Fractional CISO and vCISO services, run as a monthly service.
A fractional CISO, or vCISO, is someone who does the security work a small business needs but can't hire full time: watching for threats, testing backups, training the team, writing the plan for when something goes wrong. We run that role as part of monthly Run, alongside email security and managed detection built for a small business, not a large one.
You don't need a title. You need someone watching.
Most small businesses don't need a security department. They need multi-factor sign-in turned on everywhere, phishing caught before someone clicks it, backups that actually restore, and a plan for the day one of those fails anyway.
We don't claim certifications we don't hold. What we run is managed, AI-powered protection sized for a small business: monitoring, phishing defense and training, identity and access, devices, backups, and the guardrails around how your team uses AI.
One suspicious sign-in, split.
Where the line falls: what a machine catches and what a person decides.
From a login that doesn't look right to the account being safe again.
- Machines run it: Sign-in flagged
A login from a new device or location is caught in real time.
- Machines run it: Session paused
Access holds until the sign-in is confirmed.
- People keep it: Owner notified
A text or call goes to whoever owns the account.
- People keep it: Sign-in confirmed or denied
The owner says whether it was really them.
- Machines run it: Password reset
If it wasn't, the account is locked and the password reset.
- Machines run it: Incident logged
Added to the monthly report, with what happened and what changed.
What monthly Run covers.
What triggers each check, what it does, and what a person still decides.
| Check | Trigger | What it does | A person checks |
|---|---|---|---|
| Phishing training | Every month | Sends a test phishing email and short training to the team | Who clicked, then a short retrain |
| Suspicious sign-in | A login from an unrecognized device | Pauses the session and asks for a second factor | Anything that doesn't clear on its own |
| Offboarding lockout | Someone marked as departed | Revokes access to every connected account | The list of accounts closed, same day |
| Backup verification | Every night | Confirms the backup ran and can be restored | A test restore, monthly |
Small businesses are the ones getting hit.
Ransomware appeared in 88% of breaches at small and mid-sized businesses, against 39% at large ones.
Verizon 2025 DBIR
What this isn't.
Plain answers to the things owners worry about most.
Questions about managed cybersecurity.
What's the difference between a fractional CISO and vCISO?
They mean the same thing in practice: someone covering the security decisions a small business needs made, without a full-time hire. We run that coverage as part of monthly Run.
Do you offer email security for small business?
Yes. Phishing defense and training, and filtering tuned for the email you already use, are part of every monthly Run.
Is this managed detection and response?
It includes it. We watch for logins and activity that don't look right, around the clock, and respond the same day.
What does managed security cost?
It starts with the two-week review, a fixed fee quoted before we start. Cybersecurity work runs inside monthly Run after that.
Where does our data go when you use AI?
It stays in approved tools you own, never personal accounts. Every automation lists the data it touches and who checks it.
Start with a two-week review.
Fixed fee. You finish with a ranked plan of what to fix first, what it saves and what it protects.
Prefer email? Write to hello@satsumahq.com