Fractional CISO for startups and health tech
Build customer trust. Protect your runway. Scale with confidence.
Fractional CISO services for startups that need experienced security leadership without hiring a full-time executive. I work alongside founders, CFOs, CIOs, CTOs and boards to identify risks, prioritize investment and build a program that grows with the company.
Part I
Protect your runway
Where startups feel the pressure, when to bring in security leadership, and how I work with your team.
The founder's reality
Your team is building the business. Security needs a clear owner.
Nobody on a startup team is short on work. Security usually lands on whoever has a spare hour, until a customer, investor or incident forces the question.
Sound familiar?
Product development competes with customer questionnaires and evidence requests.
Limited funding means hard choices about hiring and tools.
New customers bring requirements you haven't dealt with before.
Fast hiring and new vendors make informal practices hard to keep up.
You need clear answers about what has to happen now and what can wait.
$4.99M
was the global average cost of a data breach, a record high and up 12% over last year.
Detection, escalation and lost business, which includes disrupted operations and customer churn, made up 63% of that cost. In the US, the average reached a record $11.5 million. For a startup, those costs come straight out of runway.
Source: IBM, Cost of a Data Breach Report 2026, research by Ponemon Institute (602 breached organizations, March 2025 to February 2026)
When to bring me in
When the next opportunity requires more security maturity.
The enterprise customer
A promising prospect asks for a SOC 2 report, a security questionnaire and supporting documents. I help clarify what they need, assemble evidence and plan the fixes.
The first healthcare contract
A customer asks about HIPAA responsibilities and a business associate agreement. We map the relationship, data flows, safeguards and who does what, with your counsel where needed.
The funding or acquisition review
Leadership needs a documented view of risks, remediation commitments and projected security spending.
The overloaded CTO
Engineering leadership is juggling product delivery, infrastructure and security. I take on program leadership and hand engineering a prioritized security backlog.
The scaling team
New hires, contractors and systems call for repeatable onboarding, access reviews and offboarding.
The AI launch
A new feature or internal tool raises questions about sensitive data, vendors, permissions and human oversight.
The leadership transition
You need an interim CISO while you recruit or reorganize.
Why customers ask: supply chain breaches, where a business partner is compromised, added $227,250 to the average breach cost, more than any other factor IBM studied. Source: IBM, Cost of a Data Breach Report 2026
Working with your leadership
One security plan. Clear decisions across your leadership team.
Founder or CEO
Security priorities aligned with growth milestones, customer commitments and your tolerance for risk.
CFO
A phased budget covering advisory work, tools, assessments and implementation, with the trade-offs explained and no duplicate spending.
CTO and engineering
Practical security requirements, clear ownership and remediation priorities that fit your development plan.
CIO, internal IT or MSP
Coordination on access management, vendor oversight, infrastructure controls, monitoring and recovery readiness.
Board
Significant risks, progress, open decisions and resource needs, presented in business language.
The working rhythm is simple: agreed leadership meetings, tracked actions and short, clear reports.
Business risk decisions stay with your leadership. My role is to inform those decisions and coordinate the work.
Part II
Build customer trust
Assessment, HIPAA, SOC 2 and HITRUST readiness, healthcare obligations, and product and AI governance.
Assessment and roadmap
Know what matters now and what comes next.
Start with the business
Your business model, customer commitments, critical services and sensitive data.
Review what's in place
Existing controls, processes, vendors and evidence.
Build the roadmap
A prioritized plan, aligned with launches, customer onboarding, assessments and available resources.
Separate now from later
Immediate priorities are split from improvements that can be staged.
Every roadmap item includes
For HIPAA-regulated organizations, the assessment includes the accurate and thorough risk analysis of electronic protected health information that the HIPAA Security Rule requires.
HIPAA, SOC 2 and HITRUST
Prepare for the requirements that matter to your business.
SOC 2 readiness
Define scope, find the gaps, put controls and evidence in place, and coordinate with the independent CPA firm doing the examination.
HIPAA
Address the obligations that apply to you, based on your activities, your relationships and how you handle protected health information.
HITRUST readiness
Look at what your customers expect and choose the right assessment path before committing resources.
Where requirements overlap, evidence can be reused, while each one keeps its own scope.
I provide readiness and program support. SOC 2 is an examination performed by an independent CPA firm, and the result is a report, not a certification. A SOC 2 report does not establish HIPAA compliance. HITRUST certification goes through HITRUST's own assessment process.
Noncompliance with regulations added $201,112 to the average cost of a breach. Source: IBM, Cost of a Data Breach Report 2026
Healthcare specialization
Healthcare growth brings additional responsibilities.
Healthcare delivery startups
Risk management connected to clinical workflows, workforce practices, vendors and continuity of care.
Health-tech vendors
A map of how patient information moves through your product, cloud services, support tools and subcontractors.
Consumer health apps and wearables
A review of the obligations tied to what you actually do. Collecting health information doesn't automatically make a company subject to HIPAA.
Under HIPAA, a company is a business associate when it creates, receives, maintains or transmits protected health information on behalf of a covered entity or another business associate. Whether that applies depends on the relationship.
