Fractional CISO & IT leadership · San Francisco · Est. 1997

Security that holds up from every angle.

We provide fractional CISO and IT leadership that works in the boardroom and the server room — from the auditor's view and the attacker's.

Outcomes

What changes when security has a real owner.

Every engagement is measured by what it leaves behind — not by hours logged or reports filed.

  • Audit-ready, and staying that way

    SOC 2, ISO 27001, HIPAA, and NIST programs that survive the audit — and the year after it.

  • Board reporting that lands

    Security risk translated into decisions executives and boards can actually make.

  • A roadmap your team can execute

    Priorities set by risk and budget, not by the last vendor pitch.

  • Calm in an incident

    Plans rehearsed before they're needed, and experienced leadership when they are.

Services

Senior security ownership, sized to your organization.

Most organizations don't need a full-time CISO. They need senior leadership that owns the risk, reports to the board, and gets the program audit-ready — for as much of the week as the work requires.

01 · The core engagement

Fractional CISO

Executive ownership of security risk, strategy, and board reporting — the accountability of a full-time CISO, without the full-time overhead.

Discuss an engagement

↑ What leadership gets

  • Risk strategy and a prioritized security roadmap
  • Board and executive reporting in plain language
  • Compliance ownership — SOC 2, ISO 27001, HIPAA

↓ What your team gets

  • Clear priorities instead of an endless wish list
  • A senior leader to escalate to when it matters
  • Budget and vendor decisions made with context

Best fit: organizations without a dedicated security executive.

Also available

Fractional IT leadership

The whole IT function, not just its security layer: budgets set with your CFO, a help desk people actually want to call, and infrastructure built office by office.

Budget & vendor mgmt / help desk / office & datacenter build-outs

Discuss IT leadership →
  1. 02

    Security assessment

    A clear-eyed look at infrastructure, identity, endpoints, cloud, and process — scored against NIST CSF 2.0 and prioritized into a report your team can act on. Penetration testing is scoped and managed through our specialist network.

    Gap analysis / NIST CSF 2.0 / cloud security review / pen test management

  2. 03

    Compliance & GRC

    SOC 2, ISO 27001, HIPAA, and NIST programs brought to audit-ready status and kept there — including the vendor reviews, customer security questionnaires, and cyber insurance applications that come with them.

    SOC 2 Type II / ISO 27001 / HIPAA / vendor risk / insurance readiness

  3. 04

    Incident readiness

    Preparation before something goes wrong, and steady, experienced leadership when it does.

    IR planning / tabletop exercises / business continuity

  4. 05

    Security awareness & culture

    Training that changes behavior instead of checking a box: phishing simulations, onboarding for new staff, and briefings that prepare executives and board members for their part in the program.

    Phishing simulation / staff training / executive & board briefings

  5. 06

    M&A security due diligence

    Know what you are buying before you sign. We assess a target's security posture and IT environment before close, then plan and lead the integration after it.

    Pre-deal assessment / findings for deal teams / post-close integration

  6. 07

    AI governance & security

    Clear rules for how your people use AI, controls that keep company data out of the wrong tools, and security reviews of the AI vendors you rely on.

    Acceptable-use policy / data protection / AI vendor review

Not sure where to start? See where you stand before the first call. A guided NIST CSF 2.0 self-assessment covering all 6 Functions, 22 Categories, and 106 Subcategories. Open the assessment ↗ csf.dollop.comSample report output Govern82% Identify68% Protect74% Detect55% Respond61% Recover70%

How we work

Senior leadership, with the right specialists on call.

When the scope calls for deeper expertise, we bring in trusted specialists from our network — so you get the depth of a full team without building a department.

Engagements are led by Robert Burns, CISSP, CISM — a security and technology executive with more than 20 years of experience building and running IT and security programs.

We work with healthcare organizations, nonprofits, digital agencies, and companies going through M&A — with experience across global agencies, healthcare, medical devices, and multi-company integrations.

Ways to engage

Scoped to the work, not the other way around.

  1. Fixed scope

    Assessment

    A defined engagement that ends with a scored report and a prioritized roadmap.

    Scoped and quoted after a first call.

  2. Ongoing

    Fractional retainer

    A standing seat as your security or IT leader, with regular executive and board reporting.

    Monthly, sized to the work.

  3. Transitional

    Interim leadership

    Full coverage of the security or IT seat during a search, leave, or reorganization.

    For as long as the gap lasts.

Specialists from our network can join any of these when the scope calls for it.

Get in touch

Let's talk about what you need.

Tell us what you're working with — a board asking questions, an audit on the calendar, a deal in diligence — and we'll tell you honestly whether we're the right fit.

San Francisco, CA · Working with teams everywhere

We use your details only to reply to you. They are never sold or shared.