Executives understand what a fractional CFO does because they can picture the work: closing the books, managing cash, briefing the board on the numbers. Security leadership is harder to picture, partly because most organizations have never had it and partly because the field has spent decades letting itself be defined by guards and cameras. So this article describes the actual work, in roughly the order it happens in a real engagement.

The First Ninety Days

The engagement begins with finding out what is true rather than what is assumed. That means walking every site, reading every policy that exists and noting every one that does not, pulling the guard contract and comparing what it promises to what the post orders say and what the officers actually do, and reviewing the access control system to see who holds credentials and whether anyone has ever audited the list. It also means talking to people. The receptionist, the night shift supervisor, the HR director, and the facilities manager each know something about the organization’s security that leadership does not, and the fractional director’s first job is to collect it.

Out of that comes an assessment written for leadership rather than for security professionals. It ranks the risks the organization actually faces, separates the problems that cost money to fix from the ones that only cost attention, and lays out a sequence. By the end of the first quarter the organization should have a clear picture of its exposure and a plan it can fund, and the director should have enough authority and enough relationships to start executing it.

The Monthly Rhythm

Once the program is moving, the work settles into a rhythm that fits the retainer. Each month the director reviews incident reports and looks for patterns the individual reports hide, meets with the guard vendor to hold them to the contract and adjust post orders as the organization changes, checks in with the department heads whose operations create security exposure, and briefs whoever the director reports to. Policies get written, revised, and pushed into training. Vendor proposals get evaluated by someone whose compensation does not depend on the answer.

Access review is a good example of the kind of unglamorous work that matters most. Every quarter the list of people with credentials gets compared against the list of people who should have them. Contractors whose projects ended, employees who transferred, vendors whose agreements lapsed: each one is a door that still opens for someone who should no longer be able to open it. In my experience this single discipline catches more real exposure than any camera upgrade, and it is almost never happening before a director arrives.

The Work Nobody Schedules

Then there is the work that arrives on its own. An employee is terminated and makes a comment on the way out that the manager cannot stop thinking about. A domestic situation follows a staff member to work. A protest is announced for the sidewalk outside. A contractor’s badge is found still active months after the contract closed. In each case the fractional director is the person leadership calls, and the value of the role shows up in how much of the response was already built before the phone rang. The threat assessment process exists. The relationship with the local police department exists. The protocol for a credible threat exists and the managers have been trained on it. The director coordinates rather than improvises.

Testing Instead of Assuming

A great deal of security in most organizations is assumed. The door is assumed to lock. The alarm is assumed to reach someone. The guard is assumed to check the credential rather than wave at the familiar face. The evacuation plan is assumed to work because it has never been tried. A fractional director spends deliberate time turning assumptions into verified facts, which means walking up to doors and pulling on them, watching the guard post at shift change, calling the alarm company to confirm who actually receives the signal, and running the incident plan as a tabletop with the people who would have to execute it. This is the work I built the P.R.O.O.F. framework around, and it is where most of the failures I have seen in my career would have been caught early.

Leadership Work

Underneath all of it is the part that makes the role a director’s role rather than a manager’s. The fractional director translates security into the language of the executive team, which is risk, cost, liability, and continuity. When the board asks whether the organization is protected, the director is the person who can answer honestly, with evidence, and with a plan for the gaps. When two departments disagree about who owns a problem, the director settles it. When the budget cycle comes around, the director makes the case in terms the CFO recognizes. Security that lives only in the guard shack never gets funded. Security that sits at the leadership table does.

Go Deeper

For the full definition of the role and how it compares to consultants and full-time hires, start with What Is a Fractional Security Director? The Complete Guide. My book Fractional Security Director expands on every part of this article, and Until Tested: Security Is Only Assumed lays out the P.R.O.O.F. framework for verifying that a program works.

Commissioner William Epps is an author and security leadership consultant. His books are published through E.P.P.S. Method Publishing Co.

Leave a comment

Get the Book

The ultimate guide for creators: strategies, stories, and tools to help you grow your craft.

Be Part of the Movement

Every week, Jordan shares new tools, fresh perspectives, and creator spotlights—straight to your inbox.

← Back

Thank you for your response. ✨

Creator Rising: A Playbook for a Meaningful Creative Life is your guide to building
not only income, but a creative life
worth living.

Inside you’ll find systems for sharing your work, habits that fuel inspiration, and ways to grow without losing
the spark that makes you create in the first place.