Virtual & fractional CISO

Board-level security leadership, without the full-time hire.

Annansec embeds an experienced security leader into your business to own what most organisations struggle to resource: setting direction, managing risk, and giving your board and your customers confidence that cyber is under control.

Governance · Risk · Assurance

Four things we own, so you do not have to hire for them.

Every engagement is a named, scoped piece of work with defined deliverables. No open-ended consulting, no day-rate drift.

Virtual & fractional CISO

Accountable security leadership on a monthly retainer, sized to what your business actually needs.

  • Board and investor reporting
  • Risk ownership and roadmap
  • Customer assurance and audits

Governance, risk & assurance

The function itself: frameworks, registers, policy architecture and the evidence to back them.

  • Risk framework and register
  • Policy architecture
  • Security operating model

Certification readiness

Certification treated as a commercial deadline, because that is usually what it is.

  • ISO 27001 and SOC 2
  • Cyber Essentials and Plus
  • PCI DSS v4.0 and UK GDPR

Supply chain assurance

Your suppliers hold your data and your obligations. Most assurance programmes cannot prove it.

  • Third-party risk framework
  • Supplier tiering and assessment
  • Contractual and audit evidence

Why security gets expensive later

Most scale-ups hire IT before they hire security. That is the right call.

The problem is what happens next.

The decisions your IT function makes in its first two years quietly determine what your first certification will cost and how long your first enterprise security review will take.

How identity is architected. How devices and access are provisioned, and revoked. Which suppliers touch customer data, and what was actually agreed with them. What gets logged, and for how long.

None of these are security decisions when they are made. They only become security decisions later, when somebody asks for evidence.

Three decisions from one business. All sensible at the time. All made by competent people.

DecidedBuy a standalone endpoint security product.

Found out laterEquivalent protection was already included in licensing it owned, alongside two controls it had been separately quoted to buy.

DecidedDeploy it, and leave the default configuration alone.

Found out laterThe detection features it was paying for had never been switched on, leaving it blind to targeted intrusion.

DecidedLet a supplier operate the card payment estate.

Found out laterOutsourcing the operation had not outsourced the accountability, and none of the supplier evidence was held.

Nobody was deferring compliance. There was simply no one in the room translating operational decisions into assurance consequences. That is the job we do.

The engagement arc

Assess, prioritise, lead, assure.

Most engagements start small and deliberately. We land on a fixed-fee piece of work with a board-visible output, then take ownership of what it recommends.

01 · Assess

Find the gap

Two to three weeks, fixed fee. We map your estate, suppliers and configuration against the certification you will need within eighteen months.

02 · Prioritise

Sequence the work

A named, costed set of gaps in the order they should be closed, with the exposure quantified. Written for a board, not for engineers.

03 · Lead

Own the roadmap

We take accountability for delivery: your risk register, your policy set, your auditor and customer conversations, your board reporting.

04 · Assure

Prove it holds

Certification achieved and maintained, questionnaires answered, supplier evidence held, diligence survived without a scramble.

Typical first engagement

An IT and Assurance Alignment Review. Two to three weeks, fixed fee, delivered as a board-ready paper. Most clients move to a retainer at the end of it, because the roadmap needs an owner.

Case study

The security you are already paying for.

A UK multi-site consumer business asked a procurement question: should we renew our endpoint security subscription? The answer took ten minutes. What surfaced while checking took the rest of the engagement.

01

Duplicate spend

A premium subscription paid annually, while equivalent protection sat unused inside enterprise licensing the business already owned, alongside privileged access controls and data loss prevention it had been separately quoted to buy.

02

Detection switched off

The product it was already paying for ran with only basic anti-virus enabled. The features that detect a genuine intruder were licensed, paid for, and disabled. No decision, no risk acceptance, just a default nobody revisited.

03

Accountability without evidence

The card payment estate was operated by a third party. The business remained answerable to its acquiring bank for it, and held none of the supplier evidence required to demonstrate that position.

Competent IT. A working estate. And still a gap, because nobody owned the translation between what operations does and what assurance requires. Five decisions went to the board within four pages.
None of this was a tooling failure

Three ordinary operational decisions, made competently, for sensible reasons. All three had assurance consequences nobody was tracking. Two cost nothing to fix once found.

Retainers

Published pricing, because you should not need a call to find out.

Retainers are sized by monthly days, not by headcount you are replacing. Projects are scoped and quoted individually.

Advisory From £3,500per month 2-3 days per month
  • Board and exec risk reporting
  • Risk register ownership
  • Security questionnaire support
  • Named point of escalation
Most common Programme From £7,000per month 5-8 days per month
  • Everything in Advisory
  • Roadmap ownership and delivery
  • Certification programme leadership
  • Supplier and audit management
Embedded From £14,000per month 10-15 days per month
  • Everything in Programme
  • Regulated and high-growth environments
  • Investor and diligence representation
  • Incident readiness and response
Projects are quoted, not listed

Alignment reviews, certification programmes, supply chain assurance and due diligence are scoped to your situation. Every one is fixed fee with written change control, so the number you agree is the number you pay.

About Annansec

A small crew, working the frontier the large firms find hard to reach.

Annansec exists because the organisations that most need security leadership are usually the ones least able to justify a full-time hire. They are growing quickly, selling into buyers who ask hard questions, and running on a technology estate assembled faster than it was governed.

We are deliberately small. That is the point: you get the person who did the work, not a team assembled around a proposal.

Where the experience comes from

  • Director of Security, global consumer platform
  • Head of Cyber Oversight, FTSE insurer
  • Head of Security Architecture and Design
  • Principal Consultant and QSA, cyber consultancy

How we work

  • Fixed scope, fixed fee, written change control
  • Board-legible output as standard
  • We refer the work we should not do
  • Contributor to national cyber working groups

Start here

Twenty minutes, and no pitch.

Tell us what is blocked, who is asking, and when they need an answer. If we are not the right people, we will say so and point you to who is.

Conversations are confidential. We do not need your data to have the first one.