RoninSec is a boutique fractional CISO practice run by one operator who spent years breaking into companies before defending them. SOC 2 for the deal. Answers for the board. Proof for the auditor.
30 minutes, no pitch. You leave with a straight read on your security posture, whether or not we work together.
Companies hit this wall between 50 and 500 people: enterprise clients, insurers and regulators start demanding proof of security leadership, and a stretched CTO no longer counts. Sound familiar?
CISOs with both board experience and technical depth are concentrated in enterprises. What the mid-market gets offered instead is a stretched IT manager, a consultancy's junior bench, or a checkbox vendor. None of them survive a boardroom.
SOC 2 for the US deal. ISO 27001 for the EU one. NIS2 because you're manufacturing, DORA because you're fintech. Each one is a project someone senior has to own, and nobody senior is free.
Investors, insurers and enterprise procurement now want a named security leader, real reporting and evidence before they sign anything.
No off-the-shelf packages. Every engagement is scoped to your stage, your regulators and your board, on one call.
Regulatory complexity and threat exposure vary dramatically by industry. Every engagement starts from sector-specific knowledge, not a generic framework.
DORA, PCI-DSS, FCA and SEC expectations, and the security bar fintech investors now set. Move fast without breaking compliance.
Patient data protection, HIPAA compliance, medical device security and the trust healthcare regulators and enterprise buyers demand.
SOC 2 readiness, enterprise security questionnaires, ISO 27001. Security as a growth enabler that unlocks deals instead of blocking them.
NIS2 obligations, OT/IT convergence risk and supply-chain security, with particular depth in the DACH market, where the compliance deadline is now a board issue.
Platform-backed delivery: structured, measurable, and visible to your board from week one.
Kickoff, stakeholder interviews and platform setup. We map your business, regulators and deal pipeline before touching a single control.
Security maturity scorecard, risk register, and a prioritized 12-month roadmap, costed and mapped to your compliance targets.
Policies, controls, vendor risk and audit preparation, driven month by month, with progress your board can see.
Monthly reports, quarterly board briefings, incident support, and a named CISO for every audit and security questionnaire.
A note on certification: an independent auditor certifies you, as it should be. My job is preparing you and managing the auditor relationship so you pass first time.

"Security leadership that speaks to boards, satisfies auditors, and protects what you've built."
Most security leaders come in one of two shapes: GRC executives who have never seen a real attack, or brilliant engineers who can't hold a boardroom. I built my career deliberately in the overlap.
Seven years across both tracks. On one side, hands-on blue and red team work inside Fortune 500 environments: pentesting, red teaming, vulnerability management and security operations at global scale. On the other, executive CISO leadership and GRC: governance, risk, compliance and board reporting. I broke into systems before I defended them, which makes my recommendations technically honest, not audit theater.
I founded RoninSec to bring that caliber of leadership, usually reserved for enterprises, to mid-market companies at their most decisive stage: clear roadmaps, board-ready reporting, and compliance programs that actually get executed.
No MSSP behind me, no tool vendor paying commission, no agency juniors doing the work under my name. You get one senior operator with one agenda: yours.
Advice that survives contact with both rooms: technical enough to hold up in front of your engineers, commercial enough to win over your board. And because I spent years on the attacker's side, the programs I build are designed to stop real attacks, not to pass a checklist.
Independent of MSSPs and tool vendors. Every recommendation exists because you need it, not because someone pays me to make it.
NIS2, DORA and GDPR alongside SOC 2 and HIPAA. One advisor across every jurisdiction you sell into.
The same rigor larger advisory firms use: maturity scoring, compliance tracking and live dashboards, with solo-practice attention.
You work with me, the same person, from the first call to the board meeting. No juniors, no account managers, no handoffs.
Retainers scale with intensity, from advisory sessions to fully embedded leadership, and fixed-scope projects are quoted as exactly that: fixed. You'll have a precise number after the discovery call and before any commitment. This is a boutique practice, not the cheapest line on your comparison sheet; it's priced for companies that want it done once, properly.
Kickoff within days of signing, stakeholder interviews in week one, and a prioritized roadmap in your hands within two weeks. If you have an audit or deal deadline, say so on the call and we plan backwards from it.
No. I work with whoever you have: your IT lead, your engineers, your ops manager. Part of the job is making the team you already have effective at security, not selling you headcount.
No, and be wary of anyone who says yes. An independent auditor certifies you. I prepare you, build the evidence, and manage the auditor relationship so you pass first time.
Yes. Enterprise security questionnaires and vendor risk requests are some of the most common reasons companies call me. Send it over before the call and we'll walk through it together.
Thirty minutes, free, no pitch. You'll get a straight read on your security posture and what your next compliance milestone actually takes, whether or not we ever work together.
Solo practice, deliberately short client list. When the roster is full, it's full.
Prefer email? bogdanfrincu@ronin-sec.com