The Fractional CISO Model
A firm of ten to twenty-five staff is too small to justify a security hire and too exposed to go without the function. This is how that function is structured from outside, what it covers, and the parts of it we do not do.
// 01 / The_Role
The problem is a role, not a product
Most small regulated firms already have IT support, and IT support is doing its job: keeping systems running. Security is a different job. It decides what is acceptable risk, writes it down, answers for it when a client or an insurer asks, and keeps the written record current as the firm changes.
Nobody owns that in a fifteen-person practice. It falls to whichever partner last read something alarming. A fractional CISO is that role, held by someone outside the firm, on a defined cadence, at a fraction of a hire.
You keep your existing IT provider. We handle what that provider was never scoped to do, and we name them as control owner in the documentation so the boundary is written down rather than assumed.
// 02 / Coverage
What the engagement covers
Multi-factor authentication enforced on every account including administrators and service accounts, which is the exclusion most often found open. Conditional access constrains where and from which devices staff sign in. Privileged access is reviewed at each quarterly review and offboarding runs from a written procedure.
Microsoft Defender configured to a documented baseline, then reconciled against your actual staff roster. Update status is confirmed at the endpoint rather than taken from a deployment log. The common failure is not a missed detection, it is three laptops nobody knew were unmanaged.
A Written Information Security Program that describes the firm as it actually operates, an incident response plan, a service provider register under 314.4(f), and an AI acceptable use policy. A plan that no longer describes your firm reads to a regulator as no plan at all.
Client security questionnaires and vendor diligence forms completed by the person who runs your controls, with the evidence behind each answer and a written list of anything you had to answer no to.
// 03 / Cadence
The cadence
This is the part worth reading twice, because it is where outside security functions are usually oversold.
Microsoft Defender, Entra ID, and Purview run without pause and log without pause. That is the licence doing its work, and it does not stop when we do.
Alert review and response run on a defined business-hours cadence. One person cannot watch a console overnight through filing season, and a vendor who says otherwise is describing a staffing model they do not have.
One standing commitment: a quarterly posture review with leadership. What changed, what is open, what is scheduled, and what it would take to close it.
// 04 / Maintenance
What maintenance adds
A cadence on its own sounds like somebody checking that nothing broke. That is the smaller half of it.
On the quarterly cadence the environment grows. New agents reach your tenant in the quarter they ship. New gallery prompts and short notes on what Microsoft changed go out as they are written. Governance is never tiered: every firm gets all of it at deployment. Maintenance is the environment as it gets better.
// 05 / Boundaries
What we do not do
Stated plainly, because the gap between what a small firm needs and what one outside advisor can deliver is exactly where engagements go wrong.
- We do not monitor a console around the clock, and we do not run a help desk. Where a firm needs eyes on a screen overnight, it needs a managed detection provider, and we will say so rather than sell around it.
- We do not deploy patches. Category II is oversight and evidence: known-exploited vulnerabilities are surfaced and tracked to closure with per-endpoint evidence, and your IT provider does the deploying.
- We do not audit, certify, or attest. Those are terms of art belonging to licensed firms. Claremont performs assessments and produces documentation you can hand to whoever asks.
- We do not run phishing simulations. No platform for it is in place. If that is a requirement, say so early and we will tell you who does it.
- We do not take two engagements at once beyond capacity. Two simultaneous engagements is the honest ceiling. If the calendar is full you will be told, not queued quietly.
// 06 / Prerequisite
What it runs on
Microsoft 365 Business Premium. Business Standard includes neither Intune nor Defender for Business, so this engagement cannot be delivered on it. That is a prerequisite, not an upsell, and it is the same plan the rest of the site names. If you are unsure which you hold, the licensing brief walks the comparison.
Enterprise tiers are not required. A firm of this size does not need E5 to hold a defensible posture, and being told it does is usually a sign the advice was written for a larger firm.
Fees are flat monthly, set by your firm's size band, scoped in writing before work begins. No hourly meters. Full engagement structure and fees.
// 07 / Next_Step
Whether this fits your firm
Thirty minutes, free, on what you hold and what is already in place. If the gap is small enough that your existing provider can close it, that is what you will be told.
