Fractional CISO Services

Seattle
CISO

Enterprise-grade security leadership for organizations that cannot afford to get it wrong.

I bring the same rigorous, AI-augmented assessment methodology I use for the Defense Industrial Base to Pacific Northwest companies that need mature cybersecurity programs — without the cost or overhead of a full-time CISO.

80+
Assessments Led
DoD
Vetted Assessor
NIST
800-171 / CMMC
AI
Augmented Process
What I Deliver

Practical Security Leadership

Core Offering
Fractional CISO

Part-time, embedded security leadership at the executive level. Policy, risk management, board reporting, and program maturation on a schedule that fits your business.

Compliance
CMMC & NIST 800-171

System Security Plans, gap analysis, POA&Ms, and control implementation that stands up to DIBCAC or C3PAO assessment — because I have led those assessments.

Acceleration
AI-Augmented Delivery

The same methodology that reduced SSP drafting time from weeks to hours. Faster, higher-quality artifacts with explicit source citations.

Readiness
Pre-Assessment Reviews

Objective third-party reviews of your current program before a formal assessment or audit. Find the gaps that matter.

How I Work

The Assessment Mindset

Phase 1
Discovery & Mapping
Current state, risk appetite, regulatory drivers

Deep-dive interviews, architecture review, and evidence collection. I map controls to your actual operations — not theoretical policies.

Business ContextTechnical RealityRegulatory Scope
Phase 2
AI-Augmented Analysis
RAG models trained on your evidence base

Iterative synthesis of System Security Plans, gap analysis, and draft POA&Ms with inline citations back to source documentation.

Phase 3
Implementation & Maturation
Practical, prioritized roadmap

Hands-on or advisory support to close gaps. I prioritize what actually moves the needle on risk and audit readiness.

PolicyTechnical ControlsTraining
Why This Matters

Real Assessment Experience

Most fractional CISOs have never sat on the other side of the table during a formal DIBCAC assessment. I have led them. I know exactly what assessors look for.

🔐
U.S. Government Vetted
Active federal background investigation
📋
DIBCAC / C3PAO Experience
Led comprehensive assessments

Core Competencies

Frameworks
NIST SP 800-171A CMMC 2.0 DFARS SSP Authoring
Technical
RAG AI Models Control Verification
Background

The Assessor Perspective

Barry Morgan is a U.S. Navy submariner turned enterprise technologist with 20+ years experience. Since 2022 he has served as Cybersecurity Assessor with DCMA/DIBCAC, pioneering AI-augmented methodologies.

Seattle CISO makes that assessor-grade expertise available to organizations before they face a formal assessment.

Ready for Clarity?

Whether you are preparing for a CMMC assessment or need an interim security leader — I am ready to help.