Skip to main content

Frequently asked questions

Understand the role before you consider the engagement.

Moat’s value depends on clear expectations: what fractional cybersecurity leadership does, how it works with existing providers, and where the scope ends.

The short version

Moat coordinates priorities and people so leadership can make informed decisions.

Specific deliverables and cadence are agreed before work begins.

Do you replace our IT provider?

No. Moat works alongside your existing IT provider. Your provider continues the technical work in its scope while Moat helps leadership set priorities, assign responsibilities, coordinate the parties involved, and track progress.

What does a fractional CISO do?

A fractional CISO provides part-time cybersecurity leadership. For Moat clients, that means turning business concerns into a prioritized plan, clarifying who owns each action, coordinating providers and specialists, and giving leadership useful reporting for decisions.

What is included in an engagement?

The exact scope is agreed before work begins. A typical engagement can include a prioritized action plan, a risk and action register, provider coordination, organization of agreed evidence, and recurring leadership reporting. Technical implementation and specialist services require a separate scope.

How is pricing determined?

Pricing follows the agreed scope, the organization’s size and complexity, and the amount of coordination required. The discovery call is used to understand the situation before Moat recommends an engagement.

What happens during the discovery call?

In 20 minutes, Lester will learn what prompted the conversation, how cybersecurity responsibilities are handled today, and what decision or deadline is in front of leadership. If Moat appears useful, the next step is a clearly defined scope.

Do you guarantee compliance or insurance approval?

No. Moat helps organize priorities, responsibilities, evidence, and decision-making. Regulators, clients, auditors, and insurers make their own determinations, and no responsible advisor can guarantee their approval.

A practical first step

Have a question tied to a real deadline or decision?

Start with a focused conversation about the deadline, decision, or security responsibility in front of your organization.