Fractional CISO · US · UK · EU

Security leadership that holds up to boards, regulators, and attackers.

RoninSec is a boutique fractional CISO practice run by one operator who spent years breaking into companies before defending them. SOC 2 for the deal. Answers for the board. Proof for the auditor.

30 minutes, no pitch. You leave with a straight read on your security posture, whether or not we work together.

7 yearsacross offensive and defensive security
3 to 6 weeksto your first compliance win
3 marketsjurisdiction-aware: US · UK · EU
The Problem

Security just became the thing standing between you and your next deal.

Companies hit this wall between 50 and 500 people: enterprise clients, insurers and regulators start demanding proof of security leadership, and a stretched CTO no longer counts. Sound familiar?

Enterprise security questionnaire on your desk SOC 2 / ISO 27001 required to close a deal NIS2 / DORA deadline Recent funding round Cyber insurance renewal CISO departure M&A due diligence
01

Real security leadership went upmarket

CISOs with both board experience and technical depth are concentrated in enterprises. What the mid-market gets offered instead is a stretched IT manager, a consultancy's junior bench, or a checkbox vendor. None of them survive a boardroom.

02

One framework becomes five

SOC 2 for the US deal. ISO 27001 for the EU one. NIS2 because you're manufacturing, DORA because you're fintech. Each one is a project someone senior has to own, and nobody senior is free.

03

"We take security seriously" stopped working

Investors, insurers and enterprise procurement now want a named security leader, real reporting and evidence before they sign anything.

How I Work

Hire the job, not the headcount.

No off-the-shelf packages. Every engagement is scoped to your stage, your regulators and your board, on one call.

Sprint

Compliance Sprint

You have a date: an audit, a renewal, a deal that won't close without a certificate.
  • ISO 27001, SOC 2, GDPR, NIS2, DORA or HIPAA, from scoping to certification
  • Gap assessment and prioritized remediation plan in the first two weeks
  • Policy suite, evidence collection and auditor liaison handled end-to-end
  • Fixed scope, fixed timeline, audit-ready outcome
Fixed-scope projects: Gap Assessment & Roadmap · SOC 2 Readiness · ISO 27001 Readiness · NIS2 / DORA Assessment · HIPAA Risk Assessment · Vendor Risk Program
Typical duration: 8 to 16 weeks · Scoped on the call
Scope a sprint
Flagship · Retainer

Embedded CISO

You need a security leader in the room: one who owns the program, answers to the board, and signs their name to it.
Includes everything in Sprint and Advisory, plus ongoing leadership:
  • Security roadmap, policy development and compliance tracking, owned end-to-end
  • Quarterly executive briefings and board presentations, built in as standard
  • Monthly reporting, risk reviews and vendor risk management
  • Your named CISO for customers, auditors, insurers and regulators
  • Incident response coordination and audit preparation
Monthly retainer · Scales with your growth stage
Book a discovery call
Advisory

Security Advisory

You need answers before you need a program: a risk read, an architecture review, a second opinion.
  • Structured risk assessments with a board-ready findings report
  • Security architecture reviews grounded in real attacker tradecraft
  • Vendor risk: third-party assessments and a working vendor risk program
  • Enterprise security questionnaires, answered fast when a deal is waiting
  • M&A due diligence and on-call counsel as decisions arise
Project-based or on-call · Scoped on the call
Start a conversation
Industries

Deep expertise in high-stakes sectors.

Regulatory complexity and threat exposure vary dramatically by industry. Every engagement starts from sector-specific knowledge, not a generic framework.

Fintech & Financial Services

DORA, PCI-DSS, FCA and SEC expectations, and the security bar fintech investors now set. Move fast without breaking compliance.

DORAPCI-DSSFCA / SEC

Healthcare & MedTech

Patient data protection, HIPAA compliance, medical device security and the trust healthcare regulators and enterprise buyers demand.

HIPAAMDRNHS DSPT

SaaS & Tech Startups

SOC 2 readiness, enterprise security questionnaires, ISO 27001. Security as a growth enabler that unlocks deals instead of blocking them.

SOC 2ISO 27001GDPR

Manufacturing & Critical Infrastructure

NIS2 obligations, OT/IT convergence risk and supply-chain security, with particular depth in the DACH market, where the compliance deadline is now a board issue.

