Responsibilities
A CISO defines the security strategy and budget, owns the policies and the risk assessment, oversees compliance with frameworks such as ISO 27001 or the ENS, leads the response to serious incidents and reports to management on risk in business terms. In larger companies the CISO leads a team; in smaller ones, the role is often combined with IT or covered externally.
Reporting line
Reporting to the CEO or the board, rather than to the head of IT, helps avoid conflicts between delivery speed and security. In the ENS, the security officer (responsable de seguridad) must be a different person from the system officer (responsable del sistema), for the same reason.
Why the role is gaining weight
NIS2 makes management bodies approve cybersecurity measures, oversee them and receive training, and they can be held liable for failures. DORA puts ultimate responsibility for ICT risk on the management body of financial entities. Both increase the need for someone who can advise management with authority.
When there is no CISO
Many small and mid sized companies cannot justify a full time CISO. A vCISO covers the same responsibilities part time or as a service, so that someone is still in charge of security and answers to management.




