Fractional IT Director
Who's making sure your IT company is doing what your business actually needs?
I’m Justin Law. I’ve spent more than 30 years in IT, and I work with growing businesses that need experienced IT leadership but aren’t ready to put a $150K+ IT Director on payroll.
I don’t replace your IT company or in-house team. I work on your side of the table — helping you manage vendors, understand your security risks, plan IT spending, and make better technology decisions for the business.
Senior IT leadership. Without the full-time cost.
Does any of this sound familiar?
The questions keeping business owners up at night
“Our IT company says we’re secure. I just don’t know how I’d verify that.”
You shouldn’t need to be an IT expert to know whether your business is adequately protected. Someone independent should be asking the questions you don’t know to ask.
“If we got hit with ransomware tomorrow, I honestly don’t know what we’d do.”
Having backups and cybersecurity tools is important. Knowing they work and knowing exactly what happens when something goes wrong is something else entirely.
“I don’t even know when half of our software and IT contracts renew.”
Contracts renew. Prices increase. Services get added and forgotten. Someone should be keeping track and making sure your vendors are still earning your business.
“Nobody here really owns IT. It just sort of… happens.”
This is the problem I solve.
Your IT provider may be doing a perfectly good job. But someone on your side needs to own the big-picture decisions about technology, security, vendors, risk, and spending.
What Is a Fractional IT Director?
An experienced IT Director on your side of the table
Your MSP provides IT services. Your software vendors sell software. Your cybersecurity providers sell security products.
There’s nothing wrong with that. But each of them naturally sees your business through the lens of what they provide.
I represent you.
My job is to ask the questions that someone inside the business needs to be asking:
- Do we actually need this?
- Is this quote reasonable?
- Are we adequately protected?
- Why hasn’t this issue been fixed?
- What happens if this system goes down?
- What should we be budgeting for next year?
- Is this technology solving a business problem, or are we buying it because somebody wants to sell it to us?
I’m not tied to an MSP, hardware manufacturer, or software company. I don’t make money by selling you more technology.
I make money by helping you make better decisions about it.
What You Get
What I actually help with
Vendor Management
I’ll help you manage the IT vendors.
I’ll review contracts and proposals, sit in on important vendor calls, ask the questions that need asking, and help make sure you’re getting what you’re paying for.
Security Oversight
An independent set of eyes on your security.
Your security shouldn’t be evaluated only by the company selling or managing your security products. I’ll help identify the real risks, prioritize what needs fixing, and make sure important issues don’t disappear into a report somewhere.
IT Budget Planning
No more surprise IT spending.
We’ll build an actual technology budget based on where the business is going — so you’re planning for major expenses instead of reacting to them one invoice at a time.
Leadership & Planning
Technology decisions in business terms.
You don’t need another person throwing acronyms around a conference room. I’ll help your leadership team understand the options, costs, risks, and tradeoffs so you can make informed decisions.
Disaster & Incident Readiness
Know what happens before something goes wrong.
Backups aren’t a disaster recovery plan. We’ll make sure responsibilities are clear and there’s a practical plan for keeping or getting the business running when something fails or you’re hit with a cyber incident.
Compliance & Cyber Insurance
Understand what you’re actually being asked to do.
Cyber-insurance applications, customer security questionnaires, and compliance requirements can get technical quickly. I’ll help translate those requirements into practical IT actions and work with your vendors to address them.
Why Get Fractional IT?
Cheap IT and cost-effective IT aren't the same thing
Almost every small business I’ve worked with has felt pressure to control IT costs. That’s completely reasonable.
But there’s an important difference between asking:
“What’s the cheapest way to do this?”
and:
“What’s the most cost-effective way to do this?”
I’ve spent more than 30 years watching businesses spend money on technology they didn’t need — and watching others save money in places that eventually cost them far more.
Neither is good IT management.
When it’s done right, IT isn’t just another expense on the P&L. It protects the business, helps employees work efficiently, controls risk, manages costs, and supports growth.
