Fractional CISO Leadership for Mid-Size Regulated Businesses
When the board, your insurer or a customer asks “are we OK?”, you need an answer you can stand behind. IronGate provides CISO-grade security leadership on retainer — a clear roadmap, obligations mapped, board-ready answers — plus the governance to adopt AI safely. Principal-led, senior practitioners accountable for outcomes, not graduate consultants.
Our core services
Core service 01
Fractional CISO (vCISO)
A $300K-plus full-time CISO is a hire most mid-size companies cannot keep busy. We carry the strategy, the board narrative and the accountability as a fractional appointment.
- Three tiers — $5,500 / $11,000 / $19,000 + GST per month
- From light advisory to embedded leadership
- Obligations mapped — CPS 230, CPS 234, SOCI, Essential Eight
- Board & executive reporting
Core service 02
Fixed-Fee Security Assessments
Principal-led, two-week assessments with a fixed scope, a fixed price and a fixed delivery date — a board-ready view of where your security actually stands, without a procurement panel.
- Security Solution Assessment — $9,500 + GST
- Security Architecture Maturity — $19,000 + GST
- AI Readiness Security — $19,000 + GST
- Two weeks, fixed scope, no panel required
Core service 03
AI Security & Governance
Adopt AI fast without creating tomorrow’s incident. We put the governance, controls and architecture patterns around AI so the board can say yes with confidence.
- AI governance & acceptable-use frameworks
- Controls for data flowing into and out of AI
- AI security architecture patterns
- AI Readiness Security Assessment — $19,000 + GST
Not ready to talk? Start with a free resource
Practical one-pagers for executives of regulated businesses. Free, plain language, delivered to your inbox.
CEO Security Decision Framework
Judge any security spend in 10 minutes
Which obligations apply?
The AU regulatory map on one page
Are we OK? Board questions
Chair the security conversation
Insurance renewal prep
What underwriters ask, and why
Broader capabilities
Beyond our three core services, we support the wider security agenda for mid-size regulated businesses and enterprise organisations.
Security Strategy & Architecture
3–5 year security strategies, roadmaps and SABSA-aligned enterprise architecture.
Assurance & Compliance
Audit-ready evidence across CPS 234, the Essential Eight, ISO 27001, NIST CSF and IRAP.
Security Talent Advisory
Team structure, role design and executive hiring support to build lasting capability.
