Fractional CISO for Startups

Founder-led security guidance that gets you board-ready in 90 days—without a full-time hire. SOC 2/ISO readiness, incident preparedness, and clear exec reporting for Seed–Series B teams

Founder-led (no junior handoffs)
Startup-ready cadence
CISM · NACD Directorship · Two-time CISO

abstract image

Offerings

In addition to services available on an ad-hoc basis, the following pre-packaged products can be delivered.

Startup Security Sprint (2 weeks)


Best for: first security owner / pre-audit sanity check

What you get:
    Rapid risk snapshot
    Top 10 fixes
    90-day plan
    Founder readout (slides)
    Starter KPIs

Cadence: Day-0 intake → Day-5 draft → Day-10 exec readout

Budget cue: Fixed fee; scoped on call.

Fractional CISO — Lite (8–12 hrs/mo)


Best for: lean teams needing steady progress

What you get:
    policy/control backlog
    vendor risk queue
    incident checklist
    monthly exec update

Cadence: Biweekly ops · Monthly exec

Budget cue: $2-4 thousand per month (scope-dependent).

Fractional CISO — Core (20–30 hrs/mo)


Best for: Seed–Series B with board, third-party, or audit drivers

What you get:
    governance calendar
    SOC 2/ISO mapping
    quarterly board deck
    annual tabletop

Cadence: Weekly ops · Monthly exec · Quarterly board

Budget cue: $5-10 thousand per month (scope-dependent).

How the first 90 days run

What a Fractional CISO engagement might look like for your business.

a white number 1 on a blue circular background

Days 0-14


    Interviews & intake
    Rapid risk snapshot
    90-day plan drafted

a white number 2 on a blue circular background

Days 15-60


    Implement top controls
    Policy backlog in motion
    Vendor risk queue running

a white number 3 on a blue circular background

Days 61-90


    Board-ready update
    KPIs baseline set
    Next quarter roadmap

About Michael Mosher

a picture in black & white of Michael Mosher's face

What I'm known for:

Two-time CISO for high-growth technology platforms
Board-ready risk reporting
Practical incident leadership and preparation
Thought-leader on security in cloud and AI

Credentials: CISM, NACD-Director, QTE

Learn more about Michael here:


Resources for startup teams




a thumbnail of the security checklist

Startup security checklist

15 pragmatic controls for Seed–Series B teams.
Use it to assign owners, set due dates, and track progress across identity, cloud, app/data, detection, and governance.


Michael's Blog

Get in touch

Let’s talk about your security goals

multihued abstract landscape

Michael Mosher

headshot of Michael Mosher

Michael has over 30 years of experience in global technology and cybersecurity roles. He has over 10 years as a cybersecurity executive, including serving as the Chief Information Security Officer (CISO) at two international technology companies. Michael has also worked at a partner level at two of the world's largest consulting firms.
Michael brings deep experience in deep industry experience in technology and telecommunications, as well as specialized expertise in:
Crisis management and planning
Strategic transformation
Cybersecurity architecture
AI risk management and enablement
Michael holds the following certifications:
ISACA Certified Information Security Manager (CISM)
NACD Directorship Certification
DDN Qualified Technology Executive (QTE)

Northwoods Security Notes Blog

(function(){ const FEED = 'https://northwoodssecuritynotes.substack.com/feed'; const API = 'https://api.rss2json.com/v1/api.json?rss_url=' + encodeURIComponent(FEED); const POST_LIMIT = 6; const root = document.getElementById('nwga-blog-feed'); root.innerHTML = '

