Cyber security has moved from an IT concern to a board-level risk in every North-East sector - financial services back-office operations facing FCA scrutiny, manufacturers managing the IT/OT boundary as plant systems connect to the internet, energy businesses navigating the cyber obligations that come with critical national infrastructure, and public sector organisations carrying citizen data under growing regulatory pressure. A Fractional CISO gives you a named, accountable senior security leader without the cost of a permanent hire: someone who can own the risk posture, present to the board and the audit committee, navigate the regulatory landscape and build the controls programme the business actually needs. Richard J. Keenlyside is based in the Tees Valley and can provide on-site security leadership across the whole of the North-East with the accessibility of a local engagement.
Local home base means on-site availability across the region can be arranged at short notice - including half-day visits, board attendance and informal site walk-throughs.
Travel and on-site: Newcastle, Sunderland, Middlesbrough and Durham all reachable as same-day on-site visits with no overnight travel.
Long-standing presence in the North-East across food manufacturing (M.I. Dicksons), industrial supply chain (LoneStar Group / Tees Valley) and the wider regional executive community.
Businesses handling sensitive data, in regulated sectors, or facing rising customer/insurer security requirements that exceed what an MSP or IT manager can credibly own.
An IT manager runs the day-to-day security controls. An MSSP monitors and responds to incidents. A Fractional CISO owns the security strategy, the risk posture and the relationship with the board - and carries personal accountability for those things. That means defining the risk appetite, presenting to the audit committee, owning the regulatory relationships, leading incident response at an executive level, and making the decisions about investment, architecture and supplier selection that an IT manager or an MSSP is not positioned to make. For North-East businesses in regulated sectors the distinction matters: regulators want to see a named senior individual, not a shared-service arrangement.
The strongest demand in the North-East comes from five areas: financial services back-office operations (Sunderland and Newcastle have a high concentration of financial services processing and contact centre operations with significant data obligations); process manufacturing and the industrial supply chain (IT/OT convergence in plant environments is a fast-growing risk); energy and utilities, particularly businesses connected to offshore and the emerging hydrogen and CCUS infrastructure in Teesside; professional services firms handling client data under contract; and public sector organisations - councils, NHS trusts and public-facing technology suppliers - that carry citizen data and face growing scrutiny from the National Cyber Security Centre.
The most common frameworks for North-East businesses are Cyber Essentials and Cyber Essentials Plus (widely required in public sector supply chains and increasingly in financial services procurement), ISO 27001 (the international standard for information security management, required by a growing number of enterprise customers and investors), SOC 2 Type II (relevant for North-East SaaS businesses selling into North American markets), and the NIS2 Directive (applicable to critical infrastructure operators including energy and utilities businesses in the Tees Valley). For financial services the FCA's DORA obligations are also increasingly relevant. The Fractional CISO owns the readiness programme and the relationship with the certification body.
The Fractional CISO prepares and presents a regular board-level security report - typically quarterly - covering the current risk posture against the agreed appetite, open incidents and near-misses, the controls programme status, regulatory position and any emerging threats relevant to the business and sector. For businesses with an audit committee the CISO attends relevant agenda items directly. The purpose is to ensure the board has the information it needs to discharge its governance obligations, and that the conversation is substantive rather than a traffic-light dashboard that conceals more than it reveals.
A typical engagement starts with a thirty-day current-state assessment: estate mapping, controls review, regulatory position, third-party and supply-chain exposure, and a structured interview programme with the IT team and key business stakeholders. At the end of thirty days there is a board-ready risk report with a prioritised remediation plan. From day thirty the Fractional CISO begins the controls programme while carrying the ongoing board reporting, regulatory relationships and incident-response ownership. For North-East businesses the on-site component of the assessment phase - site visits, team interviews, physical security review - is straightforward to deliver given the local base.
Arrange a confidential conversation · All services · All locations served