Tuesday, July 28, 2026

Top 5 This Week

Related Posts

Dan Ștefan, Fractional CISO: Why cybersecurity is a leadership decision, not just an IT issue

Discover insights from Dan Ștefan, a Fractional CISO with over 28 years of experience, on cybersecurity, risk management, NIS2, leadership, and how businesses can turn vulnerability into long-term resilience.

Dan Ștefan is a Fractional CISO with over 28 years of experience in IT infrastructure and a strategic vision backed by an Executive MBA.

His perspective comes from firsthand experience. He has seen what a company looks like when it is brought to a standstill by a risk no one anticipated, and he understands that security is not a technical issue—it is a leadership decision.

Today, he works with entrepreneurs and executives who want to transform security from a delegated problem into an owned responsibility, convinced that the difference between vulnerability and resilience is not technology itself, but the control system behind it.

You can learn more about his work at stefandan.com.

Fractional Insider: What is the most common mistake that eats away at a company’s profitability?

Dan Ștefan: I remember a day when a company couldn’t do absolutely anything—no invoices, no deliveries. Not because of a cyberattack or a virus, but because of an unresolved software licensing issue.

The entire business came to a halt. People were looking at one another. No one knew how long it would last, and no one knew what needed to be done.

On the surface, it looked like a technical problem. In reality, the issue was the absence of a control system capable of working before the crisis occurred.

The most common mistake? Believing that IT is working well simply because nothing serious has happened yet. Backups exist, but they’ve never been tested. Licenses are active, but no one knows when they expire. Everything seems fine—until the day it isn’t.

And that single day costs incomparably more than everything that could have been invested in prevention.

Fractional Insider: What is an uncomfortable truth that founders tend to ignore?

Dan Ștefan: Responsibility cannot be delegated.

You can outsource IT, hire someone to manage your computers, or sign a contract with an external support provider. But if customer data is lost tomorrow or your operations are shut down for three days, the legal responsibility won’t fall on your IT vendor. It will fall on you.

I understand why people avoid this reality. IT security seems complicated, boring, and disconnected from sales. But that very distance is what leaves you exposed—not because you lack capable technical people, but because you’ve never asked yourself one simple question: If my systems fail tomorrow, who is accountable, and what do we do?

That’s the uncomfortable question. And even more uncomfortable is the fact that until someone who is truly accountable asks it, the answer is usually, No one or I don’t know.

Fractional Insider: If you walked into a new company today, what would you change during the first 30 days?

Dan Ștefan: Nothing. During the first 30 days, I don’t change anything. I ask questions.

I’ve seen companies invest in expensive technology to solve problems they didn’t even understand. It looked impressive in the proposal, but disappointing in reality.

The first month is all about diagnosis:

Which systems are absolutely critical to the business?

What data, if lost, could bring the company to its knees?

How long can operations remain disrupted before the damage becomes irreversible?

Then comes fact-checking.

Has the backup actually been tested, or is it just a promise on paper?

Who has access to what, and why?

Are there documented procedures, or does everything depend on the memory of a single employee?

At the end of those 30 days, I present a clear picture of the company’s risks along with a prioritized action plan—not based on what’s technically interesting, but on what could cause the greatest damage if ignored.

Fractional Insider: Which performance indicator do most companies overlook?

Dan Ștefan: How many hours they can afford not to operate.

It’s not a technical metric—it’s a business decision.

Most companies don’t have a concrete answer. They know their revenue, profit margin, customer count, and even how many coffees they consume every month. But ask them how much a single day of system downtime costs, and you’re met with silence.

That number changes every IT-related decision.

If the answer is several thousand—or tens of thousands—of euros per day, then it clearly defines how much should be invested in business continuity and cybersecurity.

Without it, IT budgets are allocated based on intuition or on whoever shouts the loudest.

Once you know the real cost of downtime, investing to prevent it no longer feels like an expense.

