Tag: cybersecurity

  • What Does a Fractional CISO Cost in the UK? (2026 Guide)

    What Does a Fractional CISO Cost in the UK? (2026 Guide)

    If you’ve started looking into fractional CISO arrangements, you’ve probably noticed that nobody publishes rates. You get vague talk about “competitive pricing” and “tailored engagements” but no actual numbers.

    This is my attempt to fix that. I’ll give you the real ranges, explain what moves the price, and give you the comparison you actually need: fractional versus a permanent hire.

    What You’re Actually Buying

    Before we get to numbers, it’s worth being clear about what a Fractional CISO engagement actually covers — because the answer affects the cost.

    A Fractional CISO is not a security consultant who writes reports. That’s a different engagement model. A Fractional CISO is a part-time member of your senior leadership, operating as your de facto Chief Information Security Officer with all the accountability that implies.

    In practice, that means:

    Ownership of your security posture. Not advice about it. Actual ownership — setting strategy, making decisions, reporting to the board or CEO on risk.

    Ongoing availability. Not just fixed project days. A good Fractional CISO is reachable when something happens — a supplier breach, an insurance questionnaire, a board request for a risk briefing.

    Day-to-day security leadership. Reviewing controls, managing incidents, overseeing your IT team or MSP on security matters, making sure the work actually gets done.

    External credibility. Being able to put a named CISO on a client questionnaire, a contract, or an audit scope. For mid-market businesses dealing with enterprise customers, this alone is often worth the fee.

    That distinction matters because it separates fractional from project-based work, and the price reflects it.

    Typical Cost Ranges in the UK Market

    Here are the real numbers as of 2026, based on the UK market specifically:

    Entry-level engagement: £2,500–£4,000/month
    Usually one day a week, or a structured retainer. Covers governance, policy, and light-touch oversight. Right for smaller businesses (20–80 people) who need a documented security posture and someone accountable for it, but don’t have complex infrastructure or active compliance requirements.

    Mid-range engagement: £4,000–£7,000/month
    One to two days a week. This is the most common arrangement for UK SMEs between 80 and 300 people. Covers strategy, compliance (Cyber Essentials Plus, ISO 27001 readiness, GDPR accountability), board reporting, incident management, and oversight of your technical security team or MSP.

    Higher-intensity engagement: £7,000–£12,000/month
    Two to three days per week, or a fixed-scope intensive engagement (post-incident stabilisation, pre-acquisition security readiness, major compliance programme). At this level you’re getting something close to a full-time CISO presence without the full-time cost.

    Some providers price by day rate rather than monthly retainer. In that case, expect senior Fractional CISO day rates in the UK to sit between £900 and £1,800 per day, depending on experience and specialism.

    What Affects the Price

    The same fractional CISO will charge differently for different engagements. Here’s what moves the number:

    Days committed per month. The main variable. More days, more cost — but also more hands-on delivery versus purely strategic oversight.

    Compliance scope. If you’re pursuing ISO 27001, preparing for a major enterprise audit, or navigating sector-specific requirements (financial services, healthcare, defence supply chain), the workload increases substantially. Expect to pay for it.

    Incident history. Starting from scratch is easier than cleaning up after a breach or a failed audit. Post-incident engagements are more intensive and more expensive in the early months.

    Organisation complexity. 50 people in one office with a single cloud environment is a different engagement to 200 people across four countries with a mix of legacy systems, SaaS, and on-premise infrastructure.

    Urgency. A phased 12-month engagement costs less per month than a 90-day sprint to get you through a due diligence process. You pay for speed.

    Fractional vs Full-Time: The Real Comparison

    A permanent CISO in the UK costs, on a fully-loaded basis:

    • Base salary: £90,000–£160,000 (senior hire in London; less outside)
    • Employer NI: ~13.8% on salary
    • Pension contributions: typically 5–8%
    • Benefits package: private health, life assurance, income protection
    • Recruitment fees: typically 20–25% of first-year salary if using an agency

    Add it up and a full-time CISO typically costs £130,000–£220,000 per year all-in before you’ve counted their office space, equipment, management overhead, or the time it takes to find the right person.

    A mid-range fractional engagement at £5,000/month is £60,000 per year. You get senior-level security leadership at roughly half the cost, with no recruitment risk, no notice period to serve, and the ability to scale the days up or down as your needs change.

    For most UK SMEs, the only reason not to go fractional is if your security workload genuinely justifies full-time attention — and that usually means you’re above 500 people with a complex regulatory environment, active threat landscape, or significant security-critical product development.

    The Starting Point: A Discovery Audit

    For most businesses, the right first engagement isn’t a retainer. It’s a Discovery Audit: a structured review of your current security posture that takes two to three days and produces a prioritised action plan.

    It answers the question: where do we actually stand? It removes the uncertainty from any ongoing engagement that follows, and it’s the honest way to scope a fractional arrangement — you don’t know what you’re buying until you know what the problems are.

    If you’re comparing providers, ask whether they’ll do a discovery engagement before committing to a retainer. If the answer is no, that’s a signal.


    If you’d like to talk through what a fractional CISO engagement might look like for your business — scope, cost, timeline — see the Security & Compliance Strategy service or get in touch directly. I’ll give you a straight answer about whether it makes sense.

  • AI Arms Race: Predictive Cyber Defence

    AI Arms Race: Predictive Cyber Defence Is Here
    Published: August 20, 2025 (retrospective)

    The AI cybersecurity market is projected to hit $60B by 2028—and for good reason. In August 2025, SentinelForge v2’s predictive threat hunting caught a client ransomware pivot 72 hours before it would have detonated. No SOC. No SIEM subscription. Just CrewAI agents, local LLMs, and disciplined governance.