NIS2DACHSupply Chain
Process

From first call to running security program in weeks.

Platform-backed delivery: structured, measurable, and visible to your board from week one.

01

Mobilize

Kickoff, stakeholder interviews and platform setup. We map your business, regulators and deal pipeline before touching a single control.

02

Assess

Security maturity scorecard, risk register, and a prioritized 12-month roadmap, costed and mapped to your compliance targets.

03

Execute

Policies, controls, vendor risk and audit preparation, driven month by month, with progress your board can see.

04

Embed

Monthly reports, quarterly board briefings, incident support, and a named CISO for every audit and security questionnaire.

A note on certification: an independent auditor certifies you, as it should be. My job is preparing you and managing the auditor relationship so you pass first time.

About

Your fractional CISO.

Bogdan Frincu, Fractional CISO at RoninSec
Bogdan Frincu Founder & Fractional CISO · RoninSec

"Security leadership that speaks to boards, satisfies auditors, and protects what you've built."

Most security leaders come in one of two shapes: GRC executives who have never seen a real attack, or brilliant engineers who can't hold a boardroom. I built my career deliberately in the overlap.

Seven years across both tracks. On one side, hands-on blue and red team work inside Fortune 500 environments: pentesting, red teaming, vulnerability management and security operations at global scale. On the other, executive CISO leadership and GRC: governance, risk, compliance and board reporting. I broke into systems before I defended them, which makes my recommendations technically honest, not audit theater.

I founded RoninSec to bring that caliber of leadership, usually reserved for enterprises, to mid-market companies at their most decisive stage: clear roadmaps, board-ready reporting, and compliance programs that actually get executed.

ISC2
CISO Leadership CertificateAll 5 modules completed
HTB
CWESCertified Web Exploitation Specialist
INE
eCPPTv2Certified Professional Penetration Tester
INE
eWPTWeb Application Penetration Tester
Why RoninSec

A ronin serves no master. That's the point.

No MSSP behind me, no tool vendor paying commission, no agency juniors doing the work under my name. You get one senior operator with one agenda: yours.

Strategic + technical. The rare combination.

Advice that survives contact with both rooms: technical enough to hold up in front of your engineers, commercial enough to win over your board. And because I spent years on the attacker's side, the programs I build are designed to stop real attacks, not to pass a checklist.

No upsell agenda

Independent of MSSPs and tool vendors. Every recommendation exists because you need it, not because someone pays me to make it.

EU + US regulatory coverage

NIS2, DORA and GDPR alongside SOC 2 and HIPAA. One advisor across every jurisdiction you sell into.

Platform-backed delivery

The same rigor larger advisory firms use: maturity scoring, compliance tracking and live dashboards, with solo-practice attention.

Direct access, always

You work with me, the same person, from the first call to the board meeting. No juniors, no account managers, no handoffs.

Before You Ask

The questions every CEO asks on the first call.

What does it cost?

Retainers scale with intensity, from advisory sessions to fully embedded leadership, and fixed-scope projects are quoted as exactly that: fixed. You'll have a precise number after the discovery call and before any commitment. This is a boutique practice, not the cheapest line on your comparison sheet; it's priced for companies that want it done once, properly.

How fast can we start?

Kickoff within days of signing, stakeholder interviews in week one, and a prioritized roadmap in your hands within two weeks. If you have an audit or deal deadline, say so on the call and we plan backwards from it.

Do we need an internal security team first?

No. I work with whoever you have: your IT lead, your engineers, your ops manager. Part of the job is making the team you already have effective at security, not selling you headcount.

Do you certify us yourself?

No, and be wary of anyone who says yes. An independent auditor certifies you. I prepare you, build the evidence, and manage the auditor relationship so you pass first time.

Can you handle a security questionnaire that's blocking a deal right now?

Yes. Enterprise security questionnaires and vendor risk requests are some of the most common reasons companies call me. Send it over before the call and we'll walk through it together.

Get Started

Talk to me before the auditor does.

Thirty minutes, free, no pitch. You'll get a straight read on your security posture and what your next compliance milestone actually takes, whether or not we ever work together.

Book a Free Discovery Call

Solo practice, deliberately short client list. When the roster is full, it's full.

Prefer email? bogdanfrincu@ronin-sec.com