Virtual & fractional CISO
Accountable security leadership on a monthly retainer, sized to what your business actually needs.
- Board and investor reporting
- Risk ownership and roadmap
- Customer assurance and audits
Virtual & fractional CISO
Annansec embeds an experienced security leader into your business to own what most organisations struggle to resource: setting direction, managing risk, and giving your board and your customers confidence that cyber is under control.
Governance · Risk · Assurance
Every engagement is a named, scoped piece of work with defined deliverables. No open-ended consulting, no day-rate drift.
Accountable security leadership on a monthly retainer, sized to what your business actually needs.
The function itself: frameworks, registers, policy architecture and the evidence to back them.
Certification treated as a commercial deadline, because that is usually what it is.
Your suppliers hold your data and your obligations. Most assurance programmes cannot prove it.
Why security gets expensive later
The problem is what happens next.
The decisions your IT function makes in its first two years quietly determine what your first certification will cost and how long your first enterprise security review will take.
How identity is architected. How devices and access are provisioned, and revoked. Which suppliers touch customer data, and what was actually agreed with them. What gets logged, and for how long.
None of these are security decisions when they are made. They only become security decisions later, when somebody asks for evidence.
Three decisions from one business. All sensible at the time. All made by competent people.
Found out laterEquivalent protection was already included in licensing it owned, alongside two controls it had been separately quoted to buy.
Found out laterThe detection features it was paying for had never been switched on, leaving it blind to targeted intrusion.
Found out laterOutsourcing the operation had not outsourced the accountability, and none of the supplier evidence was held.
Nobody was deferring compliance. There was simply no one in the room translating operational decisions into assurance consequences. That is the job we do.
The engagement arc
Most engagements start small and deliberately. We land on a fixed-fee piece of work with a board-visible output, then take ownership of what it recommends.
Two to three weeks, fixed fee. We map your estate, suppliers and configuration against the certification you will need within eighteen months.
A named, costed set of gaps in the order they should be closed, with the exposure quantified. Written for a board, not for engineers.
We take accountability for delivery: your risk register, your policy set, your auditor and customer conversations, your board reporting.
Certification achieved and maintained, questionnaires answered, supplier evidence held, diligence survived without a scramble.
An IT and Assurance Alignment Review. Two to three weeks, fixed fee, delivered as a board-ready paper. Most clients move to a retainer at the end of it, because the roadmap needs an owner.
Case study
A UK multi-site consumer business asked a procurement question: should we renew our endpoint security subscription? The answer took ten minutes. What surfaced while checking took the rest of the engagement.
A premium subscription paid annually, while equivalent protection sat unused inside enterprise licensing the business already owned, alongside privileged access controls and data loss prevention it had been separately quoted to buy.
The product it was already paying for ran with only basic anti-virus enabled. The features that detect a genuine intruder were licensed, paid for, and disabled. No decision, no risk acceptance, just a default nobody revisited.
The card payment estate was operated by a third party. The business remained answerable to its acquiring bank for it, and held none of the supplier evidence required to demonstrate that position.
Competent IT. A working estate. And still a gap, because nobody owned the translation between what operations does and what assurance requires. Five decisions went to the board within four pages.
Three ordinary operational decisions, made competently, for sensible reasons. All three had assurance consequences nobody was tracking. Two cost nothing to fix once found.
Retainers
Retainers are sized by monthly days, not by headcount you are replacing. Projects are scoped and quoted individually.
Alignment reviews, certification programmes, supply chain assurance and due diligence are scoped to your situation. Every one is fixed fee with written change control, so the number you agree is the number you pay.
About Annansec
Annansec exists because the organisations that most need security leadership are usually the ones least able to justify a full-time hire. They are growing quickly, selling into buyers who ask hard questions, and running on a technology estate assembled faster than it was governed.
We are deliberately small. That is the point: you get the person who did the work, not a team assembled around a proposal.
Start here
Tell us what is blocked, who is asking, and when they need an answer. If we are not the right people, we will say so and point you to who is.
Conversations are confidential. We do not need your data to have the first one.