Outsourcing security responsibility: what stays with you

«We take over responsibility for your IT security.» That sentence appears in proposals that regularly land on the desks of Swiss management teams. It is well meant and it cannot be delivered. The question behind it is still a fair one: can you outsource security responsibility when nobody in the company has the time and nobody has the experience for it?

The answer splits into two parts, and only one of them is uncomfortable. The work can be outsourced, fully and with good results. The accountability cannot. Swiss company law says so explicitly, and the Data Protection Act repeats the same logic.

We sell external CISO mandates ourselves. Honestly, that is why this point belongs here. A mandate sold as a transfer of responsibility is bound to disappoint, and it disappoints both sides.

What the law calls non-transferable

Art. 716a para. 1 of the Swiss Code of Obligations lists what the board of directors cannot hand on. On this point the statute is unusually direct: «Der Verwaltungsrat hat folgende unübertragbare und unentziehbare Aufgaben», the board has the following non-transferable and inalienable duties. Three items on that list bear directly on information security. Item 1 names the overall management of the company and the issuing of the necessary directives. Item 2 the determination of the organisation. Item 5 the overall supervision of the persons entrusted with management, «namentlich im Hinblick auf die Befolgung der Gesetze, Statuten, Reglemente und Weisungen», in particular with regard to compliance with the law, the articles of association, regulations and directives.

In plain terms: who decides how your company is organised, who receives which directive and whether people follow it, is a question the law assigns to the top body and to nobody else. A security policy is a directive. An allocation of roles is organisation. Both therefore stay at the top, regardless of who drafts them.

For a GmbH the same principle applies. Art. 810 para. 2 uses the same formula of non-transferable and inalienable duties for the managing directors, covering overall management, the determination of the organisation and the supervision of the persons to whom parts of the management have been delegated. So this is not a topic only for stock corporations with a board of directors. Both provisions sit in the Swiss Code of Obligations, as of 1 January 2026.

The law expressly permits delegation, and that part usually gets lost in the discussion. Art. 716b para. 1 lets the board delegate management «ganz oder zum Teil einzelnen Mitgliedern oder Dritten», in whole or in part to individual members or to third parties, in accordance with organisational regulations. Third parties are named in the text. External mandates are therefore the normal case that Swiss company law anticipates.

What the same article demands in its third paragraph is the interesting part. The organisational regulations «ordnet die Geschäftsführung, bestimmt die hierfür erforderlichen Stellen, umschreibt deren Aufgaben und regelt insbesondere die Berichterstattung»: they govern management, define the positions required for it, describe their duties and regulate reporting in particular. The law permits delegation and in the same breath requires the reporting line to be settled. The version without a reporting line is the only one it does not provide for.

Three duties nobody performs for you

The clearest statement sits in the liability article. Art. 754 para. 2: whoever lawfully delegates the performance of a task to another corporate body is liable for the damage that body causes, unless they prove that they applied the care required by the circumstances «bei der Auswahl, Unterrichtung und Überwachung», in selecting, instructing and supervising.

A word of placement before anyone carries that sentence too far: the article speaks of delegation to another corporate body, not of a contract with a service provider. For the question of what survives a delegation it is still the most precise sentence in the statute book. It names three duties, and no contract discharges them.

Selection first. Have you checked whether this person or this provider can carry the role, and is that written down anywhere? What counts is your own check, not the provider's marketing promise: references, experience with companies of your size, independence from the products they will go on to recommend. The last point gets overlooked most often. A provider who sells licences and writes the security strategy at the same time holds an interest that is not your interest.

Then instruction. Does the mandate holder know what your company lives on? An external CISO who after six months still cannot say which three processes earn the money and which customer calls first during an outage has not been instructed. That is then not their omission but yours. Instruction also means mentioning the awkward things: the legacy system nobody may touch, the supplier with remote access, the decision that was deliberately not taken two years ago.

And supervision. Is there a rhythm for reporting, and does anyone read it? A quarterly report that lands in a folder is documentation without oversight. Art. 716a para. 2 states that the board of directors must ensure appropriate reporting to its members. That is an obligation to go and fetch the information, not to wait for it.

In data protection law the same pattern repeats, word for word. Art. 8 of the Data Protection Act obliges the controller and the processor jointly to ensure data security appropriate to the risk. Art. 9 para. 2 follows up: the controller must in particular satisfy themselves that the processor is able to guarantee data security. Satisfy themselves, not merely agree it in a contract. Para. 3 adds that the processor may pass processing on only with the controller's prior approval. The chain therefore remains your business too. The text is in the Data Protection Act, as of 1 September 2023. The liability side of it is covered in our post on nDSG liability for managing directors.

What the mandate does take over

An external mandate therefore delivers a great deal. What transfers is the largest part of the work and the most demanding part of the thinking.