Fractional Insider: In what situation should a company not hire a full-time executive and choose a Fractional CISO instead?

Dan Ștefan: When you already have an IT team that executes well, but no one who sees the bigger picture. When the company is growing rapidly and the infrastructure can no longer keep up with the business. When clients begin asking for proof of security that you simply don’t have.

That’s when you need a Fractional CISO. Not a full-time CISO, but executive-level expertise exactly when it matters. You pay for results, not for presence.

Fractional Insider: What is the biggest illusion founders have about growth?

Dan Ștefan: That if sales are going well, everything else will sort itself out.

I’ve seen it many times: the business grows quickly, new clients keep coming in, and the team expands. Meanwhile, behind that growth, processes and systems fail to keep pace. Procedures no longer reflect reality. No one looks up from sales long enough to check what’s happening underneath.

Growth doesn’t solve hidden problems. It amplifies them. Risks multiply along with the team.

Founders who understand this don’t treat security as a separate department. They treat it like the brakes on a sports car—they don’t make you drive slower; they allow you to drive faster, safely.

Fractional Insider: What do you consistently find broken across different companies?

Dan Ștefan: The absence of a person who is personally accountable.

It’s not a technology issue. Security solutions are in place. Backups exist. Passwords usually exist as well.

The real problem is that if you ask who ensures all of these things actually work properly, the answer is vague: “IT,” “the external provider,” or “the guy who handles the computers.”

When no one is personally accountable, responsibility becomes diluted. And when an incident occurs, that lack of ownership turns a manageable problem into a situation where no one knows what to do.

I’ve seen companies where backups existed, but no one had tested them for years. Everyone assumed someone else was checking.

That’s why the very first thing I do is simple: I assign a named owner to every major risk.

Fractional Insider: What decision could quickly increase profitability, yet companies still avoid making it?

Dan Ștefan: An IT cost audit.

Licenses paid for employees who left the company. Subscriptions activated for a project and then forgotten. Cloud resources running without being used.

Sometimes it’s negligence. Sometimes it’s simply the natural pace of growth—things are added faster than they’re reviewed.

Companies avoid this exercise because it doesn’t seem urgent.

In my experience, whenever I review IT invoices, I almost always find something: money being wasted without creating any value.

It’s the fastest profitability improvement you can achieve without selling a single additional product.

Fractional Insider: How does a Fractional CISO think differently from an internal executive?

Dan Ștefan: I come from the outside, and I have nothing to protect on the inside.

I don’t know who made the wrong decision three years ago or why no one dares to challenge it today. I don’t know which topics are considered sensitive or which ones are better left untouched. I have no personal interests within the organization.

That allows me to say things an internal employee often won’t—not because they don’t see the issues, but because they see them all too clearly and know exactly who might be offended.

An internal CISO gradually adapts to the company’s culture. Sometimes that’s beneficial. Other times, it leads them to accept risks they would have raised in their very first meeting.

Every engagement begins with one simple agenda: to tell the client exactly what I see, in the order that matters, without protecting anyone’s ego.

My style is direct—sometimes uncomfortable.

It’s not always easy. I once lost a client because I told them a truth they weren’t ready to hear.

I don’t regret it.

But I also won’t pretend it didn’t hurt.

Fractional Insider: What does a truly healthy company look like from the inside?

Dan Ștefan: It’s not a company without problems. It’s a resilient company.

Management understands its biggest risks—not in technical jargon, but in language decision-makers can understand.

They know what would happen if the main server failed tomorrow, and they know exactly what actions to take.

They know that access rights are reviewed regularly and that the employee who left two months ago no longer has access to anything.

There is a real plan, known by the people responsible for executing it.

And there is one clearly accountable person—not the IT department, not the external provider—who is responsible if something goes wrong.

A resilient company isn’t one that never falls.

It’s one that knows how to get back up.

Fractional Insider: What type of companies benefit the most from a Fractional CISO?

Dan Ștefan: Companies that have reached the point where IT can no longer be left to run on autopilot.

