Does anyone have or know of someone that has experience entering the virtual/fractional CISO business? That is the direction Iām headed and have some questions.
@jerry depends on what your looking for. I am technically a fractional CISO but nothing like your skill level.
I would say you would be great in the role. Biggest thing is to find the client fit you want, the amount of hours you want to work, and the dollars needed to live.
I average 12-16 month projects, mostly compliance based, come in ramp the team, get audited, move on.
I personally like working a 10 hour minimum retainer per client monthly and choose the amount I want to work.
Also, do not expect to get deep in the work, you will be a wide range knowledge source so meetings, risk management, convincing leaders to invest.