Some health products outside HIPAA fall under the FTC's Health Breach Notification Rule instead.
$6.64M
was the average cost of a healthcare breach, the highest of any industry for the 13th year in a row.
Attackers continue to target patient information, which can be used for identity theft, insurance fraud and other financial crimes.
Source: IBM, Cost of a Data Breach Report 2026, research by Ponemon Institute (602 breached organizations, March 2025 to February 2026)
The benefit: you make informed product, vendor and customer commitments early, before they're signed.
Product, AI and vendor governance
Build security into the way you develop and operate.
Secure development
Security expectations for engineering and clear ownership of vulnerabilities, built into how your team ships.
AI governance
Acceptable Use Policies, data-handling rules, vendor reviews and human oversight for AI tools and features.
Sensitive data
A review of sensitive data in analytics, support systems, logs and testing environments.
Marketing and analytics
A check on tracking and advertising integrations before they share health information you didn't intend to share.
92%
of organizations that reported an AI-related breach lacked proper AI access controls.
The share of security incidents involving shadow AI, where workers use unapproved AI tools, more than doubled, from 20% to 43%. And 68% of breached organizations lacked governance to manage AI or detect shadow AI.
Source: IBM, Cost of a Data Breach Report 2026, research by Ponemon Institute (602 breached organizations, March 2025 to February 2026)
A DevSecOps approach was the top factor in reducing breach costs, lowering them by $253,805 on average.
Source: IBM, Cost of a Data Breach Report 2026
Part III
Scale with confidence
Resilience, how engagements work, and what progress looks like.
Operational resilience
Prepare to respond without losing direction.
Decisions and communication
Who makes incident decisions, how issues escalate and who talks to customers and the board.
Detection
Monitoring responsibilities agreed with your technical team and service providers.
Recovery planning
Ransomware readiness, disaster recovery and business continuity plans.
Practice
Exercises built on realistic scenarios, such as a cloud outage, a compromised account or exposed customer data.
Cyber insurance
Evidence prepared for your application and coordination with your broker.
247 days
was the average time to identify and contain a breach.
42% of breached organizations said they had fully recovered, up from 35% last year. Full recovery includes restoring normal operations, meeting compliance obligations and rebuilding customer confidence.
Source: IBM, Cost of a Data Breach Report 2026, research by Ponemon Institute (602 breached organizations, March 2025 to February 2026)
The goal: keep serving customers, restore operations and communicate clearly with customers and your board.
Engagement model
Senior security leadership without a full-time executive hire.
Project work
Clearly scoped work, such as an assessment or SOC 2 readiness.
Fractional leadership
Ongoing security leadership with agreed time, responsibilities and deliverables.
Interim support
Coverage during a search or reorganization, with a handoff to your next security leader.
Every engagement defines the access, responsibilities and deliverables up front. I also help your CFO see the full program budget, including implementation and independent assessment costs.
Support changes as you grow, including the transition to an internal security leader when the time comes.
Fractional leadership is not unlimited availability or a full technical security team, and I don't guarantee sales or funding outcomes. It does give you experienced leadership where it counts.
What progress looks like
Know your risks. Know your priorities. Know who is accountable.
A current risk register and a funded roadmap.
Customer review evidence that's organized and ready.
An assigned owner for every remediation item.
Response and recovery procedures that have been tested.
Clear reporting for executives and the board.
Confidence comes from visibility, preparation and follow-through.
FAQs
Questions founders ask before we start.
When should a startup engage a fractional CISO?
Usually when a milestone raises the stakes: a first enterprise or healthcare customer, a SOC 2 request, a funding round or an AI launch. It's easier to shape those decisions before commitments are signed.
How do you work with our CFO, CTO, CIO or MSP?
I lead the security plan and coordinate it across your team. Your CFO gets a phased budget, your CTO gets priorities that fit the development plan, and your IT team or MSP handles the agreed technical work. Business risk decisions stay with your leadership.
Does our health-tech product fall under HIPAA?
It depends on what you do and for whom. If you create, receive, maintain or transmit protected health information on behalf of a covered entity or another business associate, you're a business associate. Some consumer health products fall outside HIPAA but under the FTC's Health Breach Notification Rule. We map this early, with your legal counsel making the final call.
Do we need SOC 2, HITRUST or both?
It depends on what your customers ask for. I review their requirements with you and recommend a path before you commit budget. Where both apply, evidence can often be reused, but each has its own scope.
Can you help with customer questionnaires and investor diligence?
Yes. I help you answer accurately, organize the supporting evidence and document the risks and remediation plans leadership needs to discuss.
Can we start with an assessment?
Yes. Most engagements start there, and you come away with a prioritized roadmap.
How much internal time and budget should we expect?
It depends on scope. After our first conversation you get a written proposal with the scope, the fee and the time we'll need from your team. I'll also help you plan for costs outside my fee, such as tools, implementation and independent assessments.
Next step
Let's prepare your security program for your next stage of growth.
Bring a concrete milestone: a customer security review, a product launch, a funding process or an expansion. In 30 minutes we'll talk through what it requires and a sensible place to start.
