Skip to content
Blackhole Cyberstrategy Book a fit call

Level 03 · Mandate

Fractional CISO Services

A defined mandate for organizations ready to delegate security strategy, governance, reporting, and program accountability. A named security leader — for a scope written down before the work starts.

Written mandate Named authority Defined reporting line

The mandate, in writing

Fractional CISO responsibilities begin with an explicit mandate: defined authority, reporting expectations, and accountable outcomes. Outside such a mandate, the role is advisory.

SCOPE

What the role owns — strategy, governance, reporting, program accountability — and, just as explicitly, what it does not.

AUTHORITY

The decisions the role can make alone, the ones it escalates, and who it escalates them to. Budget authority stays with you.

REPORTING

A named reporting line and a fixed rhythm of executive and board reporting, so accountability is visible — not assumed.

The mandate document is drafted together before the engagement starts, and revisited at every renewal.

Who owns what

I own

Strategy, governance, reporting, and program accountability in scope

You keep

Budget authority and anything outside the written scope

For

Organizations that need a named, accountable security leader before a full-time hire makes sense

Not for

Regulated financial, healthcare, or safety-critical operators — I will point you toward firms built for those obligations

Is a mandate the right size?

Most organizations need less than they think. The 2-minute fit check gives you an honest answer before we talk scope.

Start the fit check