Fractional CISO & IT leadership · San Francisco · Est. 1997

Flip it. Test it. Trust it.

  1. 01 · Flip it

    See your environment the way attackers and auditors do — from every angle.

  2. 02 · Test it

    Prove what holds with tabletop exercises, penetration testing, and control reviews.

  3. 03 · Trust it

    Act on a prioritized roadmap and board reporting you can stand behind.

Fractional CISO and IT leadership that works in the boardroom and the server room.

Outcomes

What changes when security has a real owner.

Every engagement is measured by what it leaves behind — not by hours logged or reports filed.

  • Audit-ready, and staying that way

    SOC 2, ISO 27001, HIPAA, and NIST programs that survive the audit — and the year after it.

  • Board reporting that lands

    Security risk translated into decisions executives and boards can actually make.

  • A roadmap your team can execute

    Priorities set by risk and budget, not by the last vendor pitch.

  • Calm in an incident

    Plans rehearsed before they're needed, and experienced leadership when they are.

  • 20+ YearsTechnology & security leadership
  • CISSP · CISMSecurity leadership credentials

SOC 2 · ISO 27001 · HIPAA · NIST CSF Security & compliance

Services

Senior security ownership, sized to your organization.

Not every organization needs a full-time CISO. Every organization needs clear ownership of security risk.

01 · Security leadership

Fractional CISO

Executive ownership of security risk, strategy, and board reporting — the accountability of a full-time CISO, without the full-time overhead.

Discuss an engagement

↑ What leadership gets

  • Risk strategy and a prioritized security roadmap
  • Board and executive reporting in plain language
  • Compliance ownership — SOC 2, ISO 27001, HIPAA

↓ What your team gets

  • Clear priorities instead of an endless wish list
  • A senior leader to escalate to when it matters
  • Budget and vendor decisions made with context

Best fit: organizations without a dedicated security executive.

02 · IT leadership

Fractional IT Leadership

Full ownership of the IT function itself — strategy, infrastructure, vendors, and the team that keeps it all running, sized to what your organization actually needs.

Discuss IT leadership

↑ What leadership gets

  • IT strategy set with the business, not just the server room
  • Budgets and vendor contracts negotiated with your CFO
  • One accountable owner for the whole IT function

↓ What your team gets

  • Infrastructure built and maintained office by office
  • Service delivery that employees trust
  • A clear leader to escalate to when something breaks

Best fit: organizations without a dedicated IT executive.

Capabilities

Brought into either engagement as the scope requires.

  1. Security assessment

    NIST CSF 2.0 scoring across infrastructure, identity, cloud, and process.

  2. Compliance & GRC

    SOC 2, ISO 27001, HIPAA, and NIST — audit-ready, and kept that way.

  3. Incident readiness

    Plans rehearsed before they're needed, leadership when they are.

  4. M&A due diligence

    Security and IT posture assessed before you sign, integrated after.

  5. AI governance

    Clear rules for how your people use AI, and what data it can touch.

  6. Security awareness

    Training that changes behavior instead of checking a box.

Not sure where to start? See where you stand before the first call. A guided NIST CSF 2.0 self-assessment covering all 6 Functions, 22 Categories, and 106 Subcategories. Open the assessment ↗ csf.dollop.comSample report output Govern82% Identify68% Protect74% Detect55% Respond61% Recover70% (opens in a new tab)

How engagements work

Senior leadership, with specialists on call.

When the scope calls for deeper expertise, we bring in trusted specialists from our network — so you get the depth of a full team without building a department.

  1. Fixed scope

    Assessment

    A defined engagement that ends with a scored report and a prioritized roadmap.

    Scoped and quoted after a first call.

  2. Ongoing

    Fractional retainer

    A standing seat as your security or IT leader, with regular executive and board reporting.

    Monthly, sized to the work.

  3. Transitional

    Interim leadership

    Full coverage of the security or IT seat during a search, leave, or reorganization.

    For as long as the gap lasts.

Every engagement is led by Robert Burns (opens in a new tab), CISSP, CISM. Specialist expertise is brought in when the scope requires it.

We still build things. Visit Labs (opens in a new tab)

Get in touch

Let's talk about what you need.

Tell us what you're working with — a board asking questions, an audit on the calendar, a deal in diligence — and we'll tell you honestly whether we're the right fit.

San Francisco, CA · Working with teams everywhere

We use your details only to reply to you. They are never sold or shared.