You don't have a CISO. Your customers, your insurer and your regulators are acting as if you do.

I'm the fractional CISO for companies of 100 to 1000 people. Three days a month, one point of contact, plain English and French. You get control over security without hiring a security team.

Book a 30-minute diagnostic
Free, no commitment, and I'll tell you whether I can help.
Or send me a message if you prefer.
Fabien Soulis
that's me 👋
sound familiar?

What I see in almost every company I talk to

Every one of these is a business problem.
A revenue, contract or liability problem wearing a technical costume.

why it happens

It's not a tooling gap. It's an empty seat.

Your IT team and your provider execute. They're good at it. But nobody owns the question "what are we protecting, in what order, and who decides?" A full-time CISO costs €120,000 to €160,000 loaded, is nearly impossible to hire, and at your size would be bored half the month.

So every questionnaire becomes a fire drill, every renewal becomes a gamble, and every new standard or law your customers mention is another word that scares you instead of a plan.

The seat needs someone who knows what they're doing in it, three days a month, every month.

My offer

Fractional CISO · 3 days a month · €4,000/month · 6-month engagement

Everything below is included.

  • A 30-day assessment: what's in place, what's missing, what actually exposes you. One page for your leadership team, not an 80-page report.
  • A 6-month roadmap, prioritized by business risk and mapped to the standards your customers and your market actually ask about.
  • Direction for your IT provider: three priorities at a time, not thirty. I speak their language, so you stop translating.
  • Customer and insurer questionnaires answered within 48 hours: you forward, I answer, you sign.
  • A number to call the day something goes wrong, and a written plan for that day, prepared before it arrives.
  • A 45-minute monthly review with the CEO, in plain language, with three numbers and one decision to make.
ISO 27001 SOC 2 GDPR Your sector's regulations Cyber-insurance requirements

If your situation doesn't fit this format, I'll tell you in 30 minutes and point you somewhere better.

concrete outcomes

Six months in, here's what you have

A file you can send anyone

A security file you can send to any customer, auditor or insurer without sweating.

A clear answer on the rules

Which laws and standards apply to you, which don't, and where you stand against each one.

An IT provider on the right things

Working on what matters, in the right order, and an IT invoice you understand.

A CEO with an answer

You can say, in one sentence, what happens if your systems are encrypted tomorrow.

why me

Why me and not a consulting firm

Fifteen years in enterprise IT security across finance, retail and industry, the last seven as a security architect on global strategic projects. I use a method that successful CISOs run and that I taught at Paris 1 Panthéon-Sorbonne. I build the tools you need to manage your security the way auditors ask for it. I know what security looks like when it's done properly in a large group, and I know how to scale it down to a company your size without turning it into a caricature.

I take on 3 companies at a time, no more.
Beyond that you're a consultant sending slides.

where this method is used

I taught employees of these organizations how to manage a company's security.

Vinci
BNP Paribas
Thales Group
KPMG
PwC
Siemens
Airbus
Saint-Gobain
Bouygues
EDF
Accenture
Vinci
BNP Paribas
Thales Group
KPMG
PwC
Siemens
Airbus
Saint-Gobain
Bouygues
EDF
Accenture
what you're probably thinking

Four fair questions

"We already have an IT provider."

Good. They stay, and I give them priorities. They'll do a better job.

"We're not sure which regulations apply to us."

That's the first thing we settle. And regardless of the law, your customers and your insurer are already asking the same questions.

"€4,000 a month is an employee's salary."

It's the price of three days of a profile you won't manage to hire, with no payroll costs, no probation period, and cancellable after six months.

"What if we only need you for one questionnaire?"

Then we don't sign. The diagnostic is free, I'll tell you what to do, and you'll do it yourself or with someone else.

another way we can work together

Your team may be ready to take this on.

Some companies don't need someone to run their security. The people are already there, and with the right method they can carry it themselves.

That's a different offer: four weeks, real projects, with your consultants or employees. They learn how to manage risk the way regulation and auditors ask for it.

See the training program
Fabien Soulis
let's talk 👋

30 minutes to find out where you stand

You tell me how security decisions actually get made, what your customers are asking, what worries you. At the end of the call I'll tell you whether I can help, how, and if it's not me, who to talk to.

Book a 30-minute diagnostic
Or send me a message if you prefer.
Fabien
Fabien Soulis · Security Architect · LinkedIn