Skip to content
Security leadership · Education & EdTech

Fractional CISO for Education & EdTech

An accountable security leader who owns risk, satisfies the regulator, and unblocks the deal, part-time.

Why it matters in education & edtech

In EdTech the product is the business, but you're also handling children's data and selling into risk-averse buyers. You have to ship great learning software and be trusted with it: CTO and CISO in one.

  • Turning pedagogy and content into a product that scales, architecture, data model and roadmap
  • Shipping AI-powered learning features (tutoring, marking, personalisation) that are genuinely useful
  • Passing the security and data-protection due diligence schools and trusts run, and protecting children's data
  • Integrating cleanly (SSO, MIS/SIS, LTI/OneRoster) and staying reliable through term-start spikes

What you get

  • Security strategy and a risk-led, prioritised improvement plan
  • Governance: policies, risk register, and a working risk committee
  • Readiness for ISO 27001, SOC 2, Cyber Essentials, and customer security reviews
  • Incident response planning, tabletop exercises, and supplier assurance
  • Board reporting that translates risk into decisions

Frameworks & standards

Applied AI / LLMsUK GDPR (children)Cyber Essentials

How we work in education & edtech

We've been the CTO building and scaling an EdTech product first-hand, and we own the security side too, so we help with the architecture, AI and integrations and the trust, privacy and controls that unlock school and trust deals.