Who owns security when nobody owns it

NIS2 makes the management body approve and oversee security measures. ISO 27001 requires the roles to be assigned. Neither says hire a CISO. In a company of forty, security lands on whoever is nearest, and nothing that is everyone's job gets done.

Daniel Grigorovich
Daniel Grigorovich
Founder · 11 Sept 2026 · 7 min read
vCISOSMENIS2
Who owns security when nobody owns it

Who should read this: a company of twenty to two hundred and fifty people with no CISO, now receiving security questions from customers or a regulator, and unsure who inside the building is supposed to answer them.

Ask a forty person company who owns security and you get one of three answers. A name, said quickly, usually the head of IT. A pause, then “well, all of us really”. Or a name said slowly, because the person saying it has just realised that the name is their own.

The third answer is the honest one. The first two are how companies arrive at an audit with a policy set nobody has read and a risk register last touched in the month it was created.

The job exists whether or not the role does

Security work in a small company is not a project with an end date. It is a stream of small decisions that arrive weekly and have to be made by someone.

A supplier sends a security questionnaire and a deadline. An engineer asks for admin rights for a week, and the week ends. A laptop goes missing in an airport. A penetration test returns eleven findings and four of them will not be fixed this quarter, which means someone has to sign a piece of paper saying that is acceptable. A customer contract arrives with a clause requiring notification within twenty four hours of an incident, and nobody has defined what counts as an incident.

None of these need a full time specialist. All of them need one person who is accountable for the answer. In companies without that person, each decision is made by whoever it landed on, differently each time, and none of it is written down.

What the rules actually require

Both frameworks that reach a European SME say the same thing in different words, and neither says what people assume.

NIS2 puts approval and oversight on the management body. The measures have to be approved by management, management has to oversee their implementation, and management can be held responsible for failures. There is more detail in NIS2 board accountability and governance. The directive also requires management to follow training, and to offer similar training to staff, covered in NIS2 training requirements. What the directive does not do is create a role. It creates accountability and leaves the org chart alone.

ISO 27001 requires the roles to be assigned. Clause 5.3 makes top management responsible for assigning and communicating responsibilities and authorities for the information security management system. Annex A control 5.2 requires information security roles and responsibilities to be defined and allocated according to the organisation’s needs. The word CISO does not appear. What appears is the requirement that a specific human, named in a document, is responsible for specific things.

So both regimes demand an owner and neither demands a hire. That gap is where most SMEs sit, and the gap is not a loophole. An auditor will ask who owns the risk treatment decisions, and “the management team” is not an answer that survives the follow up question.

Where it lands by default, and what breaks

Absent a decision, the job lands on whoever is nearest. There are three usual landing spots and each fails in a predictable way.

The head of IT. The most common, and the one that looks most reasonable. It fails on independence. The person running the infrastructure is now also the person judging whether the infrastructure is adequately protected, deciding which of their own findings to accept, and reporting on their own backlog. The conflict is structural, not personal. It also fails on scope: security decisions about suppliers, contracts, training and physical access are not IT decisions, and an IT lead has no standing to make them.

The quality or compliance manager. Common in manufacturing and in companies that already hold ISO 9001. It produces excellent documentation and very little change. The person can write the policy, run the internal audit and manage the evidence, but cannot judge whether a network segmentation design is sound or whether a logging retention period is long enough to investigate anything. The management system looks healthy from the outside. The difference between certified and secure is exactly this failure.

The founder or CTO. The most capable of the three and the least available. Decisions are correct when they are made, and they are made late, in batches, usually the week before an audit or the week after an incident. The failure mode is not judgement. It is latency.

The test that settles it

Put five questions to the leadership team, separately, and compare the answers.

  • Who signs off that a known, unfixed vulnerability is acceptable to carry?
  • Who decides when a temporary access exception expires, and who checks that it did?
  • Who reads the security documentation a supplier sends before a contract is signed?
  • Who gets called at ten in the evening when something looks wrong, and what are they authorised to do?
  • Who writes the security section of the board pack, and who challenges it?

If the five answers name three or more different people, or if any answer is a department rather than a person, nobody owns security. The company has distributed the work and retained none of the accountability, which is the arrangement that reads worst in an audit and performs worst in an incident.

What ownership actually consists of

Stripped of the job title, the work in a company of this size is a short recurring list.

  • Maintaining the risk register, and forcing a decision on each item rather than letting it age. The shape that survives scrutiny is described in evidence that assembles itself.
  • Owning the exception log: who asked, what was granted, when it expires, who checked.
  • Reviewing suppliers before signature and at renewal, which is one of the ten measures NIS2 names.
  • Answering customer security questionnaires, and keeping the answers consistent between them.
  • Running the internal audit and the management review, the loop described in internal audit and management review.
  • Deciding what counts as an incident, and rehearsing the notification path before it is needed.
  • Reporting to the board in terms the board can act on.

In a company of forty to a hundred and fifty people, that is one to two days a month of decision making, sitting on top of tooling that produces the underlying facts continuously. It is not a full time job. It is also not nothing, and it is not something that survives being everyone’s tenth priority.

Hire, assign, or borrow

Three ways to close the gap, and the arithmetic differs sharply.

Hire. A security lead in Luxembourg is a six figure annual cost once employer charges are included, takes three to five months to find in a market where every bank is competing for the same people, and needs another three months to be useful. That is most of a year before the first decision improves. The hire is right eventually for most companies that keep growing. It is rarely right as the first move, because a company that has never had the function does not yet know what shape of person it needs.

Assign internally. Cheapest, and workable if two conditions hold: the person has explicit authority written down rather than implied, and the time is protected in the calendar rather than assumed. Where it goes wrong is never the person. It is that the role was added to a full job with no authority and no hours, and lost every collision with delivery work.

Borrow. A vCISO arrangement buys the decision making without the recruitment cycle, at a few days a month rather than a salary, starting in days rather than quarters. It also buys independence: someone whose judgement on the infrastructure is not a judgement on their own work. The honest limitation is that a part time owner cannot be the person who notices something at ten in the evening, so the detection half has to come from tooling rather than attention.

The thing to avoid is the fourth option, which is to defer the decision and let the job continue landing on whoever is nearest. That is the arrangement every company already has before it chooses one of the three.

The technical reality

Both frameworks stop at accountability. NIS2 requires management to approve and oversee the measures. ISO 27001 requires the roles to be assigned and documented. An auditor can verify both by reading a page.

What neither requires is that the named owner can see anything. A security owner with a signed responsibility statement, no asset inventory, no log retention longer than the default and no alerting owns a document set, not a security posture. They can tell you what the policy says. They cannot tell you whether it held last Tuesday.

Closing that gap is unglamorous and specific. The owner needs an inventory that updates itself rather than one rebuilt by hand each audit cycle, logs kept long enough to reconstruct an incident rather than long enough to satisfy a default, findings that arrive ranked against the business rather than as an undifferentiated list, and an evidence trail that regenerates rather than being assembled the month before the auditor arrives. With those, one owner working two days a month can hold the position. Without them, a full time CISO would spend most of the week collecting facts that a system should have been collecting on its own.

Ownership is the requirement. Visibility is what makes the requirement mean something. If you want to know which of the two you are missing, an independent security audit answers it in weeks, and the broader picture of what NIS2 expects is in the NIS2 compliance guide.

Daniel Grigorovich

Daniel Grigorovich · Founder

I believe that no business should suffer from "compliance checklists" or navigating vague regulatory text. While I still stand by the principle that all software products should be reliable and secure, I want to give companies a way to overcome the challenges faced when implementing these requirements.