

About Author
Hannah Lloyd
Hannah Lloyd is CRO and co-founder of enhanced.io. She leads global new business generation and works directly with MSP partners to build and sell security practices.
enhanced.io, the channel-only Open XDR SOCaaS for MSPs
TL;DR
"Fractional" sounds like less, but a well-run Fractional Security Director model is right-sized, not cut-price.
A named, CISSP-certified security director works through the MSP, backed by a 24/7 SOC.
This is different to how some competitors, like SentinelOne Vigilance, position their managed offering.
Clients get a real point of contact, not an anonymous ticket queue.
The model works because it is embedded in the MSP relationship, not bolted on top of it.
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. The reason I mention that is because the Fractional Security Director model only works if it sits inside that same channel-only structure.
I was having a conversation last week with a partner who told me their client had flinched at the word "fractional." It sounded like a discount version of the real thing. I get why, and I think that reaction is worth unpacking.
Why "fractional" sounds like a compromise
Just to give you a bit of context, most of the pushback I hear on "fractional" comes from an assumption that it means part-time attention from someone who is really working ten other accounts and barely knows your name. That is a fair worry, because a lot of the market has trained clients to expect exactly that.
What tends to happen instead, when the model is built properly, is that the client gets a named, CISSP-certified security director who works through the MSP and stays consistent over time. Not a rotating cast. Not a support ticket. A person.
What a Fractional Security Director actually is
Fractional Security Director | Typical vCISO retainer | |
|---|---|---|
Connected to 24/7 SOC | Yes, one integrated model | Usually separate, advisory only |
Consistency | Same named person over time | Often rotates between engagements |
Client visibility | Named from day one | Varies by provider |
A Fractional Security Director (FSD) is a named, CISSP-certified security leader who works in partnership with the MSP, backed by a 24/7 SOC that handles detection and triage around the clock. The client knows who the FSD is from day one. This is not described as white-label by default, because the whole value is that the client can see the expertise sitting behind their MSP relationship.
What we mean by that is the FSD shows up to strategy conversations, quarterly reviews, and board-level updates. The SOC does the around-the-clock detection work. The FSD does the translation and the relationship.
I think of one partner, a regional MSP who kept losing healthcare prospects to bigger providers with an in-house CISO on staff. Once they could point to a named FSD in the room, that objection stopped coming up. Same conversation, different outcome, because the client finally had a person to trust, not just a tool to evaluate.
How this compares to SentinelOne Vigilance
I know some partners come to us already comparing options, so let me be direct about where the difference sits. SentinelOne Vigilance is positioned primarily around managed detection and response, with security expertise delivered as an extension of the platform team rather than as a named, embedded advisor for a specific client relationship.
The enhanced.io model puts the named FSD at the center, with the MSP retaining the relationship throughout. Does that make sense? It is less about which platform detects more, and more about who the client actually gets to talk to when something matters.
What the client actually experiences
Day to day, the client sees a consistent security lead who understands their business, not just their environment. Quarterly reviews come from that same person. Escalations get routed to someone who already has context, instead of starting from zero every time.
What I've seen work well is MSPs introducing the FSD early, even before a major incident, so the relationship is already established when it matters most.
Where this fits for your client base
If you have clients who keep asking "who is actually looking after our security," this is the answer to that question. Take a look at how enhanced.io structures the platform around this model, or see it in practice in the Shackleton Technologies story.
It pairs naturally with the wider security-as-a-business conversation, and with the Open XDR business case that underpins it.
About enhanced.io
enhanced.io is a channel-only Open XDR SOCaaS built exclusively for MSPs, with 400+ integrations across endpoint, network, cloud, identity and IoT/OT. It sells only through MSP partners, never direct to end clients, and integrates with the EDR or MDR an MSP already runs rather than replacing it.
FAQ
What does CISSP certification mean for the client?
It means the person leading their security strategy holds a recognized, rigorous credential in security leadership, not just a technical certification. It is a signal of depth in governance and risk, not only tooling.
Is the Fractional Security Director the same person every time?
Does the FSD replace our account manager?
How is this different from a traditional vCISO retainer?
What size of client actually needs this?
Can smaller MSPs offer this without hiring their own CISSP?