Fractional CISO
Executive ownership of security risk, strategy, compliance, and board reporting.
dollop technology · San Francisco · Est. 1997
Experienced leadership for technology and security.
Fractional CISO and IT leadership for organizations that need executive oversight of technology, security, or both — without hiring a full-time executive.
Security and compliance programs built for audit preparation and day-to-day operations.
Security risk translated into decisions executives can actually make.
Priorities set by risk and budget, not by the last vendor pitch.
Plans rehearsed before they're needed, and experienced leadership when they are.
Executive ownership of security risk, strategy, compliance, and board reporting.
Ownership of the IT function — strategy, infrastructure, vendors, and the team that runs it.
Also available: security assessments · compliance & GRC · incident readiness · M&A due diligence · AI governance · security awareness training
Many clients start with an assessment. It stands on its own: you keep the findings and roadmap, with no commitment to ongoing leadership.
A fixed-scope review of your security program against NIST CSF 2.0, covering infrastructure, identity, cloud, and process. You receive a findings report and a prioritized roadmap.
Ongoing security or IT leadership, with a monthly scope tailored to your needs.
Temporary security or IT leadership during a search, leave, or reorganization.
Every engagement is led by Robert Burns, CISSP, CISM, with 20+ years in technology and security leadership. Trusted specialists join when the scope requires it.
A plain-English self-assessment scored against NIST CSF 2.0. No account required.
About 10 minutes (opens in a new tab)Review the common security controls insurers ask about, and what to fix before you apply or renew.
About 5 minutes (opens in a new tab)Check your domain for externally visible security issues: email spoofing protection, HTTPS certificate and encryption, and protective settings on your home page.
About 30 seconds (opens in a new tab)Tell us what you're working with — a board asking questions, an audit on the calendar, a deal in diligence — and we'll tell you honestly whether we're the right fit.