"The prudent see danger and take refuge,— Proverbs 22:3
but the simple keep going and pay the penalty."
FRACTIONAL CISO · GRC · AI GOVERNANCE
You need a CISO's judgment far more often than you need a CISO's salary.
Executive security leadership, without the executive hire. Fifteen years running enterprise level security programs — including as CISO of a Fortune 100 healthcare division — brought to mid-sized organizations that need the outcomes, not the overhead.

Bart Lane
Founder & Principal Consultant
15 Years
In security leadership
Former CISO
Fortune 100 healthcare division
AI Governance
Advised from the build side
CISSP · CISM · CISA · MBA
Credentialed and current
Why companies bring me in
Customer security reviews keep stalling your deals
Security questionnaires, SOC 2 requests, and vendor risk assessments land in the middle of your sales cycle. Someone has to own the response — and right now that's you, on top of everything else.
Compliance is a fire drill, not a program
HIPAA, PCI, ISO 27001 — each audit becomes a scramble because there's no underlying program, just documents assembled under pressure.
Your insurance renewal now has security requirements attached
Carriers want evidence — MFA everywhere, tested backups, an IR plan that exists outside of someone's head. The application is due before your renewal date, and a weak answer shows up as premium or as reduced coverage.
Investors and acquirers are asking harder questions
Security diligence used to be a checkbox. It isn't anymore. A funding round, an acquisition, or a new PE owner means someone examines your program in detail, on their timeline, not yours.
Your teams are using AI faster than your policy can keep up
Somebody pasted client data into a chatbot last week. You don't know who, and you don't have a policy that would have stopped them. When your board or your largest customer asks how you govern AI, "we're looking into it" isn't going to hold.
Your board wants a straight answer on risk
"Are we secure?" is the wrong question, but it's the one you're being asked. You need someone who can translate technical risk into terms your board actually acts on.
Three ways to work together
Every engagement starts with a scoping call. No discovery fee, no obligation.
SECURITY PROGRAM BASELINE · 90 days · Fixed scope
Where most engagements start. You get an honest picture of where you stand and a plan you can actually execute.
- Full assessment against the framework that matters to you — NIST CSF, ISO 27001, HIPAA Security Rule, SOC 2, HITRUST, PCI DSS, or CIS
- Prioritized risk register scored by likelihood and impact
- Gap analysis with specific, actionable remediation steps
- Control mapping and an evidence-collection framework, if you're working toward a certification or audit
- Policy and documentation development
- Board-ready roadmap with 12-month sequencing
- Executive readout and Q&A session
Best for: companies with no formal security program, one that hasn't been reviewed in years, or a certification deadline that needs a real plan behind it.
FRACTIONAL CISO · Ongoing · Monthly retainer
The security executive on your leadership team, at the fraction of the time you actually need.
- Standing time each month for strategy, escalations, and decisions
- Security governance: policies, standards, and procedures that fit how you actually operate
- Vendor and third-party risk oversight
- Incident response planning, tabletop exercises, and live escalation support
- Remediation project management through to audit, including auditor liaison and customer questionnaire support
- Quarterly board and executive reporting
- Direct line to me for the questions that come up between meetings
Best for: organizations past the assessment stage that need sustained executive ownership.
AI GOVERNANCE READINESS · 8 weeks · Fixed scope
Your teams are already using AI. The question is whether you can prove it's under control.
- Inventory of AI and LLM use across the business, including shadow usage
- Risk assessment of data exposure, vendor terms, and model dependencies
- AI acceptable use policy and governance framework
- Third-party AI vendor review criteria
- Board briefing on AI risk posture
Best for: any company whose employees are using AI tools faster than policy can keep up — which is every company.
Most people advising on AI governance have never built with it
I build AI systems myself — the same kind of tools I'd help you govern. That's not a side note; it's why my AI governance advice is different.