The work: building a risk overview and keeping it current, putting measures into an order, vetting suppliers, answering customer audits and insurance questionnaires, preparing for the incident nobody expects, and translating all of it into language a management team without an IT background can read. In our experience that adds up to weeks per year, and they are weeks nobody in an SME has spare.

The judgement: deciding what comes first and what is deliberately left undone. This second half is the more valuable one. Any scanner can produce a long list of measures. Knowing which items on it will change something for your company and which ones you can leave alone with a clear conscience is the actual service. We described that at greater length under CISO responsibilities in an SME.

The external-facing role: a named contact with a title when a customer asks for the person responsible for security, when the insurer sends a questionnaire or when an audit is due. That function is often worth more in sales than in operations, which says nothing about the work but justifies the investment faster.

And the distance from day-to-day business. Someone who does not sit in the line can say that a measure costs too much for what it delivers. Internal security roles rarely say that, because the accusation of negligence arrives faster than the accusation of waste. We drew the line between an internal and an external role under CISO and information security officer, and the question that comes before it sits under Do you need a CISO.

What does not transfer fits on one line: the decision, the budget, the sign-off, the accountability. That distinction does not weaken a mandate. It is what makes the mandate workable in the first place. The same pattern applies to running a management system externally, as we described under ISMS as a Service.

Where the mandate runs idle

The most common cause of a disappointing CISO mandate is, in our experience, the missing counterpart inside the company. It rarely has anything to do with the provider or the contract.

Two symptoms give it away early. The first: the action plan is unchanged after four months, although nobody disputes it. Every item on it needs a decision that nobody takes. The external CISO proposes, the management team notes it, the plan moves to the next meeting. The second: the mandate reports to IT rather than to the management team. The role is then an additional technician with a better title, and the overall supervision under Art. 716a still receives nothing.

This is the most expensive form of security spending we know. Paying for a mandate whose recommendations nobody is allowed to approve costs money, produces paper and reduces no risk. If you have to choose between a large mandate without an internal counterpart and a smaller one with a named person who can decide, the smaller one is the better investment. It is the same thought as in running IT security without your own security team: the question is never only who does the work, but who signs it off.

That person does not need to be a security expert. They need to be allowed to decide and to be reachable. In smaller companies it is the managing director herself, with half an hour a month. At the start it takes no more than that.

What belongs in the contract and in the minutes

Five points that make the difference between a mandate and a line on an invoice.

  • The assignment written in tasks rather than hours: which decisions does the mandate prepare, which does it take itself (usually none), and which go to whom. A block of hours without that allocation is a budget, not an assignment.
  • A name inside the company, with a deputy. Who signs off, who decides in their absence. Without a deputy the gap lasts exactly as long as the next holiday.
  • A reporting line and rhythm, to the management team, with an entry in the minutes. A report that nobody can show the body has seen does not serve the purpose of Art. 716a para. 2. How that plays out in a liability case is set out under cyber liability for the board of directors.
  • Escalation with a clock on it: what happens outside office hours, who calls whom, and within what deadline. This point tends to get read during the first incident, and by then it is too late to write it.
  • The selection documented: why this person, which qualification, checked when and by whom. Two lines in the minutes. It is the cheapest of the five points and the only one you cannot create after the fact.

If you want to set this up without first reading a year of legal literature, that is exactly the work we do in our fractional CISO mandates: cutting the role to the size of the company and putting the decision path on record. An initial conversation is free of obligation.

The name missing from the contract

An external mandate takes work off your hands. It does not take a signature off your hands. That sounds like a limitation and in practice it is the better news: whoever keeps the responsibility also keeps control over the pace and over the question of what is deliberately left undone. The alternative would be a service provider deciding on your risk without carrying it. Nobody who has thought it through wants that.

If an action plan lands on the table tomorrow: who in your company is allowed to approve it?

Frequently asked questions

Can you outsource responsibility for IT security?

The work yes, the accountability no. Art. 716a para. 1 of the Swiss Code of Obligations calls overall management, the determination of the organisation and the supervision of management non-transferable and inalienable. For a GmbH the counterpart sits in Art. 810 para. 2. An external mandate takes over the execution; the responsibility stays with the leadership.

What does an external CISO actually take over?

They build the risk overview, put measures into an order, vet suppliers, answer customer audits and insurance questionnaires and report to the management team. On top of that comes the judgement about what comes first and what is deliberately left undone. What does not transfer is the decision, the budget and the sign-off.

What has to stay in house when we appoint an external CISO?

A named person with authority to decide and a deputy, a settled reporting line to the management team, and a documented selection of the mandate holder. Art. 754 para. 2 names selection, instruction and supervision as the duties of care in any delegation. Without an internal counterpart even a good mandate stays ineffective.