Who owns security when there is no CISO
Somebody already owns it, informally and badly. Naming the person, writing down what they decide and giving them a day a week is the single cheapest security improvement available to a company of this size.
In a Canadian company of 15 to 80 people the right owner is the technical founder or the most senior engineer, given explicit authority, a small budget and about one day a week. Buy outside expertise for the decisions they have not made before. It is not the office manager, not the head of IT support, and not nobody, which is the current arrangement at most companies that ask this question.
The first person to ask who owns security will not be an auditor. It will be a customer, on a form, and the answer has to be a name.
What does owning security actually mean here?
Four separable things get bundled into the phrase, and they can sit with different people. Splitting them is what makes the job possible for someone who also has a full-time role.
- Accountability
- Whose name is on the decision to accept a risk, and who a customer or an insurer is told to contact. This cannot be delegated outside the company and cannot sit with a vendor. One person, named, with a title.
- Decisions
- Which framework you target, whether data stays in Canada, whether a contract clause is acceptable, what gets fixed this quarter. This is the part that needs experience rather than time, and it is the part most worth buying help for.
- Delivery
- Turning on the controls, writing the policies, running the access review, collecting the evidence. Ordinary competent work that does not need a security executive and often should not have one doing it at $300 CAD an hour.
- Administration
- Chasing people, tracking dates, keeping the vendor list current, filing the evidence. Operations work. Give it to whoever is good at operations, and do not let it consume the accountable person's day.
A company that splits these four across three people with one name on the first is in better shape than a company that buys a retainer and leaves the accountability vague.
Which person in the company should it be?
| Candidate | Works when | Fails when |
|---|---|---|
| Technical founder or CTO | Under 40 people, where a founder still has context on every system | They are also the person building it, so nobody independent reviews the decision |
| Senior or staff engineer, one day a week | The time is protected, the authority is stated, and they want it | The day gets eaten by delivery, which happens by default unless someone defends it |
| VP engineering | There is an engineering organisation to hold to commitments | Same independence problem as the CTO, at a larger scale |
| Head of operations or finance | In a small team the load is mostly questionnaires, vendors, insurance and evidence | A technical decision arrives and they have no basis to make it |
| CEO, non-technical | Never as the working owner. Sometimes as the accountable name | Immediately, on the first customer call that goes past two questions |
| Managed IT provider | For patching, endpoints, backups and identity administration | The moment a risk has to be accepted, because a supplier cannot accept your risk |
| Fractional or virtual CISO | The decisions outrun internal experience, or a buyer wants a named security leader | There is nobody internal to do delivery, in which case you buy a roadmap and no change |
The last two rows are the ones people get backwards. A managed provider and a fractional lead are not alternatives. They cover different columns above, and plenty of 40 person companies have both plus an internal owner.
Comparing firms for this? Tell us what you need and it goes to the ones in the directory that do this work. No charge, and no phone number required.
How do you actually assign it?
- Pick the person in a meeting, not in a document. Ask them. Someone who takes this reluctantly will do it reluctantly. The job only works when the person wants the authority.
- Write one page. What they decide alone, what needs the CEO, what budget they can spend without asking, and how much time is theirs. The vCISO job description is a longer version of the same document, worth stripping down for an internal owner.
- Protect the time explicitly. A day a week that is not on a calendar and not defended by their manager is not a day a week. This is the step that fails most often.
- Give them a decision log. One shared file with the date, the decision, the reason and who agreed. This becomes the most useful artifact you own, and it is the thing auditors, insurers and acquirers all ask for in different words.
- Announce it internally. Authority nobody has heard about does not exist. Say who owns it and what people should bring to them.
- Book the outside help against specific decisions. Not a retainer to feel safe. A few hours against a framework choice, a contract clause or a first policy set. Hourly advisory in Canada runs $200 to $400 CAD and a handful of hours goes a long way at this stage.
The independence problem, honestly
When the person who builds the system is the same person who says it is secure, you have no second opinion. That is the normal condition of every company under about 50 people. Manage it, do not hide it.
Three cheap ways to manage it. Have someone other than the builder run the access review. Get one external test a year, usually a penetration test, for a finding list you did not write yourself. And when the accountable owner is also the CTO, have risk acceptances signed by the CEO, which costs nothing and is the distinction an auditor looks for. What a Canadian test costs is on penetration testing cost in Canada.
Where the reporting line should sit once you do have a security leader is on who a CISO should report to. Most of it does not apply under 100 people.
On job titles
You do not need to give anyone the title CISO. Giving it to a senior engineer at a 30 person company creates customer expectations the person cannot meet. "Security lead" or "accountable for security" in a policy document is enough for every questionnaire and every insurance application. The difference between the titles is decision rights, set out on CISO versus vCISO versus security manager.
Buy expertise, keep the accountability
Tell us who you are thinking of putting in the seat and what decisions are waiting on them. We will tell you how many hours of outside help that needs, which is usually fewer than you expect.
Get matchedCommon questions
Can the CEO just be the security owner on paper?
For the accountability column, yes, and for a company under about 25 people that is a perfectly honest arrangement. It breaks on the first customer security call, because a non-technical CEO cannot answer follow-up questions and the reviewer will notice. The workable version is the CEO as the named accountable executive with a technical person doing the work and joining the calls.
Does a customer questionnaire require the person to be called a CISO?
No. Questionnaires ask whether there is a named individual responsible for information security, and any real title satisfies that. PIPEDA has a related requirement to designate an individual accountable for personal information, which is a privacy role rather than a security one, and the two are often the same person at this size. What matters is that the name is real and reachable.
Should the security owner report to the CTO?
Ideally not, because the CTO owns delivery and the tension between shipping and securing needs somewhere to be resolved other than inside one person's head. Under 50 people this is often unavoidable. The workable compromise is that day to day work runs through the CTO while risk acceptances go to the CEO, so the person who benefits from shipping is not the only signature on the decision to ship.
What if the person we assign has never done this before?
That describes almost every founder and every first security owner, and it is fine for the delivery and administration columns, which are ordinary competent work. It is not fine for the decisions column, where inexperience is expensive: picking the wrong framework costs a year, and accepting the wrong contract clause costs more. Buy a small number of advisory hours against those specific decisions rather than a retainer, at least until the job becomes recurring.
How much of a real job is this at 40 people?
Between four and twelve hours a week, spiking to far more during a customer security review or an audit. The variance is the difficulty: it is not a steady part-time job, it is quiet for six weeks and then consumes a fortnight. What no security person costs a 30 person company breaks the hours down by driver so you can size it against your own customer count.