Most clients complete the SMB Security Sprint before moving to the vCISO Retainer. New to ALC?  Start with the Sprint →
Ongoing Engagement

Fractional CISO Retainer

Security leadership isn't a project — it's a function. The Fractional CISO Retainer gives your organization an experienced security executive on an ongoing basis, without the cost of a full-time hire.

Monthly advisory & monitoring
Direct access to the founder
Built on your Sprint roadmap
No junior staff. No handoffs.

What's included every month

Every retainer engagement includes the following. Scope is consistent. You always know what you're getting.

Monthly Leadership Call

Security Briefing & Advisory

A dedicated monthly session to review your security posture, discuss emerging risks relevant to your industry, and advise on decisions that have a security dimension — vendor selection, new technology, staff changes, and more.

Ongoing Risk Monitoring

Risk Register Maintenance

Your risk register stays current. New risks are added as they emerge, existing items are tracked to resolution, and you always have an accurate picture of where your organization stands relative to the roadmap.

Policy & Documentation

Policy Development & Review

Security policies are living documents. The retainer includes ongoing review, updates as your business changes, and development of new policies as gaps are identified. Policies are written for your organization, not pulled from a template library.

Vendor & Technology Advisory

Security Stack Guidance

Evaluating a new vendor? Adding a SaaS tool? Considering a new IT provider? You get a security lens on those decisions before they're made — not after a problem surfaces.

Incident Response

First-Call Support

When something goes wrong, you have a number to call. Incident response planning is maintained on an ongoing basis, and you have direct access for first-call advisory during an active incident.

Compliance & Regulatory

Ongoing Compliance Guidance

Regulatory requirements change. Vendor compliance obligations evolve. The retainer includes ongoing advisory on compliance posture, helping you stay ahead of requirements rather than scrambling to meet them.

How the engagement runs

The retainer follows a structured cadence so your security program is managed proactively, not reactively.

Monthly
  • Security leadership briefing (60 minutes)
  • Risk register review and updates
  • Open advisory items and decisions
  • As-needed advisory between sessions (email/phone)
Quarterly
  • Full program review against the Sprint roadmap
  • Roadmap update — priorities adjusted as the business evolves
  • Threat landscape review relevant to your industry
  • Executive summary for leadership or board reporting
As Needed
  • Incident response advisory and support
  • Vendor and technology security reviews
  • Staff security awareness guidance
  • Compliance and regulatory questions

The Sprint is the entry point

The Fractional CISO Retainer is built on the foundation established during the SMB Security Sprint. Here's why that matters.

Why the Sprint comes first

Every retainer engagement begins with a complete understanding of your organization's current security posture — your risks, your gaps, your existing controls, and your priorities. The Sprint produces exactly that: a risk assessment, NIST CSF gap analysis, and a written security roadmap tailored to your business.

That roadmap becomes the retainer work plan. Rather than spending the first several months of an ongoing engagement learning your environment, we begin the retainer with a clear, agreed-upon baseline and a defined set of priorities to work toward. Faster time to value. No redundant discovery work on your dime.

Sprint clients have priority access to retainer onboarding. If you've completed the Sprint and want to move into an ongoing engagement, that conversation starts with your existing roadmap — not a blank page.

Learn more about the SMB Security Sprint →

Is this the right engagement?

The retainer works best in specific situations. Be honest about where your organization is before reaching out.

Good fit

  • You've completed the SMB Security Sprint and want ongoing implementation support
  • You operate in a regulated industry (healthcare, finance, government contracting) with ongoing compliance obligations
  • You handle sensitive customer or financial data and need ongoing oversight
  • You've had a security incident or near-miss and want consistent leadership going forward
  • Your board or investors expect documented security governance
  • You're growing and security complexity is increasing faster than your internal capacity

Not a fit

  • You haven't completed the SMB Security Sprint or an equivalent recent assessment we can validate — start with the Sprint
  • You're looking for someone to manage your IT infrastructure (that's a different service)
  • You need a full-time CISO on-site five days a week
  • You want security handled without executive leadership involvement — the retainer requires your time
  • You're under 10 employees with no sensitive data obligations

How to get started

The path into the retainer is straightforward. It begins with a conversation.

1
Complete the SMB Security Sprint
If you haven't done the Sprint, that's the starting point. The Sprint produces the foundational assessment and roadmap the retainer is built on. Learn about the Sprint →
2
Schedule a retainer conversation
If you're a Sprint graduate ready to move into an ongoing engagement, reach out. We'll review your roadmap together and discuss what the retainer looks like for your organization specifically.
3
Agree on scope and engagement terms
Retainer engagements start at $1,500/mo. Scope and final pricing are based on your organization's size, complexity, and the current state of your roadmap. We'll have a direct conversation about what makes sense for your situation.
4
Begin the first monthly cadence
Onboarding is fast because the Sprint already established the baseline. We start the first monthly session reviewing roadmap priorities and setting the first 90-day action plan.

Ready to move beyond the Sprint?

If you've completed the SMB Security Sprint and want to discuss ongoing engagement, reach out. Engagements start at $1,500/mo — scope and final pricing are tailored to your organization.

Get in Touch →

No obligation. Direct conversation with Adam — not a sales team.