.
| Full-time CISO | Fractional CISO | |
|---|---|---|
| Annual cost | AUD 300,000 to 450,000 plus super, on-costs, and equity expectations | AUD 96,000 to 180,000 depending on tier and cadence |
| Time to productive | Three to six months of search, then onboarding | Two to four weeks |
| Utilisation | Full time, whether or not the work is full time | Sized to the work that actually exists |
| Exit | Notice period, payout, and another six-month search | End of any quarter with thirty days notice |
Our own fractional officer engagement runs from AUD 8,000 per month on a twelve-month term with quarterly review points, which puts senior, named accountability at roughly a quarter to a third of the loaded cost of a full-time hire.
But the honest argument is utilisation, not price. A 150-person organisation has perhaps one to two days a week of genuine CISO-level work: decisions, reporting, vendor calls, committee time. A full-time hire at that scale either drifts into operational work you could staff at half the price, or gets bored and leaves. Industry surveys have tracked CISO tenure below three years for a decade. The fractional model is not a discount CISO. It is the correct sizing of a role that mid-market organisations have been forced to buy in the wrong denomination.
When the fractional model works
The pattern across engagements that go well:
- You are regulated, or you supply the regulated. APRA-regulated entities push CPS 234 obligations down their supply chains. Government buyers push the Essential Eight. If those clauses are turning up in your contracts, someone senior has to own the answer.
- Enterprise customers are sending security questionnaires. A deal-gating questionnaire answered badly costs more than a year of fractional fees.
- Your insurer has started asking harder questions. Cyber insurance renewal is now a controls audit. Premiums move with the quality of your answers.
- The board has had a fright. A near miss, a peer’s breach in the press, a director who sat through an incident elsewhere. Attention is high; what is missing is someone to convert it into a funded plan.
- AI adoption is running ahead of governance. Splunk’s 2026 CISO research found 96 per cent of CISOs now carry responsibility for AI governance. Mid-market organisations are adopting the same tools with nobody carrying that responsibility at all. If that is where you are, a governance posture assessment is often the first concrete deliverable of the engagement.
When it does not work
The failure modes are as consistent as the successes, and providers rarely volunteer them:
- Title rental. A CISO name on the org chart for the insurer form, one meeting a quarter, no authority. Auditors, regulators, and serious customers detect this in a single conversation, and it is worse than the honest gap because it signals intent.
- A roadmap with no hands. If nobody internal or contracted can execute remediation, the fractional CISO produces increasingly well-written descriptions of the same risks. This is why most of our engagements begin with a security posture assessment: it sizes the remediation load honestly before anyone commits to a role that depends on it.
- Expecting 24/7 response from a two-day-a-month engagement. Incident support is part of the role. Being your standing on-call function is not. If you need that, it is a different service with a different price.
- The rotating bench. If you cannot get the practitioner’s name into the contract, you are buying a service desk with a serif font. Ask who, by name, and how much of them.
- Scope creep into operations. The fractional CISO becomes the de facto IT manager, the strategic work dies, and eighteen months later the board asks why posture has not moved. Guard the role’s altitude in the statement of work.
Seven questions to ask before you engage
- Who, by name, and how much of them? Bench depth is a feature of the firm. The role is held by a person.
- What do the first ninety days produce? You want named artefacts: a posture assessment, a risk register the executive team has seen, a roadmap with costs. Not “alignment”.
- Which frameworks have they operated against your regulator? Fluency in the abstract is common. Ask when they last sat across from your actual audience.
- How do they report to the board? Ask for a redacted sample. A board pack is a position, not a weather report; we have written about the structure that actually lands.
- What happens at 2am? Not whether they answer the phone. What the playbook says, who declares the incident, who talks to the OAIC if it comes to that.
- What evidence exists between visits? If posture is only measured when the officer is in the building, you are buying quarterly snapshots of a system that changes daily. This question matters more every year, and it is the subject of the next section.
- How does it end? The policies, registers, and reporting models should be yours, documented, and handover should be a planned deliverable rather than a hostage negotiation.
Where the digital CISO fits, and why it is worth the investment
The fractional model has one structural weakness worth naming, because it is the next thing being fixed: evidence goes stale between visits.
A fractional CISO on two days a month spends most of those days collecting evidence rather than exercising judgment. Pulling admin console exports, chasing log samples, re-checking whether last quarter’s remediation actually shipped. The scarce, expensive resource in the engagement is senior judgment, and the majority of it is consumed by assembly work. Meanwhile the board’s question has changed shape. It is no longer were we in reasonable shape at the last review. It is are we in reasonable shape now, and a quarterly cadence cannot answer it.
The environment is moving the same direction from the other side. Estates now change at machine speed: AI agents, integrations, and machine identities that outnumber human ones by more than a hundred to one in large enterprises, with mid-market trajectories following. Splunk’s 2026 CISO research frames agentic AI as central to how security leaders reach digital resilience at all. Point-in-time assurance over a continuously changing estate is a category error, and everyone in the industry quietly knows it.
This is what a digital CISO is for. Not a chatbot with a title, and not a replacement for the human role. A digital CISO is the always-on reporting layer underneath a named human officer: continuously collecting control evidence, mapping it against the frameworks you answer to, and drafting the reporting a human then stands behind. The economics follow directly. If evidence collection is automated, the fractional officer’s hours shift from assembly to judgment, the board gets a current answer instead of a quarterly one, and the cost of maintaining continuous assurance drops to something mid-market budgets can actually carry. That combination, machine-speed evidence with human accountability, is why the digital CISO is worth the investment, and why continuous assurance is displacing the point-in-time audit as the model regulators and insurers reward.
That is the model our Digital CISO Agent is being designed around, and it is worth being precise about its status: it is in development, not for sale. It reports; it does not remediate. A named human stays accountable, and it will be delivered to current fractional officer clients before it is ever offered standalone. The framework mapping it reports against is published already, early and deliberately, so design partners can tell us where it is wrong. If the evidence-staleness problem is one you recognise, that is an invitation.
Where to start
If you are weighing the fractional model, start by measuring the gap rather than debating the title. The maturity assessment takes ten minutes and gives you a scored baseline to argue about. If the gap is real and the board is ready to fund an owner, a thirty-minute conversation about the fractional officer engagement will establish whether the model fits your scale and your regulator, and we will tell you plainly if it does not.
Continue reading
Related pieces
Board reporting
Reporting AI risk to the board: a one-page position summary that actually works
What the board actually wants on the AI risk page is the answer to four specific questions. Most AI risk reports answer different questions. Here is the structure that lands, four worked examples by sector, and a template you can lift verbatim.
2 May 2026
AI research
The state of AGI: what the evidence supports, and what it does not
A sober read of the AGI evidence in 2026: what frontier systems can measurably do, what expert forecasts actually say, how seriously to take the existential question, and what the research shows about humans and AI working together.
12 September 2026
AI governance
The AI register: the audit artefact every framework now assumes you have
Auditors, regulators, and insurers now open with the same request: show me the list of your AI systems. What an AI register is, what ISO 42001, NIST AI RMF, the EU AI Act, and Australian government policy expect it to contain, and how to keep one alive.
12 September 2026