Practice 01

A CISO in the chair from day one.

Security leadership gaps are expensive in ways that don't appear on an invoice: stalled audits, drifting programmes, a board that stops believing the slides. Athencis puts a Global CISO into the role — with the authority, the scar tissue and the vendor-negotiation instincts that only come from having done it before, across multiple continents and regulators.

Who this is for

Three situations we're usually called into.

The gap

Your CISO has left, or you've never had one

A permanent hire takes six to twelve months. Meanwhile the audits, the renewals, the customer security questionnaires and the incidents don't wait. An interim CISO holds the line and — just as importantly — defines the role your permanent hire will actually succeed in.

The inflection

You're scaling past what got you here

PE investment, a big enterprise customer, a regulated market, a US public-sector opportunity: each one raises the bar overnight. A fractional CISO gives you genuine executive-level security ownership at a fraction of a full-time cost — one to three days a week, sized to the actual workload.

The event

Something has happened — or is about to

An incident, a failed audit, a due diligence process, an acquisition. These are moments where experience is the whole product. We lead the response, manage the stakeholders, and turn the event into the mandate for the improvements you needed anyway.

The reality check

You have a team, but no independent view

Sometimes the ask is simpler: a senior, independent security advisor who reports the truth to the CEO, CTO or board. Someone with no product to sell and no empire to build, whose only incentive is that the advice turns out to be right.

What the role covers

The full CISO remit — not a slice of it.

Interim doesn't mean partial. From the first week, we own the things a CISO is accountable for.

Strategy

Direction & investment

A risk-based security strategy the board can fund with confidence: prioritised roadmap, costed plan, and a clear line from spend to risk reduction.

Governance

Board & regulator

Board reporting that executives actually read, audit and regulator relationships, and security governance that fits how your business really makes decisions.

Programme

Delivery ownership

Running the compliance programmes, tooling decisions, renewals and vendor negotiations with your budget treated like our own — most recently a $2M saving negotiated on a single SIEM platform renewal.

People

Team & succession

Leading and developing your security team, defining the roles you need, hiring into them — and shaping the permanent CISO role so your hire lands well.

Engagement models

Sized to the problem, not the rate card.

Three ways to engage. All include direct access between sessions — security doesn't schedule itself around your contract days.

Model A

Interim CISO

Full-time · typically 3–9 months

Full executive ownership of the security function while you hire, restructure or navigate an event. Includes defining and recruiting for the permanent role, and a structured handover.

  • Day-one operational ownership
  • 30/60/90-day plan with evidence
  • Permanent role definition & hiring support

Model C

Executive advisory

Monthly cadence · retainer

Independent counsel to the CEO, CTO, board or investors. Programme assurance, second opinions on major decisions, and due diligence support for transactions.

  • M&A security due diligence
  • Programme & vendor assurance
  • Board briefings & crisis counsel

Recent mandates

The role, as we've been playing it.

Recent mandates2024–2026
Interim CISO Leadership of the global security organisation for a PE-backed SaaS group operating across the UK, Europe, the US and Asia: team, budget and vendor ownership, AI governance, public-sector compliance, successful SOC 2, ISO 27001 and Cyber Essentials Plus audits, and the groundwork for GovRAMP and TX-RAMP authorisation — through to recruitment and handover of the permanent CISO. Healthcare SaaS
AI Governance & Security As accountable executive: enterprise AI governance framework including agentic AI, governance processes, model cards and an AI Architecture Review Board — plus IAM for AI, SIEM for AI and AI detection & response. Global SaaS
Fractional CISO Security leadership for a building products manufacturer — plant and concrete fabrication: NIST CSF assessment, OT risk analysis and OT security architecture aligned to IEC 62443 and ISO 27001. Manufacturing / OT
Fractional CISO Security leadership for a regulated fintech: NIST CSF programme with FCA and PRA regulatory alignment, GDPR compliance and DORA operational resilience readiness. Fintech

The first ninety days

What good looks like, on a calendar.

Days 1–30

Stabilise and see clearly

Meet the team, the auditors and the key customers. Triage in-flight commitments. Produce a single honest picture of risk, compliance posture and spend — usually the first one the executive team has seen in one place.

Days 31–60

Set direction and unblock

A prioritised roadmap agreed with the executive team, quick wins delivered to build credibility, and the stuck decisions — tooling, vendors, hires — actually made.

Days 61–90

Build the machine

Governance running on a cadence, audit evidence flowing, the team clear on their roles, and a board pack that shows measurable movement. From here, it's execution.

“The best interim engagements end with the client asking you to stay — and you leaving anyway, because the function you built no longer needs you.”

— On succession, done properly

Need a CISO next month, not next year?

Tell us the situation. We'll tell you honestly whether interim, fractional or advisory is the right shape — or whether you don't need us at all.

Start a conversation