Active incident or hacked WordPress? Network / ransomware Hacked WordPress 423-888-0252 · 828-484-1257

Fractional CISO (vCISO) · BCP / DR

When something goes wrong, does the business keep running?

A fractional CISO — vCISO in the trade — is security leadership on a monthly retainer. Most small and mid-size companies have no written plan for ransomware, hardware failure, or a breach, and no one keeping those risks in check. These two services close both gaps. They sit next to the IT you already have. How this sits next to fractional CIO →

Avery Parker · principal Support since the early 1990s Networks & security since the late 1990s Linux since ~2000 Johnson City office · you talk to the same person

We do not replace your admin

A fractional CISO reviews posture, trains staff, and catches gaps before they become incidents. Your in-house IT or MSP still runs the tickets. We give them a senior security backstop and documents they can hand to an auditor, insurer, or attorney.

We work with the IT you already have

If you have an admin, a helpdesk, or an out-of-town MSP, we do not replace them. We sit next to that person: vendors, budget, security program, surge, and someone who can be in the building. Tickets and day-to-day ownership stay where they are unless you ask otherwise.

The gap most shops have

HIPAA, GLBA, ABA, and most cyber policies want a written continuity plan. Most practices do not have one. A disaster-recovery plan tells the team what to do when systems fail. Without it, recovery takes longer and costs more.

Wrong first call

If you are mid-incident, a monthly retainer is the wrong product. Start with emergency incident response. We quote BCP and vCISO after the environment can stand it.

Service 1 — Business continuity & disaster recovery

A written, compliance-ready BCP and DR plan: what to do when systems fail, data is compromised, or operations stop — documented for auditor, insurer, and counsel.

Business impact analysis

Which functions are critical, recovery order, impact of each failure.

RTOs and RPOs

How long each system can be down, and how much data loss is acceptable.

Backup verification

A process that proves backups restore — not only that a job ran.

Roles, vendors, compliance language

Who does what, who to call, HIPAA / GLBA / ABA wording as it applies.

Essential assessment

$2,500–$3,500

  • Intake questionnaire + 2-hour working session
  • Written gap assessment
  • Top 5 priority recommendations
  • 30-day email follow-up

Full BCP / DR plan

$4,500–$7,500

  • Everything in Essential
  • Full BCP document + separate DR plan
  • RTOs and RPOs per system
  • Industry compliance language
  • Two working sessions + 60-day support

Annual review retainer

$500–$1,500 / year

  • Annual review call
  • Plan updated for technology changes
  • Compliance review documentation
  • For existing full-plan clients

What the monthly CISO work looks like

It is not a dashboard login and a PDF of CVEs. It is a named person who already knows how a 20-person office actually runs: the shared mailbox, the imaging PC that cannot be patched this week, the cyber application the owner signed last year without reading.

Month one is honesty: MFA, backups that restore, who has global admin, whether email forwarding rules exist, and whether the last “security training” was a video nobody finished. Then a written list — what is actually dangerous versus what a vendor is trying to sell. After that, the monthly review keeps the list honest.

If you need a document for an insurer, a hospital partner, or counsel, that is the BCP / DR engagement above. If you need CMMC or a SPRS number, that is CMMC readiness and DefensibleScore — not a vCISO sticker on a half-finished SSP.

Clinics and law offices: see healthcare and professional practices. Mid-incident: call IR, do not start a retainer.

Service 2 — Fractional CISO

Security posture, policies, staff training, and a tested incident-response plan — at a monthly flat rate. Same person every month.

Security Essentials

$1,500 / month

  • Monthly 60-minute security review
  • Quarterly vulnerability scan summary
  • Annual security policy review
  • Email advisory (48-hour response)

Security Leadership

$2,500 / month

  • Everything in Essentials
  • Quarterly vendor risk review
  • Annual staff security training
  • Incident response plan (Year 1)
  • Priority advisory (same-day)

Security Executive

$3,500 / month

  • Everything in Leadership
  • Quarterly onsite (within 30 miles)
  • Owner / board security report
  • Cyber insurance review
  • Unlimited phone advisory
  • Works alongside your IT lead, not instead of them

Defense contractors: start free at DefensibleScore.com, then talk readiness. BCP/DR and vCISO available in the Tri-Cities and remotely nationwide.

Who does the work

Fractional leadership only works if the person on the call has actually run the stack. Avery Parker has.

Experience you can date

  • Early 1990s — computer support and repair
  • Late 1990s — networking and security
  • Around 2000 — Linux server administration
  • Web, hosting, and search alongside the infrastructure work ever since

Local and accountable

Office at 4100 North Roan Street, Suite 208, Johnson City, TN 37604. Onsite across the Tri-Cities and Western North Carolina. You talk to Avery, not a tier-1 queue. Retainers are month-to-month. We do not sell you a stack we are paid to push — vendor-neutral advice.

How coverage works (one principal, not a fake bench)

This is Avery Parker’s practice. Scheduled work is booked. Incident response jumps the queue. If he is already on a site, you hear that on the first call — not after you have waited. Partner MSPs get a scoped window in writing. We do not invent a second-shift team we do not have.

Questions we get

We are mid-incident. Is this the right page?

No. Start with emergency incident response. vCISO and BCP are for after the environment can stand a monthly program.

Do you replace our admin?

No. Tickets stay with your IT or MSP. We review posture, write the plan, train staff, and sit next to that person.

Is there a HIPAA or ABA version?

BCP language includes HIPAA, GLBA, and ABA where it applies. We do not pretend to be your counsel. Clinics and firms should also see the healthcare page.

Start with a 20-minute call.

We will look at what you have and say which service actually fits.