
The difference between a CISO and an information security officer is not in the title, but in who decides and who monitors. That sounds like a formality, but in practice it determines whether information security happens in your company or only exists on paper.
The question rarely comes up out of curiosity in SMEs. It comes from outside: a major customer sends a security questionnaire with the field "person responsible for information security". An auditor asks for the organization chart. The cyber insurer wants a name. And suddenly you need a title that did not exist yesterday. In our experience, management fills this gap within a week, usually with the IT manager and a second hat. Understandable, pragmatic, and in many cases the beginning of a problem that only becomes visible years later.
So let us look at the two roles calmly, the way they work in the day-to-day of a company with 50 to 500 employees.
CISO and information security officer: two different jobs
The CISO (Chief Information Security Officer) is a leadership role. He defines which risks the company accepts and which it does not, prioritizes the security budget, decides on measures and reports to management or the board of directors. He works on the risk map of the business and only rarely on the firewall. A good CISO spends more time on the question "Which of this do we not need?" than on the question "What do we buy next?".
The information security officer (often called ISO or security officer) is an operational and supervisory role. He makes sure that agreed measures are implemented, checks compliance with policies, maintains guidelines, supports audits and reports deviations. He is closer to the systems and to daily operations, and that is exactly his value.
The CISO answers the question "What is security worth to us, and where do we apply it?". The information security officer answers the question "Is what we decided actually being done?". One is steering, the other is operation and control. Both are necessary, but they are two different jobs, and they require different skills. One must be able to talk to the board of directors about business risks, the other must want to read an access permission concept.
In a large corporation, the two roles are cleanly separated: the CISO leads a team, and the information security officer is part of it or deliberately sits outside IT. In an SME, the functions inevitably blur because there are fewer people. But the clarity that the organization chart provides in a corporation must come from a deliberate agreement in your company. That is why it is worth understanding the two jobs separately first and then deciding how many people carry them.
By the way, no standard requires you to name these roles exactly like this. ISO 27001 requires that responsibilities for information security are assigned and communicated. It says nothing about a CISO. The Swiss Data Protection Act also requires adequate data security, but no specific title in the organization chart. The titles are convention; the responsibilities are the core.
Why the title alone protects nothing
Here comes the part that tends to get lost in job postings and questionnaires: a role only works if three things stand behind it. A mandate, time, and a direct line to management.
The mandate first. Whoever carries security responsibility must be able to decide something, or at least escalate with authority. In our experience, this is the most common gap: there is an officer, but his recommendations trickle away in the line organization because nobody has defined what happens when IT management, the CFO and the officer disagree. An officer without an escalation path is a mailbox.
We saw what this looks like in an assessment at a manufacturing company. On paper, there had been an information security officer for years, appointed back then because of a customer questionnaire. When we asked when he had last reported to management, there was silence. There was no reporting rhythm, no reserved hours, no budget, and the open items from the last audit sat untouched in a folder that nobody besides him knew about. The company was not unprotected because of this. But everything that worked, worked despite the role, not because of it. The questionnaire from back then was filled in correctly; the appointment had never achieved more than that.
Then the time. A second hat is cheap to hand out and expensive to wear. When the IT manager takes on the role "on the side", the urgent usually beats the important in daily operations: the ticket beats the risk analysis, the server outage beats the awareness program. No bad intent is needed for that. Operations are loud, security is quiet, and quiet tasks lose again every week. If you take the role seriously, you reserve fixed hours for it and protect them.
And finally, the line to the top. Security is a trade-off between risk and money, and this trade-off belongs where risk and money are decided everywhere else. Whoever carries security responsibility but sits three hierarchy levels below management and never reports to it directly cannot fulfill his most important task: carrying uncomfortable truths to where they have consequences. We described why this also matters for liability in our post on cyber liability in the board of directors: the board must be able to show that it was informed and acted. For that, it needs someone who informs it.
If these three things are missing, you do not have a security lead. You have a name for the questionnaire.
The second hat and its blind spot
One point deserves its own section because it is so widespread: the IT manager as security officer in personal union.
At first glance, it makes sense. Nobody knows the systems better, the person is already there, and a new hire costs money. At second glance, a built-in conflict of interest emerges: the same person who runs IT is supposed to judge whether this IT is run securely enough. He checks his own work, prioritizes findings against his own budget and reports deficiencies to management for which he himself is responsible. That is a question of construction, not of character. Even the most conscientious IT manager has blind spots regarding decisions he made himself.
That is why larger organizations separate the roles, and why auditors look more closely at this setup. For an SME, this does not mean the second hat is forbidden. It means you should know the conflict and balance it somewhere: through an external second opinion at fixed intervals, through an independent assessment, or through outsourced security leadership that sits next to internal IT instead of inside it.
For the same reason, the combination of "internal officer plus external security leadership" works so well in our engagements. The internal person knows the business, the external one brings the mandate, the experience and the neutral view. Neither of the two has to grade himself.
Which setup your SME needs
Which brings us to the question behind the role comparison: what do you need?
If your company is small, has no special customer requirements and provides no regulated services, you first need clarity instead of titles. One person with defined responsibility, fixed hours and the right to escalate to management covers the start. What that person is called in the organization chart is secondary.
As soon as customers send questionnaires, an ISMS is on the table or the board of directors expects regular reports, the purely operational role is no longer enough. Then you need the leadership side: someone who prioritizes risks, owns the budget and answers to management. That is the CISO function, and it does not have to be a full-time position. For most SMEs, a permanent CISO would even be the most expensive answer to the wrong question, as we calculated in our overview of CISO costs in Switzerland. A right-sized, part-time setup, a few days per month with a full mandate, covers the leadership side while someone internal carries the day-to-day. We took apart the different models for this, from fractional CISO to CISO as a service, here.
What we advise against: filling the role to fill a field in a questionnaire, and then changing nothing. That calms things down for a moment and backfires at the first incident or the first audit, when it becomes visible that there is no structure behind the name. An empty title is more expensive than none at all, because it gives everyone involved the feeling that the topic is taken care of.
The staffing question, asked correctly
So before you draft a job posting or write a name into a form, ask the question differently. Instead of "CISO or information security officer?", it reads: who in our company decides on security risks, who monitors implementation, and are these two different people with a mandate, time and access to management?
If you can answer this question cleanly, the title question resolves itself. If not, that is exactly the point where a conversation is worthwhile. We look at such setups regularly, from the first role clarification to outsourced security leadership, and we will also tell you if your second hat is enough for now. Book a no-obligation initial consultation if you want to clean up the responsibility question once and for all.
One thing interests us most: if an incident happens tomorrow, would everyone in your company know immediately who decides?




