CISO responsibilities in an SME: decisions instead of firewalls

In the first week of a new CISO mandate, the same thing happens almost every time: Someone proudly shows us the security dashboard, preferably on the big screen in the IT office. Antivirus green, backup green, the firewall too. The message behind it is clear, everything here is under control.

Then we ask three questions. What are your five biggest risks, in writing? Who decided that the maintenance partner's remote access may stay the way it is? And when did management last see a security report they also understood?

In our experience, silence usually follows. Not the embarrassed silence of people doing bad work, the technology is often set up properly. It is simply that nobody owns the tasks these questions are about.

This gap describes the responsibilities of a CISO in an SME more accurately than any job ad. What gives the role its value are decision tasks. Many companies hire a technician for it and only realise later that they needed someone who organises responsibility.

What the job ad says

Read a typical CISO job ad and you get a shopping list: SIEM experience, penetration testing, firewall management, cloud security, plus ideally three certifications. It sounds like a superhero with admin rights.

In our experience, a list like that describes the daily work of a security engineer. A good profession, only a different one. In the worst case, the mix-up costs an annual salary for a function that never touches the actual problem. We took the two roles apart in our post on the CISO and the information security officer.

The daily work of a CISO happens elsewhere: in meetings, documents and conversations with people who have no appetite for security on that particular day. The production manager wants to keep his line running. The CFO wants to know what she is supposed to pay for this time. The apprentice in sales clicked on a link and barely dares to report it. These are the people a CISO works with, and far more than with log files. It sounds unspectacular, and it is. This is the part that protects.

CISO responsibilities in practice: a typical week

Take a typical mandate week in a manufacturing SME. Not a single hour of it goes into a tool.

On Monday, IT delivers twelve open findings from the latest vulnerability scan. Budget and time are enough for four. Now someone has to decide which four come first, and be able to justify why the remaining eight can wait. Prioritising here also means consciously leaving things undone and putting that in writing. If someone later wants to know why finding number seven stayed open, there is an answer with a date and a reason.

On Tuesday, a management decision is due. The machine supplier wants to keep its remote access, IT pushes back, the production manager needs the support. The CISO writes the decision memo: the risk in business language, the cost of the secure option, a recommendation. Management has to decide itself. The value of the role lies in getting the question onto the table in a decidable form, instead of letting it smoulder as a standing conflict between two departments.

On Wednesday, it is about responsibilities. Who blocks accounts when someone leaves, and within what deadline? Until now the answer was "IT, at some point". Now it is written into a process with names and deadlines. Nothing about this is technically demanding. Nobody had written it down before. We find gaps like this in almost every mandate, regardless of industry and size.

On Thursday, contracts are on the table. The new payroll provider wants to move personal data into its cloud. The CISO does not read source code for this. He checks whether it is regulated where the data resides, who informs whom within what time in case of an incident, and how to get out of the contract again. A surprisingly large part of an SME's security posture lives in contracts.

On Friday, one page goes to management: where we stand, what has changed since last month, which decision is up next. No tool vocabulary, no 40 slides. This one page has a second life. It later proves that leadership was informed and acted. In liability questions at board of directors level, such documentation carries real weight.

In between sits the task that never appears in any weekly plan and still achieves the most: preparing for the emergency. Who do we call first? Who is allowed to decide that systems go offline, even on a Saturday evening when the managing director is on holiday? Who talks to customers while the cleanup runs inside? And where is the list of emergency numbers when the intranet has just been encrypted? Two hours a year in which an incident is played through at the table achieve more here than the next product on the shelf. It is not glamorous work. In an emergency, it is the difference between a managed Wednesday and a chaotic week.

What does not belong on the list

At least as revealing is the part that is missing. Configuring firewalls, patching endpoints, working through tickets, running servers: all of that is operations. Operations matter, someone has to do them, and in many SMEs the IT team does them properly. But if security responsibility is fully absorbed into IT's day-to-day business, nobody checks in the end whether the whole thing is still heading in the right direction.

There is a simple test for whether this separation exists in your company: When did someone last say no to a security purchase? A functioning CISO says no on a regular basis. No to the tool, because the risk behind it is small. Occasionally also no to a policy that serves nobody except the auditor. In our experience, enough money flows into security at many SMEs, part of it just goes to places that protect little. A filled CISO role therefore lowers spending more often than it raises it.

If you are currently weighing up whether your company needs the role at all: You will find the honest self-test in our post Do you need a CISO?

How you notice the role is vacant

From the outside, it is hard to tell whether the decision tasks sit with someone or whether only the technology is being looked after. The org chart usually says "information security" somewhere. We see five patterns again and again when the tasks are distributed on paper and still nobody carries them.

The security budget follows the vendors' calendar. Purchases and renewals happen when the renewal email arrives. A risk consideration behind them is rare.

The risk list exists as a feeling. Ask three people about the company's biggest risks and you get three different answers, all from the gut.

The board of directors asks about the security posture and receives a product list as the answer. Tool names replace the statement of how the company is actually doing.

In an incident, whoever happens to be reachable decides. Without prepared responsibilities, the loudest voice in the room takes over in an emergency.

And the question about accepted residual risk draws blank looks. Every company carries residual risks, that is normal and also sensible. The difference lies in whether someone knows them, has named them and can stand behind them, or whether they are simply there until one of them materialises.

Each of these patterns looks harmless on its own. Together they show a company in which security exists, but nobody leads it.

How much of this does an SME need?

All the tasks above scale with the size of the company, but they never disappear entirely. Even a business with 80 people needs someone who prioritises risks, prepares decisions and reports to leadership. It hardly needs a full-time position for that.

In most of our mandates, one to four days per month are enough once the foundations are in place. The effort concentrates at the beginning. The first 90 days or so go into taking stock: which risks exist, who carries responsibility for what today, which contracts and access rights exist at all. Out of that come the first prioritised risk list and a fixed reporting rhythm to management; the responsibilities get names. After that, maintenance and decision work remain, and the workload drops noticeably. We broke down what this means in francs in our post How much does a CISO cost in Switzerland?

More important than the workload is how the role is cut. A role that follows the shopping list from the job ad mainly produces activity. Cutting it along the decision tasks leads somewhere else: to clarity about what protects the company and what it can save itself.

If you want to know what the role would look like in your company, with what workload and what scope, then talk to us. A first conversation is non-binding, and often that alone is enough to see the gap clearly.

Who decides at your company?

Back to the green dashboard from the first week. The technology behind it was fine, by the way, there was nothing left to install that would have improved the situation. What was missing was a person who turns many green lights into a justified direction. That is, boiled down to one sentence, the answer to the question about CISO responsibilities in an SME.

And with that, the question we are honestly interested in: Who at your company answers, today, which risk you consciously carry?