Services
Fractional CISOFractional CIOAI Readiness & Security AuditStrategic Implementation
Who we serve
NonprofitsChurches & ministriesSmall businessesMSP partners
Company
AboutCase studiesInsightsContactStart with a conversation →

Thursday · 4:52 PM · the executive director’s inbox

The renewal arrives with forty questions.

Multi-factor authentication. Tested backups. An incident response plan. Fourteen days to answer, and nobody is certain what the honest answers are.

New message4:52 PM
Cyber liability renewal — underwriting
Action required: security questionnaire (40 items)
Please complete the attached application within 14 days. Renewal terms are contingent on responses regarding MFA, backup testing, endpoint protection, and incident planning…
DUE IN 14 DAYS

Friday · 9:14 AM · the staff channel

Someone already pasted the donor list into an AI tool.

To “clean it up.” No policy said not to. No one knows where it went.

#staff-general9:14 AM
JR
Jordan · Developmentfyi I dropped the donor export into ChatGPT to dedupe it — worked great, want me to do the members list too?
SM
Sam · Programswhich account did you use? does that go anywhere?
JR
Jordanmy personal one… is that a problem?

Monday · 7:30 AM · the board chair

“Are we protected?

A fair question. The MSP sends a report every month. The firewall is managed. And still nobody in the building can answer it in one sentence.

New message7:30 AM
Board Chair
Re: Cyber insurance renewal
Saw the questionnaire on the agenda. Before Thursday’s meeting — are we protected? What are our top three risks, and who owns them? Keep it to a page.
BOARD MEETING · THURSDAY

The part nobody says out loud

Nobody in the building owns this.

Not because the team isn’t capable. Because the job belongs to an executive you can’t hire full-time.

Skip intro

Fractional CIO & CISO leadership for nonprofits and small businesses.

A part-time technology and security executive with public-company and federal experience — executive judgment on security, compliance, and safe AI adoption, without the executive salary.

Leadership experience
ExpediaConcurAccoladeVacasaCoalfireU.S. NavyExpediaConcurAccoladeVacasaCoalfireU.S. Navy

What we do, in eleven words

Executive
judgment
on
security,
compliance,
and
AI.
Without
the
executive
salary.

How we work

Three ways to put a CIO and CISO on your side.

Most clients start with a 30-day audit, then keep us on as their fractional executive. Some need hands on the keyboard for a defined project. Each one is scoped in a conversation, not a form.

Entry point · 30 days

AI Readiness & Security Audit

A fixed-scope, 30-day assessment of your AI strategy, security posture, and compliance gaps. You get a prioritized roadmap your board can read and your IT partner can execute — not a 90-page PDF that gathers dust.

  • Where AI is already in use, sanctioned or not, and what it touches
  • Security posture against NIST CSF 2.0, mapped to the frameworks your customers ask about
  • A ranked, costed roadmap with the first 90 days spelled out
NIST CSF 2.0 · current-state tiers
Deliverable · prioritized roadmapAbout the audit
Ongoing · monthly retainer

Fractional CIO / CISO Most popular

A part-time technology executive on your leadership team. Strategy, vendor oversight, board reporting, compliance, and incident response — the calls a CIO and CISO make, made by one who has held both titles.

  • Monthly steering with leadership; quarterly reporting for the board
  • Owner of your risk register, policies, and vendor and cyber-insurance questionnaires
  • First call when something goes wrong, with a plan already written
Where the fractional executive sits
Cadence · monthly + quarterly boardAbout the retainer
Project · scoped per engagement

Strategic Implementation

Hands-on delivery when the roadmap needs building: AI integration with guardrails, security program rollouts, and automation that connects the tools you already own — no new software to buy.

  • Governed AI workflows on top of your existing systems
  • Security program build-outs: policies, controls, evidence, and the people who run them
  • Fixed scope, fixed timeline, one accountable executive
Only your tools, plus the guardrails
Terms · custom, scoped per projectAbout implementation

What a fractional executive actually does

The work between the org chart and the outage.

01of 06
Strategy

A technology plan the board can fund.

Three-year roadmap, annual budget, and the two or three bets that actually move the mission. Written for trustees, not engineers.

ROADMAPBUDGETBOARD DECK
Security

A program, not a product.

Controls chosen for your risk, an owner for each one, and evidence you can hand to an auditor, an insurer, or an enterprise customer.

NIST CSF 2.0SOC 2ISO 27001
AI governance

Adopt AI without inheriting its risk.

An acceptable-use policy, a tool inventory, and guardrails around the workflows that touch member, donor, or patient data.

NIST AI RMFPOLICYINVENTORY
Compliance

Questionnaires answered with a straight face.

HIPAA, PCI DSS, CMMC, grant and cyber-insurance requirements — mapped once to a single control set so you stop answering the same question five ways.

HIPAAPCI DSSCMMC
Vendors & MSPs

Someone on your side of the contract.

Renewal reviews, SLA accountability, and a second opinion before the next platform purchase. Your IT provider gets a peer, not a critic.

RENEWALSSLA REVIEWDUE DILIGENCE
Incident response

The plan exists before the phone rings.

Tabletop exercises, a written playbook, insurer and counsel on speed dial, and a calm voice on the call when it matters.

PLAYBOOKTABLETOPCOMMS

Find your situation

What’s on your mind?

