Two regulations name the role - and both allow a service provider to fill it

Cyber insurance carriers, regulators, and auditors expect strong governance, documented processes, and risk oversight. Two regulations go further: they require a designated security leader by name. The FTC Safeguards Rule requires covered financial institutions to designate a Qualified Individual to oversee the information security program - and it expressly permits that individual to be employed by a service provider (16 CFR 314.4(a)), on three conditions: you retain responsibility for compliance, you designate a senior member of your personnel to direct and oversee the Qualified Individual, and you require the service provider to maintain an information security program that protects you. NYDFS 23 NYCRR 500 mirrors it for New York financial services: a CISO must be designated, and may be employed by a third-party service provider under the same three conditions (23 NYCRR 500.4). In plain terms: a fractional CISO is how an SMB fills a named regulatory role without a full-time hire - see FTC Safeguards for whether the rule covers you.

What the engagement letter has to say

The permission in both rules is conditional, and the conditions are satisfied on paper before they are satisfied in practice. Read the agreement you are about to sign and look for three things stated plainly, in the document itself rather than in a proposal or a sales deck.

  • That you retain responsibility for compliance. The provider is performing the function; it is not assuming your legal obligation. An agreement that implies the provider becomes responsible for your compliance is describing something the rule does not permit, and a reviewer will notice.
  • That a named senior person on your side directs and oversees the engagement. Not a department, not a title placeholder - a person, identified, senior enough that directing the security function is within their authority. If the agreement leaves this blank, you have not met the condition, whatever else the document says.
  • That the provider maintains its own information security program protecting your information. This is the provider's obligation, distinct from the program it runs for you, and it should be stated as an obligation rather than described as a practice.

Two more things worth checking while the document is open: that the scope of the designated role is written down - what the individual is accountable for, and what remains yours - and that the arrangement produces records you can hand to someone else. An engagement that leaves no artifact behind is difficult to evidence later, and evidence is the entire point of a designation.

We structure engagements to meet those conditions.

What "direct and oversee" actually means for your senior person

This is the condition most often treated as a formality, and it is the one a reviewer tests. The person you designate is not expected to be technical. They are expected to be the point at which security decisions become the business's decisions.

In practice, quarter to quarter, that means:

  • Receiving reporting and reading it. The risk picture, what changed, what is open, what is being recommended. Reporting nobody reads is indistinguishable from reporting that was never produced.
  • Setting direction on the open questions. The fractional CISO brings the recommendation and the trade-off; the designated person decides what gets funded, what gets accepted, and what gets deferred - and the decision is recorded with their name against it.
  • Being the escalation path. When something material happens, the fractional CISO escalates to them, not to a distribution list. They should be able to say who calls them, and when.
  • Holding the engagement to account. Was the work done. Was the reporting delivered on the agreed cadence. Are the risks accepted last quarter still the right ones to accept.

None of that requires a security background. It requires availability, authority, and a record. If the person you have in mind cannot commit to that, designate someone who can - the condition is about oversight being real, not about who has the most impressive title.

What proves it - the artifacts

A Safeguards examination, an NYDFS certification, a carrier's application or claim review, and an enterprise customer's security questionnaire are four different audiences asking one question: show me. Each of them accepts documents, not descriptions. The set that answers all four:

  • The written designation. Who the Qualified Individual or CISO is, that they are employed by a named service provider, who on your side directs and oversees them, and the date it took effect. One page, signed, filed somewhere you can find it under pressure.
  • The program document. The information security program itself - what is in scope, what controls exist, who owns them. This is the thing the designated individual oversees, and its absence makes the designation abstract.
  • The risk assessment. Current, dated, and connected to the program: the risks identified, how they were ranked, and what was decided about each. A designation with no risk assessment behind it reads as a name on a form.
  • The reporting cadence and the reports. Evidence that oversight happened on a schedule rather than being reconstructed in the week before an audit. Dated reports, with the recipient on them, are far more persuasive than an assertion that reviews occur.
  • The report to ownership or the board. The periodic written report on the state of the program to the people who govern the business. This is the artifact that demonstrates the oversight chain runs all the way up, and it is the one most often missing.

If you want a view of how a carrier reads this before you submit anything, the cyber insurance readiness tool walks the same ground an application does.