Loading posts…

'; function strip(html){ const tmp = document.createElement('div'); tmp.innerHTML = html || ''; return (tmp.textContent || tmp.innerText || '').replace(/\s+/g,' ').trim(); } function fmtDate(s){ const d = new Date(s); if (isNaN(d)) return ''; return d.toLocaleDateString(undefined, { year:'numeric', month:'short', day:'numeric' }); } fetch(API) .then(r => r.json()) .then(data => { if(!data || !data.items){ throw new Error('No items'); } const items = data.items.slice(0, POST_LIMIT); const title = document.createElement('h2'); title.className = 'nwga-feed-title'; title.textContent = 'Latest from the blog'; const grid = document.createElement('div'); grid.className = 'nwga-feed-grid'; items.forEach(item => { const url = item.link; const post = document.createElement('article'); post.className = 'nwga-card'; const a = document.createElement('a'); a.className = 'nwga-post-title'; a.href = url; a.target = '_blank'; a.rel = 'noopener'; a.textContent = item.title || 'Untitled'; const date = document.createElement('div'); date.className = 'nwga-date'; date.textContent = fmtDate(item.pubDate); const excerpt = document.createElement('p'); excerpt.className = 'nwga-excerpt'; const raw = strip(item.description || item.content || ''); excerpt.textContent = raw.length > 220 ? raw.slice(0, 217) + '…' : raw; const read = document.createElement('a'); read.className = 'nwga-read'; read.href = url; read.target = '_blank'; read.rel = 'noopener'; read.textContent = 'Read on Substack →'; post.append(a, date, excerpt, read); grid.appendChild(post); }); const actions = document.createElement('div'); actions.className = 'nwga-actions'; const more = document.createElement('a'); more.className = 'nwga-btn'; more.href = 'https://northwoodssecuritynotes.substack.com'; more.target = '_blank'; more.rel = 'noopener'; more.textContent = 'See all posts'; actions.appendChild(more); root.innerHTML = ''; root.append(title, grid, actions); }) .catch(() => { root.innerHTML = '

Couldn’t load the feed right now. Visit the blog →

'; }); })();

 

Privacy Policy — Northwoods Global Advisors

Effective date: September 15, 2025Who we are
Northwoods Global Advisors (“NWGA”, “we”, “us”, “our”) provides fractional/vCISO and security advisory services to startups and small companies. If you have questions, email michael [at] nwglobaladvisors.com.
Information we collect
You give us:
• Contact form / email / booking: name, email, company, message, and call details you choose to share.
• Newsletter (Substack): email address and preference settings (managed by Substack).
• Downloads & resources: if a resource is gated by email, we collect the address you provide.
We collect automatically (site analytics):
• Basic traffic data (page views, referrers, device/browser info).
• We do not run ads or behavioral advertising.
Note: We may use a privacy-respecting analytics tool (e.g., Plausible, which is cookie-free) or Google Analytics. We do not combine analytics with advertising IDs.How we use information
• Respond to inquiries and deliver requested resources.
• Provide services you ask for (e.g., scheduling a call).
• Operate and improve our website and content.
• Communications you opt into (newsletter/updates).
• Legal, security, and fraud prevention purposes.
Legal bases (EEA/UK visitors)
We process personal data when one of these applies: consent (e.g., newsletter), contract (to respond/provide services you request), legitimate interests (site operations, security), and legal obligations.
Sharing and processors
We don’t sell your personal information. We share it only with service providers who help us run the site and deliver what you requested, such as:
• Carrd (website hosting/build)
• Substack (newsletter subscriptions and post delivery)
• Calendly or similar (call scheduling)
• Analytics (e.g., Plausible or Google Analytics)
• Email provider (sending/receiving email)
• Blog feed display (an RSS widget or API to show recent posts)
These providers process data on our instructions and under appropriate safeguards.International transfers
Our service providers may process data in the U.S. and other countries. We rely on appropriate safeguards (e.g., standard contractual clauses) provided by those services when required.
Data retention
• Contact & inquiries: typically up to 24 months after our last interaction (so we can follow up and track context), unless you ask us to delete earlier.
• Newsletter: until you unsubscribe (managed by Substack).
• Booking details: as long as needed to coordinate the call and for routine business records.
• Analytics: per the provider’s default retention (aggregate/anonymous where possible).
Your choices & rights
• Unsubscribe from the newsletter at any time via Substack.
• Opt out of non-essential cookies (if we use them) via your browser or any consent tool we provide.
• Access, correct, or delete your information: email [email protected].
• Depending on your location, you may have additional rights (e.g., data portability, objection). We’ll honor applicable law.
Cookies and tracking
Our site uses only the scripts we need to operate (e.g., analytics, embedded forms, or the blog feed). If we use cookie-free analytics (like Plausible), no personal data is stored in cookies. If we use Google Analytics, it may set cookies for measurement—your browser settings and any consent banner we provide control that behavior.
Security
We use reasonable administrative, technical, and organizational measures to protect personal information. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
Children
Our site and services are not directed to children under 16, and we do not knowingly collect their personal information.
Changes to this policy
We may update this policy from time to time. We’ll post the updated version with a new Effective date.
Contact
Questions or requests: michael [at] nwglobaladvisors.com