Alan McKenna
Fractional CIO · Health-Tech · Fintech · B2B SaaS

The enterprise deal isn't stuck. It's waiting for proof.

Security questionnaires, SOC 2, ISO 27001, HIPAA. Somebody has to build the infrastructure behind the answers. I'm a fractional CIO who has done exactly that inside 4Catalyzer, Redesign Health, Qualio, and Bilt, and I do it for one company at a time: yours.

Vendor security questionnaire §4 · Access Control
4.1 — Is single sign-on with MFA enforced for all corporate systems?
YesEvidence: Okta org policy · attached
4.2 — Are all endpoints centrally managed with enforced disk encryption?
YesEvidence: MDM posture report · attached
4.3 — Do you hold a current SOC 2 Type II or ISO 27001 certification?
YesEvidence: Report available under NDA
The document standing between you and a signed contract
Built & secured technology at
SphereLookerBiltButterfly NetworkRedesign HealthColorHyperfineCalibrateQualio4CatalyzerLiquid Robotics SphereLookerBiltButterfly NetworkRedesign HealthColorHyperfineCalibrateQualio4CatalyzerLiquid Robotics
In one line

A fractional CIO is an experienced Chief Information Officer who works part-time so a startup gets senior technology and security leadership without a full-time executive salary. For health-tech, fintech, and SaaS companies, that means one person who owns the roadmap and builds the infrastructure behind SOC 2, ISO 27001, and HIPAA, so enterprise deals stop stalling in security review.

When founders call me

Three moments where IT and security suddenly become the whole ballgame.

Our biggest prospect just sent a 200-question security review, and I don't know how we'd answer half of it.

The deal blockerEnterprise buyers won't sign without evidence: SSO, managed devices, a certification or a credible path to one. I build the infrastructure behind the answers, then help you answer.

We just raised. The board expects SOC 2 by the next round, and nobody here has done an audit before.

The compliance clockFrom zero to audit-ready: the tooling, the ISMS policies, the evidence, and the auditor relationship. I've run this end to end, including first audits with zero major findings.

Honestly, IT is a founder with admin rights, shared passwords, and laptops we've never gotten back.

The scaling debtEvery startup accrues it. I replace it with identity, device management, and offboarding automation that scales from 15 people to 500, before an incident or an auditor finds it first.

Engagements

Three ways to work together. Every one starts small.

No six-month proposals, no discovery theater. Each engagement is scoped around a concrete outcome, and most clients start with the Sprint.

Most common starting point

Security & Compliance Sprint

For teams with a deal in security review or an audit on the calendar.

A fixed-scope engagement that takes you from where you are to audit-ready on the framework you're targeting.

  • Gap assessment against SOC 2, ISO 27001, or HIPAA
  • Identity, MDM, and EDR stack built and hardened
  • Compliance platform wired up, evidence flowing
  • ISMS policies, access reviews, IR & DR plans
  • Auditor selection and audit support
How SOC 2 works for startups →
Ongoing

Fractional CIO

For companies that need the function owned, not a project finished.

Part-time, ongoing ownership of your technology and security function, strategy through execution.

  • Roadmap, budget, and vendor ownership
  • Security reviews answered as they arrive
  • Quarterly access reviews and vendor risk
  • Onboarding/offboarding that runs itself
  • Board- and buyer-ready reporting
What a fractional CIO does →
Event-driven

Diligence & Scale Events

For fundraises, M&A, audits gone sideways, and public-market prep.

Focused engagements when the stakes spike and the technical answers have to be right.

  • Technical diligence prep for fundraising or M&A
  • IPO/SPAC readiness, done through multiple events
  • Audit rescue when findings are piling up
  • Office build-outs and infrastructure moves
Describe your event →
Why fractional

You have four other options. Here's the honest comparison.

Option 01Hire a full-time CIO or Head of IT

The right call eventually, and I'll tell you when you're there. Until then it's a $250k+ salary line for a function that needs senior judgment weekly, not daily. Several clients have had me build the function, then hire and hand off to their first full-time leader.

Option 02Sign with a generalist MSP

MSPs are built for tickets: reset the password, fix the printer, close the queue. They don't sit in your board meeting, own your audit, or answer an enterprise prospect's security review. You'd still need someone senior directing them, which is the role I fill, and I bring the hands too.

Option 03Rely on your compliance platform alone

Vanta, Drata, and Secureframe are excellent, and I implement them constantly. But they're monitoring layers: they tell you which controls are failing. Someone still has to build the Okta, Jamf, and CrowdStrike infrastructure underneath so the checks turn green, and write the policies auditors actually read.

Option 04Bring in a big consultancy

You'll get a polished readiness assessment and a roadmap, priced at multiples of a full engagement with me, and the implementation will still be your problem. I deliver the assessment in week one, then stay to do the work.

Track record

Fifteen years of owning the outcome, not just the ticket.