My job isn’t to convince you to spend more on technology.
It’s to help you know where spending money makes sense — and where it doesn’t.
I've seen what "saving money on IT" can cost
At one company I walked into, more than 700 computers had been installed using the same Microsoft Office license.
By the time I arrived, Microsoft had already served the company with an official audit demand.
I had to figure out what they actually had, work with Microsoft to get the licensing corrected, and then explain something uncomfortable to the executives:
Buying all those licenses wasn’t going to be cheap.
But the potential penalties for being out of compliance were going to be a whole lot more expensive.
That’s an extreme example, but I’ve seen versions of the same decision throughout my career — save some money today without fully understanding the risk, then pay considerably more tomorrow.
I’ve also inherited complex IT environments with virtually no documentation. Before you can improve or properly support an environment like that, somebody has to reverse-engineer it just to figure out how everything works.
That’s expensive too.
After 30+ years in IT, I’ve learned that the best technical answer isn’t always the best business answer.
Experience helps you know the difference.
How It Works
What happens when we start working together?
1. First, I learn how your IT actually works.
I’ll talk with you, your team, and your IT providers. We’ll look at your major systems, vendors, contracts, security, spending, documentation, and the things that are already keeping you up at night.
2. Then we figure out where the holes are.
Not everything needs fixing immediately. We’ll identify the risks, problems, unnecessary spending, and missing pieces — then separate what’s urgent from what can wait.
3. We build a practical plan.
You’ll know what I recommend doing, why it matters, what it should roughly cost, and who should be responsible for getting it done.
4. Then I help make sure it actually happens.
This isn’t another IT assessment that gets emailed to you and spends the next three years sitting in a folder.
I stay involved, work with your vendors and leadership team, track the priorities, and help keep IT moving in the right direction.
Engagement Options
How much IT leadership do you need?
Not every 25-person business has the same IT needs, and neither does every 75-person business.
That’s why I offer three levels of involvement.
- 1 leadership call / month
- Vendor contract review (reactive)
- High-level security check-in
- Annual budget planning
- 48-hour response SLA
- Everything in Advisory, plus:
- 2 calls / month
- Proactive vendor negotiation
- Independent security audit
- Disaster recovery plan
- Quarterly written business review
- 24-hour response SLA
- Everything in Standard, plus:
- Weekly touch
- Full incident response runbook
- Cyber-insurance readiness package
- Compliance guidance (HIPAA / SOC2 / PCI-adjacent)
- Board- or investor-ready reporting
- Same-day response SLA
Compare to a full-time IT Director: $130K–180K/year fully loaded. Even the top tier here is a fraction of that cost.
Within Each Package
How pricing within a tier is set
Your employee count determines which package fits. Where you land within that package’s price range comes down to a few concrete factors – not guesswork.
| Factor | Lower end | Higher end |
|---|---|---|
| Environment complexity | Single cloud stack (M365 / Google Workspace) | Hybrid — on-prem servers + cloud + legacy systems |
| Vendor / contract count | 3–5 vendors under management | 8+ vendors under management |
| Locations | Single site | Multiple sites / distributed remote workforce |
| Regulatory exposure | None | Light (insurance requirements, client security questionnaires)* |
| Headcount within the band | Bottom of the tier's employee range | Top of the tier's employee range |
* Heavier regulatory exposure (HIPAA, SOC2, PCI-adjacent requirements) usually means the Strategic package, not just the top of a lower tier.
A note on messy starting environments: undocumented or poorly maintained environments often take extra work in the first 60–90 days. That's typically priced as a one-time onboarding fee on top of the retainer — not a permanent position at the top of the range.
Not ready to talk yet?
Start with the free Security Readiness Assessment.
It takes about three minutes and you’ll get a clearer picture of where you stand and what I’d look at first.
Get Started
Let's talk about what this looks like for your business.
We’ll spend 20 minutes talking about your business, how IT is being handled today, what’s working, what’s frustrating you, and where you think you might have gaps.
No pressure. No sales pitch. Just a conversation.
