Security Leadership Seat · USD 6,500 / month
90-day CISO mandate: Northgate Health
Alex Morgan runs the security function. Accepting risk stays with the board, in writing, every time.
Northgate handles patient data and has no security leader. The temptation with a fractional CISO is to hand over the whole problem, including the decision to live with a risk. This mandate deliberately does not do that, and clause 3 explains why that distinction is the most important line in the document.
From 1 February, Alex owns the security programme, the control register, incident response and spend to USD 30,000. Every decision to accept a residual risk is the board's, taken in writing on a standard form, with Alex's recommendation recorded alongside it whether or not the board follows it.
Document control
- Document number
- MAN-NGH-01
- Version
- 1.0
- Effective
- 1 February 2027
- Owner
- Alex Morgan, Fractional CISO
- Approved by
- Northgate Health board, resolution 2027-03
- Next review
- 1 May 2027
- Classification
- Confidential. Board and executive
Why
The position at mandate start
| Observed | Evidence |
|---|---|
| No named security owner | Security sits informally with the platform lead, alongside his day job |
| No risk register | None exists. Risks are discussed and not recorded |
| No incident response plan | Two incidents in 18 months, both handled well and neither documented |
| Access reviews have never run | Confirmed. 240 staff, no periodic review |
| Patient data in scope | Yes. This is why the mandate exists |
| Engineering practice is strong | Encryption, MFA, logging and backups all in place and evidenced |
As with most companies this size, the technical controls are better than the governance. Northgate can do security; what it cannot currently do is show what it decided, who decided it and when.
Authority
Decision rights
| Alex decides | Executive decides | Board decides | |
|---|---|---|---|
| Security programme and its priorities | Yes | ||
| The risk register and how risks are scored | Yes | ||
| Security policies and standards | Yes | ||
| Incident response plan and running an incident | Yes | ||
| Security spend to USD 30,000 | Yes | ||
| Selecting testers, auditors and tooling | Yes | ||
| Stopping a release on security grounds | Yes, with same-day escalation | ||
| Security spend above USD 30,000 | Yes | ||
| Accepting a residual risk, any severity | Board, in writing | ||
| Notifying a regulator or a patient | Board, with legal advice | ||
| Anything contractual with a customer | Yes | ||
| Disciplinary action following an incident | People team |
The line
Why a CISO must not accept risk
A security leader who can both identify a risk and decide to live with it is a single point of failure in the governance, and it is the arrangement most companies default to without noticing. It looks like delegation. It is actually the removal of a check.
| Step | Who | Recorded as |
|---|---|---|
| Identify and score the risk | Alex | Risk register entry, dated |
| Recommend treat, transfer, avoid or accept | Alex | Written recommendation against the entry |
| Decide | The board | Risk acceptance form, signed |
| Record a decision that differs from the recommendation | The board | Both positions kept, side by side |
| Review accepted risks | Alex prepares, board reviews | Quarterly, every accepted risk |
| Escalate a material change | Alex, same day | In writing to the chair |
The fourth row is the one that earns its place. If the board accepts a risk against Alex's recommendation, both the recommendation and the decision stay on the record. That is not a defensive measure for the CISO, it is how the next board knows what this board knew.
Plan
What the 90 days does
-
Incident response plan, one page
Who decides, who calls, who tells customers, in what order. Before anything else, because an incident in week two would otherwise be handled the way the last two were.
-
Risk register built
Every risk scored and recorded. Nothing accepted yet.
-
First risk acceptance session with the board
The board sees what it is carrying, probably for the first time.
-
Access review, all 240
Quarterly cadence set afterwards. This always finds leavers with live accounts.
-
Penetration test scoped and a firm engaged
Alex scopes and selects. The testing is done by a qualified firm, not by the mandate.
-
Board review
A register, a plan, a cadence and a set of decisions the board has consciously taken.
Escalation
What reaches the chair the same day
- Any suspected incident involving patient data, confirmed or not
- Any risk newly scored as critical
- Any release stopped on security grounds, with the reason
- Any regulator, customer or researcher contact about security
- Any material change to a previously accepted risk
- Any circumstance in which Alex believes the board should take legal advice
| Measure | Today | What good looks like by 1 May |
|---|---|---|
| Risk register | None | Complete, scored, reviewed quarterly |
| Accepted risks with a board signature | 0 | Every one of them |
| Incident response plan | None | Written, and rehearsed once |
| Access reviews | Never run | Complete, quarterly cadence set |
| Penetration test | Never | Scoped, firm engaged, booked |
| Security incidents | 2 in 18 months | Not a measure. Reported, never targeted |
Incident count is deliberately not a target. Targeting it rewards not reporting, which is the single worst outcome available to a security programme.
Document control
Revision history
| Version | Date | Author | Change |
|---|---|---|---|
| 1.0 | 20 January 2027 | Alex Morgan | Agreed by board resolution 2027-03. Effective 1 February 2027. |
| 0.3 | 15 January 2027 | Alex Morgan | Draft. Clause 3 expanded after the chair asked why the CISO could not accept low severity risks. The answer is in the clause. |
| 0.2 | 12 January 2027 | Alex Morgan | Draft. Release-stop authority added, with same-day escalation attached to it. |
| 0.1 | 8 January 2027 | Alex Morgan | First draft from the security readiness review of 19 December. |