Enigma Partners Global

Fractional CISO

Senior security leadership, shaped around your organisation.

You may need your first security leader, or your existing CISO may need more senior support. Douglas Trainer works with your leadership and technical teams to understand the risks, agree priorities and help move the work forward.

Both fractional CISO and CISO support are flexible monthly retainers, usually 2–8 days per month. Our target clients are organisations with 50+ employees, with no upper headcount limit. The scope and working pattern depend on what your organisation needs.

The gap

Someone in your business has just been handed security. Often a finance director, an operations lead, a company secretary, or an IT manager who already has a full job.

The trigger is usually real and recent: a GDPR worry, a tender lost over a security questionnaire, an insurer asking for evidence, or a board asking about AI. There is no framework, no named expert, and no time.

None of that means you have done anything wrong. It means the help on offer has not matched what businesses your size actually need. That is the gap we fill.

What you get each month

The scope is agreed around your needs and available days. Typical areas of work include:

  • A named senior adviser, leading your security programme or supporting your existing CISO.
  • Agreed senior security time, usually 2–8 days per month, focused on your priorities.
  • A live risk register and remediation tracker, kept current and reported against.
  • One governance document produced or refreshed each month: a policy, an incident response plan, a business continuity outline, or an AI acceptable use standard.
  • A one-page executive briefing suitable for a finance director, a lawyer, or a board.
  • Readiness support for client security questionnaires and cyber insurance renewals.
  • Advisory support during a security or data incident: triage and clear direction when it matters, not a 24/7 operations centre.

Pricing

The published examples below show different levels of support. Both services usually run from 2–8 days per month. We agree a monthly fee against the scope and time required; arrangements outside these examples are quoted individually. Every level is month to month, invoiced monthly in advance, with 30 days notice. No long lock-in.

£1,250 / month

A day every other week

Organisations with 50+ employees wanting a named security lead and a defensible baseline.

Most common

£1,995 / month

A day a week

Mid-size firms with no in-house security, an active cloud IT environment, and real exposure to manage.

£3,750 / month

5 to 6 days a month

Firms facing board, client-assurance or regulatory scrutiny who want boardroom attendance and an incident retainer.

What sits outside the arrangement, and we will say so plainly: hands-on remediation and configuration (we advise, your IT team or a named Enigma consultant implements under a separate line); penetration testing and IT health checks (scoped separately with a CREST or CHECK partner); formal certification audits; and 24/7 incident response.

Start with an audit

£2,950

Cloud Security Baseline. Fixed fee.

You do not have to commit to an ongoing arrangement to work with us. Most firms start with a fixed-fee Cloud Security Baseline audit. It is a two-week diagnostic across your cloud IT environment, whether you run Microsoft 365, Google Workspace, or another stack: identity, external sharing, device management, data loss prevention, email security, and how AI is being used.

You receive a full audit report, a one-page executive briefing written for a board, and a prioritised remediation tracker. It is genuinely useful on its own, and it tends to show a clear ongoing need.

If you move into an ongoing arrangement within 30 days, we credit the full £2,950 audit fee against your first two months. So you are never paying twice to get started.

Who you are working with

The work is led by Douglas Trainer, Managing Partner. Fourteen years in British Army Intelligence, where actionable intelligence mattered more than raw data.

ISO/IEC 27001

Lead Auditor and Lead Implementer, IBITGQ certified

ISO 27005

Risk Manager, certified

CIISec

Chartered Institute of Information Security, member

British Army

Intelligence Corps, 14 years, three operational deployments

Who it is for

  • Organisations with 50+ employees, with no in-house security lead.
  • Businesses running on a cloud IT environment, such as Microsoft 365 or Google Workspace, as the backbone of the operation.
  • A capable non-specialist who has just inherited security and needs a framework and a partner.
  • Heritage and luxury manufacturing, professional services such as law and accountancy, property and estate agencies, specialist distributors, and long-established family firms with a modern compliance problem.

Common questions

We already have a CISO. Is this for us?

Yes. CISO support provides additional senior capacity alongside your existing security leader: a second opinion, help with a defined programme or support during a busy period. Both services usually involve 2–8 days per month on a flexible monthly retainer. We agree the priorities, duration and working pattern with you.

How is this different from our MSP or our IT provider?

Your IT provider keeps things running. They patch, they fix, they answer the helpdesk ticket. That is real work and you need it. What they rarely do is step back and own the security picture: what your actual risks are, what a client or an insurer will ask for, what to tell the board. A Fractional CISO fills that gap. We are the named security lead who thinks about the whole thing, writes it down, and keeps it current. We work alongside your IT provider, not instead of them.

We already have cyber insurance and Cyber Essentials. Do we still need this?

Those are a good start, and if you have them you are ahead of many firms your size. They tend to be a snapshot, though: true on the day you signed, then slowly out of date. A policy or a certificate does not maintain your risk register, answer a client security questionnaire, or brief your board when someone asks about AI. That ongoing ownership is the part most mid-sized firms are missing, and it is the part we provide.

What if we only need help for a few months?

That is fine, and it is honest to say so up front. Every level is month to month with 30 days' notice. Plenty of firms start with the fixed-fee Cloud Security Baseline audit at £2,950, act on the findings, and stop there. Others use a few months of support to get through an insurance renewal or a big client's due diligence, then pause. You are not signing into a long contract. You keep it while it is useful to you.

What exactly do we get for £1,995 a month?

The £1,995 monthly example provides about a day of senior security time a week. Both services usually range from 2–8 days per month; the fee and deliverables are agreed against your scope. You get a named security lead of record, a live risk register and remediation tracker that we maintain and report against, and one governance document produced or refreshed each month. You also get an executive one-page briefing suitable for a finance director, a lawyer, or a board, plus support when a client security questionnaire or a cyber insurance renewal lands on your desk. The exact monthly price reflects the size and complexity of your organisation.

Do you do the technical fixes yourselves?

We advise on what needs to change and in what order. The hands-on configuration is done by your own IT team or by a named Enigma consultant under a separate line, so the work is clear and the billing is clear. Penetration testing and IT health checks are scoped separately and delivered with a CREST or CHECK partner. We are honest about this because a security lead who marks their own homework is not much use to you.

How quickly can you start?

The Cloud Security Baseline audit is a two-week diagnostic across your cloud IT environment, whether you run Microsoft 365, Google Workspace, or another stack: identity, external sharing, device management, data loss prevention, email security, and how AI is being used. You get an audit report, a one-page executive briefing, and a prioritised remediation tracker. If you take an ongoing arrangement within 30 days, we credit the £2,950 audit fee against your first two months. From there, ongoing support usually begins the following month.

What happens if we have an incident?

You get advisory support during a security or data incident: triage, clear direction, and help deciding what to do and who to tell. To be plain about the limit, this is not a 24/7 security operations centre. It is a calm, experienced hand on the tiller when something goes wrong, which for most mid-sized firms is exactly what has been missing at the worst possible moment.

Not sure whether this is your gap yet?

Take the free readiness checklist. Seventeen questions, ten minutes, and an honest score you can keep. If it points to a real gap, a short call is the next step. No pressure, no pitch.