Bilt RewardsFintech
Led SOC 2 and PCI compliance programs to zero major findings on first audit; built RBAC and DLP across the collaboration stack; zero-trust endpoint model on Kandji and Intune.
SOC 2 + PCI · 0 findings
QualioQuality & compliance SaaS
Contracted for two years guiding the company through ISO 27001 certification, the exact certification their own customers require of them.
ISO 27001 · Certified
Redesign HealthVenture studio
Standardized security frameworks and HIPAA-compliant infrastructure across 40+ health-tech and fintech portfolio companies, supporting 1,200+ users.
40+ companies · HIPAA
4CatalyzerBiotech venture studio
Ran IT and security for nine biotech startups including Butterfly Network and Hyperfine; led technical diligence and SEC compliance prep through multiple SPAC and IPO events.
IPO/SPAC diligence
MSG EntertainmentSphere, Las Vegas
Led the engineering team building production pipeline infrastructure for Sphere, the Las Vegas venue with a four-acre screen, including migrating an 800TB render infrastructure into Azure.
Sphere · 800TB to cloud
ColorGenomics
Scaled secure, HIPAA-compliant infrastructure for scientists and research teams through 300% company growth.
HIPAA · 300% scale
LookerAnalytics platform
Built the enterprise security program, SAML authentication and MFA, formal DR and business continuity, while managing a $6M IT budget and redundant infrastructure at 99.99% uptime.
$6M budget · 99.99%
Liquid RoboticsMarine robotics · defense
Established NIST- and DFARS-compliant infrastructure for Department of Defense contracts, running IT and network security across California and Hawaii sites.
NIST/DFARS · DoD
How it starts

The first conversation is a working session, not a sales call.

Tell me what's in front of you: the framework you're targeting, the questionnaire on your desk, the deal that's stalling. I'll tell you exactly what it takes to get through it, whether or not that involves me.

You'll leave with a clear picture of your gaps and priorities either way. If we're a fit, I'll follow up with a scoped proposal within days, not weeks.

Book a working session
One hour · here's the agenda
  1. Your situation. The deal, the deadline, the framework, the board pressure. Fifteen minutes.
  2. Rapid gap read. We walk your stack: identity, devices, cloud, vendors, against the target framework.
  3. The path. What audit-ready takes from where you stand: sequence, effort, and honest timeline.
  4. Fit, or not. If I'm not the right shape for it, I'll say so and point you somewhere better.
About

I've been the first and only IT hire. I know what the job actually needs.

For fifteen years I've built technology and security functions from scratch, inside venture studios like 4Catalyzer and Redesign Health, genomics companies like Color, analytics platforms like Looker, and fintech scale-ups like Bilt. I've carried companies through SPACs, IPOs, first audits, and 300% growth years, usually as the most senior technical operator in the room.

Before any of that I taught IT at the college level, which turns out to be the most useful credential for this work: I can make an ISMS policy, a zero-trust rollout, or an auditor's finding make sense to a founder who has nine other fires burning. You get the judgment of a CIO and the hands of an engineer, at a fraction of either salary line.

CompTIA Security+ITIL 4Jamf CertifiedMS Endpoint AdminB.S. Business Admin
FAQ

The questions founders actually ask.

What is a fractional CIO?

A fractional CIO is an experienced Chief Information Officer who works part-time, on a retainer or project basis, giving a startup senior technology and security leadership without the cost of a full-time executive. For regulated startups, a fractional CIO typically owns the technology roadmap, builds the identity, device, and security infrastructure, and leads SOC 2, ISO 27001, or HIPAA readiness. Read the full explainer →

How much of your time do we actually get?

It depends on the engagement. A compliance sprint is front-loaded and intensive; a fractional CIO retainer typically means a consistent weekly commitment, with more during audits, incidents, and scale events. We set the shape in the scoping conversation, and it flexes when reality demands it.

We already have an IT person. Do you replace them?

Usually the opposite. If you have a capable admin or support engineer, I give them direction, architecture, and air cover, the senior layer they've been missing. Several engagements have ended with me hiring my own full-time replacement, which I consider a success.

We already bought Vanta. Isn't that enough?

Vanta (or Drata, or Secureframe) is the monitoring layer, and I'll happily work with whichever you chose. But the platform reports on infrastructure; it doesn't build it. The SSO, device management, EDR, and policies underneath are what make the checks turn green, and that's the work I do.

SOC 2 or ISO 27001, which one do we need?

Short version: if your buyers are mostly US enterprises, SOC 2 Type II is usually the ask; if you sell into Europe or into quality-driven industries, ISO 27001 often carries more weight, and health-tech frequently ends up needing HIPAA alignment regardless. The real answer depends on who's asking you for proof. See the full comparison →

What does it cost?

Less than a full-time hire, more than a helpdesk contract, and always scoped to a concrete outcome before we start. I'll give you a specific number after the working session, when I know the size of the gap, and you'll never get an open-ended invoice.

Have a deal in security review, or an audit on the calendar?

Bring me the questionnaire, the framework, or the mess. One working session and you'll know the path, whether or not it includes me.

Book a working session
Prefer email? alan@soc2cio.com · Maplewood, NJ · Tri-State & remote