It is good practice for organisations to nominate someone at board level to be responsible for managing the company’s cyber security risks. In small and medium sized businesses, this responsibility can be found in a number of portfolios, including finance, legal, compliance, and IT.
A Chief Information Security Officer is not the same as Head of IT. It is a specialist role that impacts all areas of the business. The CISO should be independent of IT, providing assurance to the board that IT is doing what is necessary to identify and manage technology risk. Giving the role to the individual in charge of IT usually creates a conflict of interest.
In most cases, individuals with CISO responsibilities who are not in the IT function will not have the right experience or background to perform the role effectively. They will rely on the IT function and therefore be conflicted. This may prevent the CISO effectively discharging their function as the independent voice of risk management at board level.
A CISO is a key element of modern Enterprise Risk Management (ERM). Through our VCISO service, Astaara can support your CISO at a fraction of the cost of employing an additional FTE. We can help them prepare for board meetings pertinent to cyber, help them identify compliance gaps, and generate the evidence that you are complying with the new regulations. Our VCISO service also gives you access to multiple points of expertise, depending on your needs.