Gareth Shaw, CEO Pera Prometheus
Key Takeaways
- Every organisation needs someone who owns security but whether that person is full time or provides fractional support, depends on your size, risk and obligations.
- You have three real choices, which are; a full-time hire, a Fractional Security Manager or an outsourced managed service.
- Fractional is the wrong answer when your size or your risk demands a permanent dedicated function.
- For most organisations that sit in the middle, a Fractional Security Manager gives you real ownership of security without the cost of a full-time salary.
You already know you need someone responsible for security. What you has to be decided is the appropriate level of commitment the role requires, the associated cost, and how to best structure support to meet the needs of the business.
At Pera Prometheus, we provide Fractional Security Managers. This blog post sets out the three ways to resource security leadership, what each really costs and a simple way to choose between them.
When is a Fractional Security Manager the wrong answer?
Let’s start with the cases where fractional support does not fit.
- Scale and Risk. A large organisation or one carrying serious risk every day, needs a dedicated Full Time Employee (FTE). If high profile security decisions are Business as Usual (BaU) activities then a shared resource will be stretched too thin.
- Ownership. Some organisations decide upon fractional support or a managed service arrangement to deal with security risks as part of a flawed mitigation strategy for managing issues. The fundamental reason for this failing is that a business cannot outsource its risks. You can delegate authority but not responsibility, we will come back to why, later.
- Mismatch of Need. If what you actually want is a team to run your firewalls and patch your servers, that is a managed IT issue, not one of security leadership. Hiring a leader when you need hands on IT tools leaves you paying for the wrong tool for the job.
If none of the above describe your situation then a Fractional Security Manager is worthy of further investigation.
The economics people get wrong
A full-time senior security hire with professional knowledge and experience is a five or six-figure annual cost and is a hard role to fill. Nearly half of UK businesses already have a basic information security skills gap, so the people who do this work well, are in short supply and command a premium.
A Fractional Security Manager provides cost effective access to the same professional capability, at a cost that scales to your requirement. You buy the days you need rather than employ an FTE. The mistake some businesses make is selecting on price alone. Each model does a different job, so aim for the right fit, not the lowest number.
An advantage of a Pera Prometheus Fractional Security Manager is that you aren’t just gaining access to one individual’s knowledge and experience – but that of the entire organisation. Pera Prometheus consultants meet weekly and discuss issues or concerns (without divulging specific details) so that our clients benefit from our collective experience.
Why you cannot outsource Accountability
Whichever support model you choose, responsibility for security remains with you and your business. The NCSC is clear that boards and directors have to govern information and cyber risks themselves. They do not need to be technical experts but they cannot pass the accountability to someone else and walk away.
This is the real test of any option. A full-time hire or a Fractional Security Manager can all do the work. Only one question matters when you compare them. What level of trust and confidence do you need that an appropriate level of advice and expert support is being provided to enable you to make diligent business decisions? Ultimately, you are accountable and responsible for all risk in your business.
A simple way to choose your Fractional Security Manager
Here are 5 factors worth considering when making your decision about the benefits of a Fractional Security Manager:
- Organisational Scale. Bigger and more complex businesses point towards a full-time security manager whereas Fractional Security Managers may be a better option for SMEs. However, a Fractional Security Manager can offer niche advice to part of a wider Team in large organisations.
- Risk Appetite. The more damage a breach would do, the more dedicated attention you need. Your risk appetite should determine your decision.
- Legislative and Contractual Obligations. Do contractual commitments or regulations require you to demonstrate consistent security? If you are obliged to maintain recognised certifications such as ISO 27001, Cyber Essentials or Defence Cyber Certification, you may need someone to own and implement a consistent and cohesive implementation strategy to achieve conformance. There is a requirement with all security frameworks to implement a constant programme of security procedures, not just attain a certificate. As an IASME approved Certification Body for Cyber Essentials, Cyber Essentials Plus and DCC Level 0, we see the difference between organisations that do this properly and those who do not.
- Change Management and Supply Chain. If your systems and suppliers change often, you need someone responsible for considering the security implications of these change.
- Your in-house Capability. Be honest about what your current team can and cannot cover. Understand their skills and capability. Unfortunately Pera Prometheus often see situations whereby the HR Manager of IT Director has been given security responsibilities – this isn’t their job and you are setting both them and your business up for failure if you believe it is. If you don’t understand the difference here, get in touch with us, we will train you and build your awareness.
If you map the above considerations to your organisation then you should have a clear understanding on the type of security manager you need. High risk and constant, hire full time. Small with little at stake, a managed service may be enough. The middle ground , where security genuinely matters but a full-time employee cannot be justified, is where Fractional Security Managers deliver value.
Read more: Role of a Fractional Security Manager in the UK Defence Supply Chain, The Three Controls Behind DCC Level 0, Explained.
Conclusion
How much does it cost? This is the wrong question to lead with. The right one is simpler – ‘Who owns our security?’ A Fractional Security Manager will not suit everyone, but for most organisations dwelling on it, it is most likely the right fit. Choose the model that gives you a named security owner and provides you with confidence that security risks are appropriately managed and mitigated and you will have chosen well.
What to do next
Working out how to resource the right security manager is difficult and the wrong choice can be costly both financially and reputationally. Fractional Security Managers are a core capability delivered by Pera Prometheus. As UK military veterans we have a wealth of experience working within MOD, as well as extensive experience supporting commercial clients.
Get in touch and we will talk it through, honestly, before you commit to anything. If we don’t believe that a Fractional Security Manager is right for you, we will tell you.
Frequently Asked Questions
Q: When is a Fractional Security Manager the wrong choice?
A: When your size or risk needs a full-time, dedicated person.
Q: How does the cost of a Fractional Security Manager compare with a full-time hire?
A: It is a much more cost effective approach as you purchase the support days you need rather than pay for an FTE. The saving provided by an Fractional Security Manager is only realised if the model matches your need.
Q: What is the difference between a Fractional Security Manager and a Managed Service?
A: A managed service runs tools and tasks for you. A Fractional Security Manager leads on the management and implementation of your security strategy.
Q: Can we outsource security accountability entirely?
A: No. You can outsource the work but your board keeps the legal and governance responsibility for security, whichever model you choose.
Q: Does the fractional model work for regulated or defence contracts?
A: Yes. A good Fractional Security Manager will implement a robust and resilient security strategy with supporting risk management and mitigation operations to protect your business and satisfy the supply chain expectations of your partners and clients. This will include maintenance of certifications such as; Cyber Essentials, Cyber Security Model, Secure by Design and the DCC. You can see what a Cyber Essentials Plus audit actually involves before you start.
Stay Safe, Stay Secure


