FRACTIONAL CISO & CCO
Named owner for
security and compliance
without a full-time hire
We keep your AI policy applied as tools and rules change, answer client security reviews for you, and carry compliance forward. Part-time, accountable, and there when it matters.
- Named, accountable owner
- EU AI Act, NIS2, DORA, GDPR, ISO 27001, SOC 2, ISO 42001
- A fraction of a full-time CISO
One owner, three jobs
A named person who keeps policy applied, carries compliance forward, and answers your clients for you. Not a slide deck. Someone accountable.
Policy, kept alive
Rules that move with the tools, not a PDF from last year.
- Policy reviewed as tools and risks change
- New AI tools vetted before they spread
- Rules embedded in onboarding and daily work
Compliance, carried forward
Regulation decoded into tasks, not left as a deadline.
- EU AI Act, NIS2, DORA, GDPR turned into next steps
- ISO 27001, SOC 2, ISO 42001 alignment kept current
- Evidence collected as work happens, not before audits
Clients, answered
Security reviews and tenders get a name, not a scramble.
- Security questionnaires answered for you
- Tender answers in writing, with evidence
- One accountable name clients can point to
Consistent leadership, ongoing accountability
A fractional officer works alongside your team across policies, questionnaires, and audits, providing continuity and a clear point of contact for as long as your organization needs support.
- Customer trust: clients get a named owner and evidence the rules run.
- Legal safety: compliance owned by someone who reads the regulation so you don’t.
- No full-time salary: a senior owner for a fraction of a CISO’s cost.
Senior security ownership, without the senior hire
Most CEE software SMEs can’t fill a CISO seat and don’t need to.
Full-time CISO
- Hard to hire, harder to keep, in this market
- Senior salary for work that is partly overhead
- Still needs a separate AI security specialism
- One person, one point of failure
Your fractional officer
- Named owner from week one
- A fraction of the cost - pay for what you use
- Built around AI from the start
- Backed by the whole Stihia team behind them
How it starts
Three steps. The first costs you just half an hour.
Intro call
Thirty minutes. We map your tools, clients, and deadlines, and tell you honestly whether a fractional officer is the right next step.
First 30 days
Policy refreshed, evidence baseline set, and a rhythm established with your team.
Steady rhythm
Tool reviews, quarterly attestations, and questionnaires as they land, owned end to end, on a retainer you can plan around.
Questions we get asked
Is this just a policy we pay for every month?
No. The deliverable is an owner, not a document. They keep the rules applied, answer your clients, and carry compliance forward. A policy you already have becomes part of what they run, it is not the thing you buy.
Do we still need the workshop and the policy work?
They fill different jobs. The workshop builds awareness, the policy sets the rules, and the officer keeps both alive over time. Many clients start with one and add the others; some bring the officer in to run what already exists.
What happens when the engagement ends?
You keep the policy, the evidence trail, and the review rhythm. The work is documented so it survives the handover, and if your needs grow, we can talk about a full-time hire or an internal owner instead.
How much of my time does it take?
A short sync each month and a review each quarter, plus ad-hoc input when a client questionnaire or a new tool needs a decision. Most of the work happens off your desk.
What does it cost?
A monthly retainer, scoped on the intro call based on company size, the number of client reviews you run, and how much of the implementation you want owned for you. You see the price before you commit to anything.
Want a name on it, not an open question?
Start with a half-hour call. Tell us where AI is spreading, what your clients ask, and what is already overdue, and we will tell you honestly whether a fractional officer fits.