Who owns each security responsibility?
Security does not fail because a company chose the wrong tool. It fails because seven jobs exist, four of them have no name against them, and everybody assumed somebody else was doing them. This finds those four and puts them in the order they will hurt.
Seven responsibilities have to sit with somebody in any company that holds customer data: policy, access, vendor risk, incident response, awareness, customer security questionnaires, and reporting upward. In most companies under two hundred people, two or three of them have a genuine owner, two or three are shared in a way that means nobody, and the rest have never been assigned at all. Nothing goes wrong until the day one of them is tested.
Answer for each of the seven. The gaps appear on this page ranked by what breaks first, and nothing is emailed anywhere unless you ask for it at the end.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
How this ranks the gaps
Each responsibility carries a base weight for how quickly an absent owner turns into a visible problem. Access is highest because it fails twice, once when somebody leaves with their accounts intact and once when an auditor asks for the last review. Incident response is next because the cost of working out who decides during an incident is paid at the worst possible moment. Board reporting and awareness sit lower, not because they matter less over a year but because nothing breaks on a Tuesday when they are missing.
What you said is coming next then moves the order. A certification with a date pushes policy and access up. A pile of customer reviews pushes questionnaires up. A recent incident pushes incident response to the top whatever else is true. Size adds weight to access, vendors and reporting, because all three scale with the number of people and suppliers.
Shared counts as most of a gap rather than none. A responsibility held by three people with no single name is the one that produces the sentence nobody wants to hear, which is that everybody thought somebody else had it.
Common questions
Is naming an owner really enough?
Naming is the first half. The second half is protected time and written authority, because an owner with neither is a name on a slide. The pattern that works in a company under a hundred people is a named person, a defined share of their week, and a short written statement of what they can decide on their own. Who owns security when there is no CISO sets out how to write it.
Can one person own all seven?
At under fifty people, often yes, and that is usually the right answer rather than spreading them thin. What matters is that the seven are written down as theirs, so the work is visible and can be handed over. Above a hundred people the seven start to want at least two owners, because questionnaires and access reviews are steady work that crowds out everything slower.
Does the owner have to be an employee?
Accountability has to sit inside the company. Delivery can sit outside. A fractional arrangement works when an internal executive still owns the decisions and the outside person does the work and advises, and it fails when everyone assumes accountability was outsourced with the tasks. The scope definer separates the two.
We have owners for all seven. What now?
Then the next useful question is not who but how well, which is what the maturity assessment measures across domains. Ownership without a cadence drifts back into a gap within about two quarters, so put a review date on each.
How does this connect to a risk register?
An unowned responsibility is a risk, and it belongs on the register with a name and a date like any other. If your register has no entries about ownership, it is describing threats rather than your actual exposure. See the risk register guide.