14 situations
Cyber-insurance renewal

The insurer sent a forty-question form.

Answer it honestly, fix what is missing, keep the evidence for next year.

Where to start →
AI in the building

Staff are already using AI with our data.

A one-page policy, a tool inventory, guardrails on the workflows that matter.

Where to start →
Customer diligence

A big customer wants SOC 2.

Control set, evidence, auditor relationship — and the questionnaires that arrive first.

Where to start →
Board question

The board asked, “Are we protected?”

A quarterly report a trustee can read in ten minutes, with the decisions stated plainly.

Where to start →
MSP relationship

We pay an MSP. Are we actually protected?

An independent look, then a peer on your side of the contract.

Where to start →
Grant requirement

The grant asks for a cybersecurity policy.

A written program you can honestly attest to, mapped to the terms of the award.

Where to start →
Church technology

Sunday cannot fail and member data must be safe.

Church-management security, broadcast readiness, AI guidelines for volunteers.

Where to start →
HIPAA

We handle patient information.

HIPAA obligations mapped once to a control set that answers every questionnaire.

Where to start →
Something went wrong

We think we've been breached.

A written playbook, insurer and counsel on speed dial, and an executive on the call.

Where to start →
Budget and roadmap

Technology decisions are made by whoever is in the room.

A three-year roadmap and a budget that holds, written for trustees.

Where to start →
Where do we stand?

We want an honest baseline before we spend.

A 30-day audit that ends in a prioritized, costed roadmap.

Where to start →
Build something

The roadmap needs building.

Governed AI workflows and automation on the tools you already own.

Where to start →
CMMC

We sell to the Department of Defense.

CMMC readiness and evidence your engineers can implement against.

Where to start →
MSP partner

Our clients keep asking for things engineers shouldn't own.

A white-label CISO bench under your name.

Where to start →

Nothing matched that phrase — which usually means it is a conversation, not a search. Book twenty minutes →

Track record

Twenty years securing public companies and federal systems. Now on call for yours.

The judgment behind ForEffect was formed running IT and security for travel, healthcare, and government platforms, auditing banks and credit unions, and serving as a U.S. Navy officer. That is the bar we bring to a church, a clinic, or a twelve-person firm.

0+Years in security leadership
0Days · audit to roadmap
0Business day to a reply
CISSPCertified Information Systems Security Professional(ISC)²
CISACertified Information Systems AuditorISACA
CMACertified Management AccountantIMA
NIST CSF 2.0NIST AI RMFCMMCHIPAAPCI DSSSOC 2ISO 27001

Client voices

Leaders who wanted a partner, not a vendor.

“What stood out about working with Mike and ForEffect was that they took the time to understand how our church actually operates before writing a line of code.”

AJ
Alex JohnsonExecutive Pastor, Gold Creek Community Church

“As an early-stage company, we couldn’t justify a full-time security hire, but we still had enterprise customers asking hard questions.”

TR
Tristan ReesCo-Founder & COO, Code Lexica

Leadership

One executive. Both chairs. Fifteen years of holding them.

Mike McGee has led IT and information security as a VP and CISO inside public companies and federal programs, audited financial institutions as an IT security auditor, and served thirteen years as a surface warfare officer in the U.S. Navy. He founded ForEffect so organizations without a seven-figure IT budget could have the same quality of decision-making.

He holds an MBA in Financial Management from the Naval Postgraduate School and a B.S. in Economics from the U.S. Naval Academy — which is why the budget conversation and the security conversation happen in the same meeting.

VP, IT & Information SecurityVACASA
CISO · SVP Government SolutionsACCOLADE
Director, Information SecurityEXPEDIA
Director, Security & ComplianceCONCUR
IT Security AuditorCOALFIRE
Surface Warfare OfficerU.S. NAVY

Read Mike’s full background

Who we serve

Built for the organizations a full-time CISO was never priced for.

Each of these has its own page, its own proof, and the same first conversation.

Questions we hear

Frequently asked

What is a fractional CIO or CISO?
A senior technology or security executive who works with your organization part-time — typically a few days a month — carrying the same responsibilities a full-time CIO or CISO would: strategy, risk, vendor oversight, compliance, board reporting, and incident leadership. You get the judgment without the salary, benefits, and recruiting cost of a full-time hire.
How is ForEffect different from a managed service provider (MSP)?
An MSP runs your technology day to day: help desk, patching, backups, monitoring. ForEffect sits on your leadership team and decides what should be run, why, and to what standard — then holds vendors, including your MSP, accountable to it. Most of our clients keep their MSP; we work alongside them.
What does an engagement cost?
Every engagement is scoped in the first conversation. The 30-day AI Readiness & Security Audit is a fixed fee; the fractional CIO/CISO retainer is a flat monthly fee based on cadence and scope; implementation projects are quoted per project. We publish real numbers when we scope, not surprises after.
Where do you work?
ForEffect is based in Mill Creek, Washington, in the Seattle area, and works remote-first. Most clients are in Washington State; we also serve organizations across the United States, with on-site time when it matters.
How quickly can we start?
An audit can usually begin within two weeks of the first conversation. Retainers typically start with a 30-day onboarding month so the first steering meeting has a real risk register in front of it.

One call, no deck

Start with a conversation.

Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.

info@foreffectai.comSeattle · Remote-first

Book a 20-minute conversation

Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.

Choose a time
or
Send a short note instead