I know where models actually leak data, because I've architected around it. I know what vendor terms matter, because I've signed them. I know which controls are theater and which ones hold, because I've had to implement both sides.
When your team brings you an AI proposal, you don't need a framework printed from a website. You need someone who can look at the architecture and tell you where the real risk sits.
Fifteen years of decisions that held up
A sample of the work
Every engagement is different, but the pattern is consistent: a real business trigger, an honest assessment, and a program the organization can actually run. Names are withheld — discretion is part of what you're hiring.
Regional Health System
Healthcare · 10-hospital system
Rebuilt a fragmented security and GRC function into a structured team, guided the hire of a permanent Director of Security to lead it, assessed the existing security tooling for real coverage rather than assumed coverage, and ran a cyber incident response tabletop end to end. They came away with a security leader of their own and a response plan they had actually rehearsed — not one sitting in a binder.
Digital Health Company
Healthcare Technology · Venture-backed
Sat on the executive review of CISO candidates, bringing a practitioner's read on which of them could actually do the job. After the hire, mentored the incoming CISO through onboarding — the stretch that usually decides whether a new security executive takes hold or stalls.
Specialty Insurance Firm
Financial Services · Multi-state commercial lines
A NYDFS (23 NYCRR 500) gap assessment and a compliance roadmap sequenced around the filing date rather than around the framework. The firm submitted its official certification of compliance ahead of the regulatory deadline.
National Craft Spirits Brand
Consumer Goods · Multi-state distillery and retail operations
Security policy development and a program-maturity effort sized to a fast-growing brand with distributed retail operations. What had been informal practice became a documented program the team could run — and keep maturing — without outside help.
Who this is for
I work best with a particular kind of organization. If this sounds like you, the first call will go somewhere.
Size
Small and mid-sized organizations. The common thread isn't headcount, it's that you carry real security obligations and nobody's full-time job is to own them. If the engagement makes sense, size isn't the barrier.
Industries
Healthcare and health tech, insurance, financial services, and professional services firms handling regulated or client-sensitive data. Most of my career has been in healthcare, where the consequences of getting it wrong aren't measured in fines.
Situation
You already have IT, and they're competent. What you don't have is someone whose job is to own security strategy, answer to the board, and be accountable for that answer.
What I'm not
I don't resell tools, I don't run your infrastructure, and I'm not here to replace the people who do. I'm an extension of your leadership, not a vendor with a product to place.
Where I'm probably not the right fit: pre-revenue startups, companies looking to check one box for one customer questionnaire, and organizations that want to hand security to someone else so they can stop thinking about it.

About the Founder
The short version
For fifteen years I did security the hard way — inside the organization, on the hook for the outcome. I briefed boards, defended budgets, and owned the answer when someone asked “are we actually exposed?”
Most recently I was Chief Information Security Officer for the UK division of a Fortune 100 healthcare enterprise, responsible for cybersecurity, governance, risk, compliance, and physical security across a national hospital network. Before that, I led information security for a nationally recognized cancer research institute and a multibillion-dollar healthcare services organization.
Two things make my advice different from most security consultants'. First, I've sat in the board seat — I've spent more than a decade translating technical risk into decisions executives actually make, which is exactly what mid-market leaders need and rarely get. Second, I build with AI myself — real, working tools I use in my own practice. When I advise on AI governance, I'm speaking from the build side, not just the policy side.
I also serve my community as a cybersecurity advisor to a nonprofit board, and previously taught cybersecurity as an adjunct professor. And I write The Independent CISO, a newsletter on the business of independent security leadership.
Credentials: MBA · CISSP · CISM · CISA — all active.
Full background →Questions I get asked
Start with a conversation
Thirty minutes, no pitch. Tell me what's driving the urgency — a client questionnaire, an audit, a board question, an incident — and I'll tell you honestly whether I'm the right fit and what the path looks like.
Book a 30-Minute CallPrefer email? bart@p223consulting.com · Franklin, TN