"The prudent see danger and take refuge,
    but the simple keep going and pay the penalty."
    — Proverbs 22:3

    FRACTIONAL CISO · GRC · AI GOVERNANCE

    You need a CISO's judgment far more often than you need a CISO's salary.

    Executive security leadership, without the executive hire. Fifteen years running enterprise level security programs — including as CISO of a Fortune 100 healthcare division — brought to mid-sized organizations that need the outcomes, not the overhead.

    Bart Lane - Founder & Principal Consultant

    Bart Lane

    Founder & Principal Consultant

    15 Years

    In security leadership

    Former CISO

    Fortune 100 healthcare division

    AI Governance

    Advised from the build side

    CISSP · CISM · CISA · MBA

    Credentialed and current

    Why companies bring me in

    Customer security reviews keep stalling your deals

    Security questionnaires, SOC 2 requests, and vendor risk assessments land in the middle of your sales cycle. Someone has to own the response — and right now that's you, on top of everything else.

    Compliance is a fire drill, not a program

    HIPAA, PCI, ISO 27001 — each audit becomes a scramble because there's no underlying program, just documents assembled under pressure.

    Your insurance renewal now has security requirements attached

    Carriers want evidence — MFA everywhere, tested backups, an IR plan that exists outside of someone's head. The application is due before your renewal date, and a weak answer shows up as premium or as reduced coverage.

    Investors and acquirers are asking harder questions

    Security diligence used to be a checkbox. It isn't anymore. A funding round, an acquisition, or a new PE owner means someone examines your program in detail, on their timeline, not yours.

    Your teams are using AI faster than your policy can keep up

    Somebody pasted client data into a chatbot last week. You don't know who, and you don't have a policy that would have stopped them. When your board or your largest customer asks how you govern AI, "we're looking into it" isn't going to hold.

    Your board wants a straight answer on risk

    "Are we secure?" is the wrong question, but it's the one you're being asked. You need someone who can translate technical risk into terms your board actually acts on.

    Three ways to work together

    Every engagement starts with a scoping call. No discovery fee, no obligation.

    SECURITY PROGRAM BASELINE · 90 days · Fixed scope

    Where most engagements start. You get an honest picture of where you stand and a plan you can actually execute.

    • Full assessment against the framework that matters to you — NIST CSF, ISO 27001, HIPAA Security Rule, SOC 2, HITRUST, PCI DSS, or CIS
    • Prioritized risk register scored by likelihood and impact
    • Gap analysis with specific, actionable remediation steps
    • Control mapping and an evidence-collection framework, if you're working toward a certification or audit
    • Policy and documentation development
    • Board-ready roadmap with 12-month sequencing
    • Executive readout and Q&A session

    Best for: companies with no formal security program, one that hasn't been reviewed in years, or a certification deadline that needs a real plan behind it.

    FRACTIONAL CISO · Ongoing · Monthly retainer

    The security executive on your leadership team, at the fraction of the time you actually need.

    • Standing time each month for strategy, escalations, and decisions
    • Security governance: policies, standards, and procedures that fit how you actually operate
    • Vendor and third-party risk oversight
    • Incident response planning, tabletop exercises, and live escalation support
    • Remediation project management through to audit, including auditor liaison and customer questionnaire support
    • Quarterly board and executive reporting
    • Direct line to me for the questions that come up between meetings

    Best for: organizations past the assessment stage that need sustained executive ownership.

    AI GOVERNANCE READINESS · 8 weeks · Fixed scope

    Your teams are already using AI. The question is whether you can prove it's under control.

    • Inventory of AI and LLM use across the business, including shadow usage
    • Risk assessment of data exposure, vendor terms, and model dependencies
    • AI acceptable use policy and governance framework
    • Third-party AI vendor review criteria
    • Board briefing on AI risk posture

    Best for: any company whose employees are using AI tools faster than policy can keep up — which is every company.

    Most people advising on AI governance have never built with it

    I build AI systems myself — the same kind of tools I'd help you govern. That's not a side note; it's why my AI governance advice is different.

    I know where models actually leak data, because I've architected around it. I know what vendor terms matter, because I've signed them. I know which controls are theater and which ones hold, because I've had to implement both sides.

    When your team brings you an AI proposal, you don't need a framework printed from a website. You need someone who can look at the architecture and tell you where the real risk sits.

    Talk Through Your AI Risk

    Fifteen years of decisions that held up

    Quarterly board reporting for over a decade, across three organizations — translating technical risk into decisions executives actually make.
    $1M+ contracts supported through pre-sales security and client-facing assurance work.
    Incident response resolution time cut by two days by building and deploying dedicated IR teams and procedures from scratch.
    FDA 21 CFR Part 11 compliance achieved for clinical research systems at a nationally recognized cancer research institute, meeting the regulatory bar for research data integrity.
    $2.5M security budget and $1M+ in Zero Trust and IoT projects delivered as CISO of a Fortune 100 healthcare division, protecting patients, staff, and clinical operations across a national hospital network.

    A sample of the work

    Every engagement is different, but the pattern is consistent: a real business trigger, an honest assessment, and a program the organization can actually run. Names are withheld — discretion is part of what you're hiring.

