Who I Help · Startups and Health Tech

Fractional CISO for startups and health tech

Build customer trust. Protect your runway. Scale with confidence.

Fractional CISO services for startups that need experienced security leadership without hiring a full-time executive. I work alongside founders, CFOs, CIOs, CTOs and boards to identify risks, prioritize investment and build a program that grows with the company.

Part I

Protect your runway

Where startups feel the pressure, when to bring in security leadership, and how I work with your team.

The founder's reality

Your team is building the business. Security needs a clear owner.

Nobody on a startup team is short on work. Security usually lands on whoever has a spare hour, until a customer, investor or incident forces the question.

Sound familiar?

Product development competes with customer questionnaires and evidence requests.

Limited funding means hard choices about hiring and tools.

New customers bring requirements you haven't dealt with before.

Fast hiring and new vendors make informal practices hard to keep up.

You need clear answers about what has to happen now and what can wait.

$4.99M

was the global average cost of a data breach, a record high and up 12% over last year.

Detection, escalation and lost business, which includes disrupted operations and customer churn, made up 63% of that cost. In the US, the average reached a record $11.5 million. For a startup, those costs come straight out of runway.

Source: IBM, Cost of a Data Breach Report 2026, research by Ponemon Institute (602 breached organizations, March 2025 to February 2026)

When to bring me in

When the next opportunity requires more security maturity.

The enterprise customer

A promising prospect asks for a SOC 2 report, a security questionnaire and supporting documents. I help clarify what they need, assemble evidence and plan the fixes.

The first healthcare contract

A customer asks about HIPAA responsibilities and a business associate agreement. We map the relationship, data flows, safeguards and who does what, with your counsel where needed.

The funding or acquisition review

Leadership needs a documented view of risks, remediation commitments and projected security spending.

The overloaded CTO

Engineering leadership is juggling product delivery, infrastructure and security. I take on program leadership and hand engineering a prioritized security backlog.

The scaling team

New hires, contractors and systems call for repeatable onboarding, access reviews and offboarding.

The AI launch

A new feature or internal tool raises questions about sensitive data, vendors, permissions and human oversight.

The leadership transition

You need an interim CISO while you recruit or reorganize.

Why customers ask: supply chain breaches, where a business partner is compromised, added $227,250 to the average breach cost, more than any other factor IBM studied. Source: IBM, Cost of a Data Breach Report 2026

Working with your leadership

One security plan. Clear decisions across your leadership team.

Founder or CEO

Security priorities aligned with growth milestones, customer commitments and your tolerance for risk.

CFO

A phased budget covering advisory work, tools, assessments and implementation, with the trade-offs explained and no duplicate spending.

CTO and engineering

Practical security requirements, clear ownership and remediation priorities that fit your development plan.

CIO, internal IT or MSP

Coordination on access management, vendor oversight, infrastructure controls, monitoring and recovery readiness.

Board

Significant risks, progress, open decisions and resource needs, presented in business language.

The working rhythm is simple: agreed leadership meetings, tracked actions and short, clear reports.

Business risk decisions stay with your leadership. My role is to inform those decisions and coordinate the work.

Part II

Build customer trust

Assessment, HIPAA, SOC 2 and HITRUST readiness, healthcare obligations, and product and AI governance.

Assessment and roadmap

Know what matters now and what comes next.

1

Start with the business

Your business model, customer commitments, critical services and sensitive data.

2

Review what's in place

Existing controls, processes, vendors and evidence.

3

Build the roadmap

A prioritized plan, aligned with launches, customer onboarding, assessments and available resources.

4

Separate now from later

Immediate priorities are split from improvements that can be staged.

Every roadmap item includes

Business impact
Recommended action
Owner
Dependencies
Target timing

For HIPAA-regulated organizations, the assessment includes the accurate and thorough risk analysis of electronic protected health information that the HIPAA Security Rule requires.

HIPAA, SOC 2 and HITRUST

Prepare for the requirements that matter to your business.

SOC 2 readiness

Define scope, find the gaps, put controls and evidence in place, and coordinate with the independent CPA firm doing the examination.

HIPAA

Address the obligations that apply to you, based on your activities, your relationships and how you handle protected health information.

HITRUST readiness

Look at what your customers expect and choose the right assessment path before committing resources.

Where requirements overlap, evidence can be reused, while each one keeps its own scope.

I provide readiness and program support. SOC 2 is an examination performed by an independent CPA firm, and the result is a report, not a certification. A SOC 2 report does not establish HIPAA compliance. HITRUST certification goes through HITRUST's own assessment process.

Noncompliance with regulations added $201,112 to the average cost of a breach. Source: IBM, Cost of a Data Breach Report 2026

Healthcare specialization

Healthcare growth brings additional responsibilities.

Healthcare delivery startups

Risk management connected to clinical workflows, workforce practices, vendors and continuity of care.

Health-tech vendors

A map of how patient information moves through your product, cloud services, support tools and subcontractors.

Consumer health apps and wearables

A review of the obligations tied to what you actually do. Collecting health information doesn't automatically make a company subject to HIPAA.

Under HIPAA, a company is a business associate when it creates, receives, maintains or transmits protected health information on behalf of a covered entity or another business associate. Whether that applies depends on the relationship.