When a fractional CISO is not the answer

It is not the right structure for everyone, and the honest cases are easy to recognize. You need a full-time employee in the role when:

  • A contract says so. Enterprise customers and government-adjacent work sometimes require that the security leader be your employee, or require an on-site presence, or exclude service providers from the role outright. The contract language governs, and no arrangement structured around it survives scrutiny.
  • A regulator or examiner has told you so. The two rules discussed here permit a service provider. Not every regime does, and an examiner who has raised the question about your specific institution has effectively answered it. Counsel decides this one, not a vendor.
  • The volume of decisions exceeds any part-time cadence. If security decisions arrive daily, if you run a security team that needs a manager present, or if the environment changes faster than a scheduled cadence can keep up with, the work is a full-time job and treating it otherwise produces a backlog rather than oversight.
  • Nobody internal can take the oversight role. The three conditions require a senior person on your side who directs and oversees. If that person genuinely does not exist and cannot be appointed, the arrangement does not meet the conditions - and a designation that does not meet the conditions is worse than no designation, because it looks like compliance and is not.
  • You are being asked to name a person, not a function. Some diligence reviews want an individual with a documented tenure at your organization. That is a reasonable thing for them to want, and the right response is to say what you actually have rather than to dress up the arrangement.

The test for the rest of the cases is simple: can the oversight condition be met by a real person with real authority, and does the decision volume fit the cadence you can sustain. If both answers are yes, fractional works and is provable. If either is no, hire.

Frequently Asked Questions

Can a fractional CISO satisfy our insurance or compliance requirement for designated security leadership?

For the two regulations that name the role: yes, with conditions the regulations themselves spell out. The FTC Safeguards Rule expressly permits your Qualified Individual to be employed by a service provider if you retain responsibility for compliance, designate a senior member of your personnel to direct and oversee them, and require the provider to maintain an information security program that protects you (16 CFR 314.4(a)). NYDFS permits a third-party CISO under the same three conditions (23 NYCRR 500.4). We structure engagements to meet those conditions. For insurance: applications ask who is accountable for your security program, and a documented fractional arrangement gives you a real answer - whether it satisfies a specific carrier's wording is a question we'll help you answer accurately on that application.

Who signs the certification or the attestation - you or us?

You do. The obligation is the covered entity's, and the rules that permit a service provider in the role do not move the signature. The fractional CISO produces the program, the risk assessment, and the reporting the signature rests on, and will tell you plainly where the record is thin before you sign anything. If a provider offers to sign it for you, that is a reason to slow down rather than a convenience.

Our insurance broker asks whether we have a CISO. What do we say?

Answer it the way the arrangement actually is: the role is designated and held by a named service provider, with a named senior person internally who directs and oversees it. Do not answer a bare yes and leave the structure undisclosed, and do not answer no because the person is not on payroll - both answers create a problem at claim time. Bring the written designation to the conversation and let the broker read it; that is the document the carrier will want if a claim is ever examined.

An enterprise customer's security review asks for our CISO's name and reporting line. What goes in the field?

The individual performing the role, the provider that employs them, and the internal executive they report to. Procurement reviewers see outsourced security leadership routinely; what draws follow-up questions is a reporting line that does not resolve to anyone at your company, or an answer that changes between the questionnaire and the interview. Give them the designation document as the attachment and the field answers itself.

Does the designated individual have to be an employee of a single provider, or can the role be shared?

Both rules describe a designated individual, so the answer given to a regulator, a carrier, or a customer has to resolve to a person and to the provider employing them. Work behind that person can and usually does involve specialists - that is true of in-house security functions as well - but the designation itself should not be written as a committee. If your agreement names a team rather than a role holder, expect to be asked who the individual is.

We already have an IT provider. Can they be the designated individual?

They can, and the questions to ask are the same ones you would ask anyone: does the agreement state the three conditions, is the program documented separately from the day-to-day support work, and is there reporting to your designated senior person that exists independently of ticket volume. The practical concern is not competence but separation - the party operating the controls is also the party reporting on them, and a reviewer may raise that. An independent third-party assessment is the usual way to settle it.

What happens if we designate someone and then never do the oversight?

You have a designation that will not survive being examined. The three conditions are conjunctive - the permission to use a service provider depends on all of them, and oversight is the one that leaves the thinnest paper trail when it is skipped. The failure surfaces at the worst moment: an examination, a claim, or a diligence review, where the absence of dated reporting is read as the absence of a program. If the cadence is not being kept, fix the cadence or change who holds the oversight role.

Related