Fractional CISO: Fractional Security or Strategic Advantage?
Download resourcesAbout this session
Martin Lemay, Chief Security Officer at Devolutions and founder of the vCISO firm CyberSpective, spent fifteen years as a penetration tester before becoming a full-time CISO, and argues the fractional or virtual CISO role is often confused with the in-house CISO despite real differences in accountability, presence and scope. He contrasts a vCISO, hired for strategic planning, risk framing (Quebec's Law 25 comes up repeatedly) and compliance on a limited number of hours a month, with a full CISO's continuous operational oversight, culture-building and accountability for decisions, and warns that vCISO contracts usually include liability waivers a client may not fully register. Practical threads include using ISO 27001 or SOC 2 certification to shortcut lengthy security questionnaires instead of answering hundreds of items by hand, treating an all-green questionnaire as a red flag rather than reassurance, and front-loading a new vCISO engagement with consecutive days on-site to build trust before dropping to a lighter weekly cadence. He closes with United States CISO compensation figures, noting Canadian pay runs lower, and fields questions on gaining executive access as an outside consultant and the risk of future non-compete clauses.
The role of the Chief Information Security Officer (CISO) is evolving, with many organizations turning to Fractional CISOs (or vCISOs) to provide leadership and expertise on a part-time basis. This approach offers cost-effective access to high-level security talent, but it also raises questions about consistency, integration, and the potential for a “fractional“ security posture. In this talk, we will explore the confusion and controversy surrounding the Fractional CISO model, examining its benefits, challenges, and the impact it can have on an organization's overall security strategy. Attendees will gain insights into whether a Fractional CISO is a practical solution for their security needs or if it leads to a diluted security approach.
Key takeaways
- Clarify accountability in writing before engaging a vCISO: most vCISO contracts carry a liability waiver on strategic recommendations that a full-time CISO does not have.
- Offer ISO 27001 or SOC 2 certification in place of lengthy security questionnaires; a certificate that proves third-party validation moves faster than answering 300 items by hand.
- Treat an all-green vendor security questionnaire with suspicion rather than comfort; it more often signals boxes checked than genuine coverage.
- Front-load a new vCISO engagement with several consecutive days on-site to build relationships and understand the business before shifting to a lighter weekly or biweekly cadence.
- Match the model to the business: high-velocity, risk-tolerant companies suit a vCISO's flexibility, while businesses wanting embedded culture and constant monitoring need a full-time CISO.
Speakers

With nearly 15 years of experience in the IT and cybersecurity field, Martin Lemay has successfully bridged the gap between technical expertise and strategic leadership. Starting from a robust technical foundation, Martin has seamlessly transitioned… Read moreRead less
With nearly 15 years of experience in the IT and cybersecurity field, Martin Lemay has successfully bridged the gap between technical expertise and strategic leadership. Starting from a robust technical foundation, Martin has seamlessly transitioned into project management and executive roles, where he has designed, planned, implemented, and tracked comprehensive cybersecurity programs from the ground up. His initiatives are meticulously aligned with industry-leading standards such as ISO/IEC 27001, NIST CSF, CIS Controls, and CyberSecure Canada. Martin’s deep technical knowledge, combined with his executive experience, uniquely positions him to communicate and advocate for cybersecurity initiatives across diverse audiences. Whether addressing technical teams, executive boards, or stakeholders with varying levels of expertise, Martin excels at translating complex cybersecurity concepts into actionable strategies, ensuring that security is understood and prioritized at all levels of the organization.