A major client starts asking for proof that their data is secure. A NIS2 or GDPR audit is approaching. Or the company has grown so quickly that no one knows exactly who has access to what anymore.

These companies already have either an internal IT team or an outsourced IT provider. What they’re missing is someone who can see the entire picture: where the real risks are, what needs to be addressed first, and how all of this will stand up to scrutiny from clients or regulators.

They need someone who can tell them where they truly are—not where they wish they were.

Fractional Insider: What is the most common mistake companies make when working with a Fractional CISO?

Dan Ștefan: Signing the contract and then relaxing.

I understand the instinct. You hire someone to take care of the problem, and you shift your attention back to sales.

But it doesn’t work that way.

I can map the risks, build the roadmap, and establish priorities. But the decision to actually implement change belongs to you.

If you don’t attend alignment meetings, if your team receives tasks but never has the time to complete them, or if every uncomfortable decision gets postponed, the entire project stalls.

The best results I’ve achieved have always come from decision-makers who understood one simple principle:

I bring the methodology.

They bring the commitment.

Without both, nothing moves forward.

Fractional Insider: Realistically, what results should companies expect within the first three to six months?

Dan Ștefan: The first result is simple—and underestimated: you finally know where you stand.

Not based on intuition. Not based on what your IT team tells you. But based on an independent assessment.

I’ve met entrepreneurs who had been running companies for ten years without ever having that level of clarity.

By month six, the essential controls are not only in place—they’ve been verified.

Backups have been tested, not merely mentioned in a report.

Access rights have been reviewed.

At least one crisis scenario has been rehearsed with the people responsible for executing it.

And here’s one of the strongest signs that things are moving in the right direction:

Your team starts asking the right questions without waiting for me to ask them first.

When that happens, I know we’ve built something that will remain after I’m gone.

Fractional Insider: What distinguishes an outstanding Fractional CISO from an average one?

Dan Ștefan: An average one delivers reports.

A great one changes decisions. Paper accepts anything.

You can write dozens of pages about vulnerabilities and recommendations. But if, at the end of the engagement, management continues making the same decisions as before, nothing has truly been accomplished.

A strong Fractional CISO knows how to communicate with different people in different languages.

With the IT team, they speak technically and concretely. With the CEO, they speak in terms of risk and business impact. With the CFO, they speak in numbers and financial consequences. And they know when silence is more powerful than any argument.

Real value becomes visible during difficult moments—when you have to explain that a decision made three years ago has become today’s problem, or that the approved budget doesn’t cover the level of risk the company has chosen to accept.

That requires more than expertise.

It requires the courage to tell uncomfortable truths and the credibility that comes from having done it successfully before.

I have moments of hesitation too.

Moments when I know what I have to say will be difficult to hear. In those moments, I remind myself why I chose this work: Not to be liked. But to be useful.

Fractional Insider: What is one business or leadership belief that many people would disagree with?

Dan Ștefan: Cybersecurity is not the IT department’s responsibility. IT executes.

But the risk belongs to you—and so do the consequences: regulatory fines, lawsuits, lost contracts, and reputational damage.

Many executives treat cybersecurity as a technical issue that can simply be delegated and forgotten.

Then the first serious incident happens, and they discover an uncomfortable reality:

You can delegate operational work.

You cannot delegate accountability.

I’m not saying you need to understand how a firewall works.

I’m saying you need to know that your company has one, that it is functioning properly, that it has been tested, and that there is a specific person—with a name and surname—who is directly accountable to you for it.

That is what security leadership looks like.

Dan Ștefan’s interview highlights that cybersecurity is no longer just an IT responsibility—it is a strategic leadership priority. From risk management and business continuity to NIS2 and GDPR compliance, organizations that take a proactive approach to security are better equipped to build resilience, protect their operations, and achieve sustainable growth.


LEAVE A REPLY

Please enter your comment!
Please enter your name here

Popular Articles