Some health products outside HIPAA fall under the FTC's Health Breach Notification Rule instead.

$6.64M

was the average cost of a healthcare breach, the highest of any industry for the 13th year in a row.

Attackers continue to target patient information, which can be used for identity theft, insurance fraud and other financial crimes.

Source: IBM, Cost of a Data Breach Report 2026, research by Ponemon Institute (602 breached organizations, March 2025 to February 2026)

The benefit: you make informed product, vendor and customer commitments early, before they're signed.

Product, AI and vendor governance

Build security into the way you develop and operate.

Secure development

Security expectations for engineering and clear ownership of vulnerabilities, built into how your team ships.

AI governance

Acceptable Use Policies, data-handling rules, vendor reviews and human oversight for AI tools and features.

Sensitive data

A review of sensitive data in analytics, support systems, logs and testing environments.

Marketing and analytics

A check on tracking and advertising integrations before they share health information you didn't intend to share.

92%

of organizations that reported an AI-related breach lacked proper AI access controls.

The share of security incidents involving shadow AI, where workers use unapproved AI tools, more than doubled, from 20% to 43%. And 68% of breached organizations lacked governance to manage AI or detect shadow AI.

Source: IBM, Cost of a Data Breach Report 2026, research by Ponemon Institute (602 breached organizations, March 2025 to February 2026)

A DevSecOps approach was the top factor in reducing breach costs, lowering them by $253,805 on average.

Source: IBM, Cost of a Data Breach Report 2026

Part III

Scale with confidence

Resilience, how engagements work, and what progress looks like.

Operational resilience

Prepare to respond without losing direction.

Decisions and communication

Who makes incident decisions, how issues escalate and who talks to customers and the board.

Detection

Monitoring responsibilities agreed with your technical team and service providers.

Recovery planning

Ransomware readiness, disaster recovery and business continuity plans.

Practice

Exercises built on realistic scenarios, such as a cloud outage, a compromised account or exposed customer data.

Cyber insurance

Evidence prepared for your application and coordination with your broker.

247 days

was the average time to identify and contain a breach.

42% of breached organizations said they had fully recovered, up from 35% last year. Full recovery includes restoring normal operations, meeting compliance obligations and rebuilding customer confidence.

Source: IBM, Cost of a Data Breach Report 2026, research by Ponemon Institute (602 breached organizations, March 2025 to February 2026)

The goal: keep serving customers, restore operations and communicate clearly with customers and your board.

Engagement model

Senior security leadership without a full-time executive hire.

1

Project work

Clearly scoped work, such as an assessment or SOC 2 readiness.

2

Fractional leadership

Ongoing security leadership with agreed time, responsibilities and deliverables.

3

Interim support

Coverage during a search or reorganization, with a handoff to your next security leader.

Every engagement defines the access, responsibilities and deliverables up front. I also help your CFO see the full program budget, including implementation and independent assessment costs.

Support changes as you grow, including the transition to an internal security leader when the time comes.

Fractional leadership is not unlimited availability or a full technical security team, and I don't guarantee sales or funding outcomes. It does give you experienced leadership where it counts.

What progress looks like

Know your risks. Know your priorities. Know who is accountable.

A current risk register and a funded roadmap.

Customer review evidence that's organized and ready.

An assigned owner for every remediation item.

Response and recovery procedures that have been tested.

Clear reporting for executives and the board.

Confidence comes from visibility, preparation and follow-through.

FAQs

Questions founders ask before we start.

When should a startup engage a fractional CISO?

Usually when a milestone raises the stakes: a first enterprise or healthcare customer, a SOC 2 request, a funding round or an AI launch. It's easier to shape those decisions before commitments are signed.

How do you work with our CFO, CTO, CIO or MSP?

I lead the security plan and coordinate it across your team. Your CFO gets a phased budget, your CTO gets priorities that fit the development plan, and your IT team or MSP handles the agreed technical work. Business risk decisions stay with your leadership.

Does our health-tech product fall under HIPAA?

It depends on what you do and for whom. If you create, receive, maintain or transmit protected health information on behalf of a covered entity or another business associate, you're a business associate. Some consumer health products fall outside HIPAA but under the FTC's Health Breach Notification Rule. We map this early, with your legal counsel making the final call.

Do we need SOC 2, HITRUST or both?

It depends on what your customers ask for. I review their requirements with you and recommend a path before you commit budget. Where both apply, evidence can often be reused, but each has its own scope.

Can you help with customer questionnaires and investor diligence?

Yes. I help you answer accurately, organize the supporting evidence and document the risks and remediation plans leadership needs to discuss.

Can we start with an assessment?

Yes. Most engagements start there, and you come away with a prioritized roadmap.

How much internal time and budget should we expect?

It depends on scope. After our first conversation you get a written proposal with the scope, the fee and the time we'll need from your team. I'll also help you plan for costs outside my fee, such as tools, implementation and independent assessments.

Next step

Let's prepare your security program for your next stage of growth.

Bring a concrete milestone: a customer security review, a product launch, a funding process or an expansion. In 30 minutes we'll talk through what it requires and a sensible place to start.