// FRACTIONAL SECURITY ARCHITECT · HANS STUDY · ONTARIO, CANADA

Fractional security architect

For a firm with an IT lead or an MSP already running day to day, but nobody senior enough to own segmentation, firewall policy, a security-system network, or the OT sitting beside it. This is a hands-on design and review retainer, not an executive seat. The work shows up in the firewall rule base and the switch configs, not just in a slide deck.

The gap this fills

Most firms this size have someone capable of keeping the lights on. Patching happens, tickets get closed, and the MSP answers the phone. What's usually missing is a second set of senior eyes on the decisions that are expensive to get wrong: where a new VLAN gets drawn, whether a change to the firewall policy actually closes the gap it's meant to, and whether the integrator's proposed design for the camera network holds up once it's live.

A fractional CISO owns the program and reports to the board. This role sits a level below that, closer to the configuration itself, and it's built for firms that need the second role before they need the first.

What the retainer covers

Design and change review

A second look at network and security changes before they go live: new segments, firewall rule changes, VPN and remote access additions, and anything touching the security-system network.

Hardening standards

A written baseline for switches, firewalls, servers, and the security-system network, so the MSP or IT lead has a standard to configure against instead of defaults.

Integrator oversight

Reviewing a Genetec or access control integrator's proposed design, checking the as-built against what was promised, and attending the calls where the technical decisions actually get made.

Hands-on configuration

Not every month is review only. Some months the work is a firewall policy rewritten directly, a VLAN scheme implemented, or a segmentation project carried through to the switch configs.

What it excludes

  • Governance and board reporting. That sits on the fractional CISO retainer, one level up.
  • Compliance programs such as CPCSC, CMMC, or ISO 27001 ownership, which run as their own engagements.
  • Helpdesk and end-user support, which stays with your IT lead or MSP.

Price

Starting at $2,250 a month.

CAD, plus HST.

Remote delivery via the DHD, a remote access device. Terms apply.

Where this sits next to the rest of the practice

When the gap is strategic, a written security program, board reporting, and compliance ownership, that's fractional CISO work. When the gap is day-to-day monitoring, patching, and maintenance on infrastructure that's already well designed, that's managed network and server support. This retainer sits between the two: senior design judgment applied to a network an IT lead or MSP is already operating, without taking over either of the other two jobs.

A second senior opinion, on retainer

A scoping call covers what the environment looks like today and what size of retainer fits it.