    Regional Health System

    Healthcare · 10-hospital system

    Rebuilt a fragmented security and GRC function into a structured team, guided the hire of a permanent Director of Security to lead it, assessed the existing security tooling for real coverage rather than assumed coverage, and ran a cyber incident response tabletop end to end. They came away with a security leader of their own and a response plan they had actually rehearsed — not one sitting in a binder.

    Digital Health Company

    Healthcare Technology · Venture-backed

    Sat on the executive review of CISO candidates, bringing a practitioner's read on which of them could actually do the job. After the hire, mentored the incoming CISO through onboarding — the stretch that usually decides whether a new security executive takes hold or stalls.

    Specialty Insurance Firm

    Financial Services · Multi-state commercial lines

    A NYDFS (23 NYCRR 500) gap assessment and a compliance roadmap sequenced around the filing date rather than around the framework. The firm submitted its official certification of compliance ahead of the regulatory deadline.

    National Craft Spirits Brand

    Consumer Goods · Multi-state distillery and retail operations

    Security policy development and a program-maturity effort sized to a fast-growing brand with distributed retail operations. What had been informal practice became a documented program the team could run — and keep maturing — without outside help.

    Who this is for

    I work best with a particular kind of organization. If this sounds like you, the first call will go somewhere.

    Size

    Small and mid-sized organizations. The common thread isn't headcount, it's that you carry real security obligations and nobody's full-time job is to own them. If the engagement makes sense, size isn't the barrier.

    Industries

    Healthcare and health tech, insurance, financial services, and professional services firms handling regulated or client-sensitive data. Most of my career has been in healthcare, where the consequences of getting it wrong aren't measured in fines.

    Situation

    You already have IT, and they're competent. What you don't have is someone whose job is to own security strategy, answer to the board, and be accountable for that answer.

    What I'm not

    I don't resell tools, I don't run your infrastructure, and I'm not here to replace the people who do. I'm an extension of your leadership, not a vendor with a product to place.

    Where I'm probably not the right fit: pre-revenue startups, companies looking to check one box for one customer questionnaire, and organizations that want to hand security to someone else so they can stop thinking about it.

    Bart Lane, Principal Consultant at P223 Consulting

    About the Founder

    The short version

    For fifteen years I did security the hard way — inside the organization, on the hook for the outcome. I briefed boards, defended budgets, and owned the answer when someone asked “are we actually exposed?”

    Most recently I was Chief Information Security Officer for the UK division of a Fortune 100 healthcare enterprise, responsible for cybersecurity, governance, risk, compliance, and physical security across a national hospital network. Before that, I led information security for a nationally recognized cancer research institute and a multibillion-dollar healthcare services organization.

    Two things make my advice different from most security consultants'. First, I've sat in the board seat — I've spent more than a decade translating technical risk into decisions executives actually make, which is exactly what mid-market leaders need and rarely get. Second, I build with AI myself — real, working tools I use in my own practice. When I advise on AI governance, I'm speaking from the build side, not just the policy side.

    I also serve my community as a cybersecurity advisor to a nonprofit board, and previously taught cybersecurity as an adjunct professor. And I write The Independent CISO, a newsletter on the business of independent security leadership.

    Credentials: MBA · CISSP · CISM · CISA — all active.

    Full background →

    Questions I get asked

    They run and secure your infrastructure — patching, monitoring, endpoints, backups. That's operational work, and when it's done well it matters. What it generally doesn't cover is ownership of your security strategy: which risks you accept, what your board hears, how you answer a customer's security review, and what gets done first when everything is a priority. I work above that layer, alongside the people already handling the day-to-day rather than around them.

    It depends on scope, and I won't quote a number before I understand what you're dealing with. What I can tell you: assessments are fixed-fee, so you know the cost before we start, and retainers are monthly. The scoping call is free, and if what you need is smaller than what I do, I'll tell you.

    Retainers are built around a set amount of standing time each month — enough for strategy, escalations, and board prep — plus a direct line for the questions that come up in between. The exact number is set during scoping, based on what you need rather than which tier you picked.

    No, and I'd be skeptical of anyone who said yes. Your team knows your environment better than I ever will. My job is to give them direction, priorities, and cover — and to take the governance and board-facing work off their plate so they can do the work they're actually good at.

    Scoping call to signed agreement is usually a couple of weeks. On a Security Program Baseline you'll have preliminary findings well before the ninety days are up — I don't hold everything for a reveal at the end. If something urgent surfaces in week two, you hear about it in week two.

    Retainer clients get live escalation support — I'm on the call. And part of the retainer work is making sure that call goes well: a tested IR plan, defined escalation paths, and a tabletop exercise so the first time your team runs the process isn't during a real event.

    Yes. I've worked under HIPAA obligations for most of my career and I'm comfortable with the contractual and compliance terms your environment requires.

    Good — that's often the right outcome, and I've helped clients do exactly that, including sitting on the executive review of candidates and mentoring the person they hired. Everything I build is yours: policies, registers, roadmaps, documentation. Your new CISO should be able to pick up where I left off instead of starting over.

    Start with a conversation

    Thirty minutes, no pitch. Tell me what's driving the urgency — a client questionnaire, an audit, a board question, an incident — and I'll tell you honestly whether I'm the right fit and what the path looks like.

    Book a 30-Minute Call

    Prefer email? bart@p223consulting.com · Franklin, TN