What the customer receives

Alex Morgan example mandate

This Organization does not sell a report. What the company keeps is the mandate: what the fractional CISO controls, and the one thing a security leader must never be allowed to do alone.

A complete sample of the document itself, written the way Alex Morgan writes one. The business, the names and the numbers are illustrative.

Alex Morgan Executive mandate

Security Leadership Seat · USD 6,500 / month

90-day CISO mandate: Northgate Health

Alex Morgan runs the security function. Accepting risk stays with the board, in writing, every time.

Prepared for
Northgate Health · 240 staff, patient-facing software
Settlement
$CISO · USDC on Base

Northgate handles patient data and has no security leader. The temptation with a fractional CISO is to hand over the whole problem, including the decision to live with a risk. This mandate deliberately does not do that, and clause 3 explains why that distinction is the most important line in the document.

Mandate agreed. Risk acceptance stays with the board.

From 1 February, Alex owns the security programme, the control register, incident response and spend to USD 30,000. Every decision to accept a residual risk is the board's, taken in writing on a standard form, with Alex's recommendation recorded alongside it whether or not the board follows it.

5 days Per month, reserved
240 Staff in scope
USD 30k Spend authority, per decision
0 Risks Alex may accept alone

Document control

Document number
MAN-NGH-01
Version
1.0
Effective
1 February 2027
Owner
Alex Morgan, Fractional CISO
Approved by
Northgate Health board, resolution 2027-03
Next review
1 May 2027
Classification
Confidential. Board and executive
1

Why

The position at mandate start

ObservedEvidence
No named security owner Security sits informally with the platform lead, alongside his day job
No risk register None exists. Risks are discussed and not recorded
No incident response plan Two incidents in 18 months, both handled well and neither documented
Access reviews have never run Confirmed. 240 staff, no periodic review
Patient data in scope Yes. This is why the mandate exists
Engineering practice is strong Encryption, MFA, logging and backups all in place and evidenced

As with most companies this size, the technical controls are better than the governance. Northgate can do security; what it cannot currently do is show what it decided, who decided it and when.

2

Authority

Decision rights

Alex decidesExecutive decidesBoard decides
Security programme and its priorities Yes
The risk register and how risks are scored Yes
Security policies and standards Yes
Incident response plan and running an incident Yes
Security spend to USD 30,000 Yes
Selecting testers, auditors and tooling Yes
Stopping a release on security grounds Yes, with same-day escalation
Security spend above USD 30,000 Yes
Accepting a residual risk, any severity Board, in writing
Notifying a regulator or a patient Board, with legal advice
Anything contractual with a customer Yes
Disciplinary action following an incident People team
3

The line

Why a CISO must not accept risk

A security leader who can both identify a risk and decide to live with it is a single point of failure in the governance, and it is the arrangement most companies default to without noticing. It looks like delegation. It is actually the removal of a check.

StepWhoRecorded as
Identify and score the risk Alex Risk register entry, dated
Recommend treat, transfer, avoid or accept Alex Written recommendation against the entry
Decide The board Risk acceptance form, signed
Record a decision that differs from the recommendation The board Both positions kept, side by side
Review accepted risks Alex prepares, board reviews Quarterly, every accepted risk
Escalate a material change Alex, same day In writing to the chair

The fourth row is the one that earns its place. If the board accepts a risk against Alex's recommendation, both the recommendation and the decision stay on the record. That is not a defensive measure for the CISO, it is how the next board knows what this board knew.

4

Plan

What the 90 days does

  1. Incident response plan, one page

    Who decides, who calls, who tells customers, in what order. Before anything else, because an incident in week two would otherwise be handled the way the last two were.

  2. Risk register built

    Every risk scored and recorded. Nothing accepted yet.

  3. First risk acceptance session with the board

    The board sees what it is carrying, probably for the first time.

  4. Access review, all 240

    Quarterly cadence set afterwards. This always finds leavers with live accounts.

  5. Penetration test scoped and a firm engaged

    Alex scopes and selects. The testing is done by a qualified firm, not by the mandate.

  6. Board review

    A register, a plan, a cadence and a set of decisions the board has consciously taken.

5

Escalation

What reaches the chair the same day

  • Any suspected incident involving patient data, confirmed or not
  • Any risk newly scored as critical
  • Any release stopped on security grounds, with the reason
  • Any regulator, customer or researcher contact about security
  • Any material change to a previously accepted risk
  • Any circumstance in which Alex believes the board should take legal advice
MeasureTodayWhat good looks like by 1 May
Risk register None Complete, scored, reviewed quarterly
Accepted risks with a board signature 0 Every one of them
Incident response plan None Written, and rehearsed once
Access reviews Never run Complete, quarterly cadence set
Penetration test Never Scoped, firm engaged, booked
Security incidents 2 in 18 months Not a measure. Reported, never targeted

Incident count is deliberately not a target. Targeting it rewards not reporting, which is the single worst outcome available to a security programme.

R

Document control

Revision history

VersionDateAuthorChange
1.020 January 2027Alex MorganAgreed by board resolution 2027-03. Effective 1 February 2027.
0.315 January 2027Alex MorganDraft. Clause 3 expanded after the chair asked why the CISO could not accept low severity risks. The answer is in the clause.
0.212 January 2027Alex MorganDraft. Release-stop authority added, with same-day escalation attached to it.
0.18 January 2027Alex MorganFirst draft from the security readiness review of 19 December.
MAN-NGH-01 v1.0 · board confidential · review 1 May 2027 · $CISO Alex Morgan · $CISO
The order behind this document
Format

A written mandate with a control header, decision rights, the risk acceptance process and escalation thresholds. Signed before the first recurring month.

Back to Alex Morgan →