Do you need a CISO? The honest test for your SME

Do you need a CISO? If you are asking yourself this question, the honest answer for most Swiss SMEs is: no. At least not in the way the question is usually meant. What people mean is a position: a person in the org chart, with a salary that quickly reaches six figures in Switzerland.

What you need sounds far less glamorous: someone has to make security decisions for your company, set priorities and report to management. This function is missing in many SMEs. And it is something different from the position.

Where the question suddenly comes from

In our experience, hardly any managing director asks this question on their own initiative. It comes from outside. An enterprise customer sends a security questionnaire and wants to know who is responsible for information security at your company. The cyber insurer asks the same thing when the policy comes up for renewal. The board of directors has read something about personal liability. Or a business nearby got hit, and the question is suddenly on the table at your company too.

Look closely at these triggers. None of them asks for a title. The customer wants to know whether someone is responsible. The insurer wants to know whether someone knows the risks and has them under control. The board of directors wants to be able to prove that someone is paying attention. The answer "we hired a CISO" would satisfy all three, that is true. It is only the most expensive way to answer a question that really reads: who carries the responsibility for security at your company?

As long as you narrow the question down to the title, you have exactly two options: create an expensive position or do nothing. Both are wrong for most SMEs.

The title is the wrong unit

A full-time CISO makes sense where there is enough work for one: in heavily regulated industries and in corporate group structures. In an SME with 50 to 500 employees, security work rarely fills a full workload. What happens then? Either the position is never created, or it is created and the person fills their time. They write policies nobody reads and procure tools that strain the budget without measurably reducing risk. We have seen both variants. The second one is more expensive.

The function behind it is still indispensable, and it consists of a few things that can be named clearly. Someone knows the company's most important risks and has assessed them. Someone decides what gets tackled first and what can deliberately wait. Someone says no to spending that only promises protection. And someone reports to management in a language that is understood there.

The obvious objection: "Our IT does that." Usually it does not, and that is not a reproach. IT operates systems, and operations is a different job from oversight. Whoever configures the firewall cannot at the same time independently judge whether the firewall strategy is right. Add to that the conflict of interest: with every security question, IT is also judging its own work. We described why this does not work structurally in our post on why IT operations does not replace a security strategy, and the distinction between the roles in detail in the difference between a CISO and an information security officer.

A third variant deserves its own paragraph because it is so widespread: the CISO on paper. The customer questionnaire demands someone responsible for information security, so someone gets appointed. Usually the head of IT, sometimes the CFO, occasionally whoever happened to be in the room during the meeting. The person gets the addition to their job description, but no time, no budget and no mandate to tell management uncomfortable things. The questionnaire is answered. The function remains unfilled. This is the variant that feels best and delivers least: it seems to cost nothing and creates exactly the kind of false security that collapses fastest in an incident.

The test with three questions

You can find out whether the function is filled at your company without a consultant and without an assessment. Three questions are enough.

First: who decides on trade-offs between security and business at your company? Concretely: IT wants two-factor authentication for everyone, sales pushes back because it gets in the way during customer meetings. Or the quote for a better backup concept has been sitting on the table for three budget rounds, and nobody can say whether it is more important than the new webshop. Who decides that? If the answer is "IT", the wrong level is deciding. Trade-offs like these affect the business and belong where business decisions are made. If the answer is "nobody, it fizzles out every time", nobody is deciding at all. That is the most common variant.

Second: who reports to management on the security situation on a regular basis? Regular means: even when nothing is on fire. One report per quarter, understandable, with the relevant risks and the status of the measures. If management only hears about security after incidents, it does not know its risk situation. It then also cannot decide with due care, and it is exactly this care it has to prove when things get serious.

Third: who stands up after an incident? The insurer asks questions, affected customers want answers, depending on the case so do authorities. Someone has to be able to explain which risks were known and what was done about them. "We would have to look into that" is not an answer you want to give in that situation.

If you can answer all three questions with a name, your function is filled. The title of that person is secondary. If you hesitate on one or more questions, you have found the gap the CISO question is about.

How to fill the function

There are two honest ways to fill it, and which one fits depends on your company.

The internal route works if three conditions are met. The person needs dedicated time for the task, not "on top of the day job, workload permitting". They need direct access to management, without their report being watered down through three levels of hierarchy first. And they must not be the same person who is responsible for IT operations, otherwise they are judging their own work again. In an SME, these three conditions are hard to meet at the same time. It is possible, but it is rare.

The external route is the mandate: an experienced person who takes on the function in a defined scope and reports directly to management. The advantage lies less in the expertise than in the structure. An external person has no systems of their own to defend and no interest in a growing security budget. The disadvantage is just as real: they do not know your company at the start and have to earn that understanding. A mandate that delivers finished answers in the first week delivers answers off the rack. In return, the scope can be adjusted: more at the beginning, less in steady state, more again when an audit or a certification is coming up.

What should happen in the first months is the same in both variants: an inventory of what is there, a risk assessment oriented to the business rather than to a standard, and a reporting rhythm to management that runs even without an incident. Whoever starts with a tool list has not understood the order.

What the function may cost

That leaves the question of price. A full-time position is the most expensive solution, and we have broken down what it costs in Switzerland separately: How much does a CISO cost in Switzerland? For the function as described above, in our experience an SME needs a few days per month rather than a full-time employee. This is exactly what the model of the external CISO on a time basis is for, whether you call it fractional CISO, CISO as a service or a mandate.

How do you recognise whether the person is doing their job? By a simple pattern: over time, a good CISO lowers an SME's security costs. That sounds contradictory, but it is the logical consequence of the function. Whoever assesses and prioritises risks discovers first the spending that achieves nothing: duplicate tools and measures that only protect on paper. Cleaning up comes before buying more. If your external CISO mainly recommends new purchases in the first year, you have not hired a CISO but a salesperson with a better title.

That is also the standard you may hold us to.

Three questions, one name

Forget the title for a moment. Translated, the question "Do I need a CISO?" reads: is someone at our company responsible for security who decides, prioritises and reports? If yes, you are further along than most. If no, you fill the function deliberately, at a scale that fits your company. That rarely requires six-figure personnel costs, and "IT will handle it on the side" has already failed the test above once.

Which of the three questions could you not answer with a name?

If you want to talk about what this function could look like at your company: an initial conversation costs nothing and commits you to nothing. We will also tell you if you do not need a CISO. That, too, is part of the function.