    SentinelForge v2 Production Stack

    proxmox-ve
    └── sentinelforge (docker)
        ├── crewai crews     (24/7 autonomous monitoring)
        ├── ollama           (local inference)
        ├── grafana          (observability)
        └── uptimekuma       (SLA: 99.9%)
    

    The Catch: Anatomy of a Prevention

    • Day 1: Anomalous LDAP query pattern flagged by Audit Crew
    • Day 2: Lateral movement indicators correlated across 3 systems
    • Day 3 (72h): Human review triggered; client isolated affected segment
    • Result: Zero encryption, zero ransom, zero downtime

    What This Means for SMEs

    Enterprise-grade predictive defence is now accessible without enterprise budgets. The stack cost: £0/month in cloud tokens, running on repurposed hardware.

    1. AI agents don’t get tired—24/7 monitoring without alert fatigue.
    2. Local inference keeps sensitive threat data off third-party servers.
    3. Governance logs every detection decision—invaluable for insurance and compliance.

    Want predictive AI defence for your business? Book a Secure AI QuickScan.

    Next: EU AI Act compliance—governance frameworks in practice (Nov 2025).

  • What 2024 Taught Me About Turning AI Work Into Infrastructure

    s

    2024 was the year AI stopped feeling like a side experiment and started feeling like part of the working stack.

    The biggest change was not speed. It was structure.

    What changed

    • routine work got easier to delegate
    • review became part of the workflow instead of an afterthought
    • local execution mattered more than hype
    • security thinking moved earlier in the process

    The numbers were useful, but the bigger shift was behavioural. I spent less time wrestling with one-off tasks and more time building repeatable paths.

    What worked

    The pattern that kept showing up was simple:

    1. keep the sensitive bits local when possible
    2. make the outputs reviewable
    3. use the repository as the record of truth

    That combination did more for consistency than any single tool choice.

    What I would change

    If I were doing it again, I would write more of the operating rules earlier. The systems worked better once the guardrails were explicit.

    That is usually how these things go. The tech is rarely the hard part. The hard part is deciding how much freedom the workflow should really have.

  • M365 Copilot GA: Auditing in the AI Era

    t

    When Microsoft 365 Copilot arrived, the immediate question from clients was not “Can it help?” It was “Is it safe to turn on?”

    My answer was simple: not without a proper permissions review.

    AI does not remove tenant risk. It makes existing risk easier to surface.

    What I kept finding

    Across multiple audits, the same issues kept coming back:

    • over-permissive app consents
    • mailbox forwarding rules that nobody had reviewed in months
    • Intune drift that had crept in quietly

    None of that was exotic. It was just the usual gap between default settings and an actual security posture.

    Why the audit mattered

    The useful part of the process was not the reporting template. It was the discipline.

    I needed a way to check the tenant, explain the findings clearly, and keep the evidence somewhere traceable. That made the audit easier to repeat and a lot harder to hand-wave away.

    The lesson

    If Copilot is going to sit on top of the tenant, the tenant needs to be in decent shape first.

    That means permissions, logging, and a clear view of who can do what. Otherwise the tool just gives people faster access to a system they do not actually understand.

  • ChatGPT Enterprise: My First Steps into AI-Assisted IT

    ChatGPT Enterprise: My First Steps into AI-Assisted IT
    Published: September 25, 2023 (retrospective)

    2023 marked my pivot from 25+ years of pure IT/cybersecurity scripting to blending AI into daily workflows—starting with OpenAI’s ChatGPT Enterprise launch in late August. As a fractional IT Director managing M365 environments and Proxmox homelabs, I was sceptical: could AI handle PowerShell automation without hallucinating disasters? This post recaps those early experiments, wins, and the spark that ignited my AI journey.

    The Catalyst: Enterprise AI Goes Live

    ChatGPT Enterprise dropped on August 28, 2023, promising admin controls, data privacy, and unlimited GPT-4 access—perfect for SME cybersecurity without the free-tier limits. I spun it up immediately for real client work: generating Intune policies, parsing M365 audit logs, and drafting Bash scripts for QNAP backups. No more hours tweaking regex—AI nailed 80% on first try.

    Early tests:
    – Converted manual PowerShell M365 mailbox audits to reusable functions
    – Automated DD-WRT router configs for client VPNs
    – Brainstormed cPanel/WHM hardening checklists

    Key Wins and Pitfalls

    Q3 Milestones:
    September: First AI-generated Intune deployment script—deployed live, zero errors. Saved 4 hours per client.
    October: Ollama early access teased local runs, but cloud GPT-4 crushed complex queries.
    November: GitHub’s generative AI repos tripled to 65k+, inspiring my first LocalLLM-Router sketches.

    Experiment Time Saved Issues Found
    M365 Audits 4h/client Overly verbose outputs
    Intune Policies 2 days/project Needed fact-checking
    Backup Scripts 3h/setup Hallucinated syntax (fixed iteratively)

    Pitfalls taught resilience: AI excelled at boilerplate but flopped on edge cases—my cybersecurity instincts always double-checked outputs.

    Lessons from the Frontlines

    1. Start small: Use AI for scripting grunt work, not strategy.
    2. Local potential: Ollama’s October buzz hinted at cost escapes from cloud tokens.
    3. Governance early: Even then, I logged prompts/outputs for audit trails—foreshadowing SentinelForge.

    ChatGPT Enterprise wasn’t a replacement; it amplified my expertise, prepping 2024’s Control Tower orchestration.

    Ready for AI-secured IT? Contact me for M365 audits or homelab setups.

    Next: GitHub AI Boom and My Homelab Shift (Nov 2023).