Back to glossary

CISO (chief information security officer)

4 min read

In security governance, the CISO is the person an organisation holds accountable for its information security: they decide which risks are accepted, in what order the rest are treated, and they answer for it to whoever governs the company. It is a decision-making role rather than a technical one, and most of the confusion follows from that.

July 30, 2026
Compartir:

What the role decides and what it does not

The boundary of the role is risk, not technology. A CISO approves the policies, keeps the risk register, decides what gets fixed first and what is accepted with a signature behind it, asks for the budget, and answers when something goes wrong. Where it is set up well the work looks more like prioritising on incomplete information than like configuring anything, and it is what holds up an information security management system where one exists.

What it is not: the CISO does not operate the SOC, does not run the penetration tests, and does not administer the firewall. In a small organisation the same person may well do all of that, and that is a staffing reality rather than the definition of the role. When the two are conflated you get the familiar failure: someone hired to decide is absorbed into the operation, and the decisions carry on being taken by default.

There is one incompatibility worth knowing before the hats are handed out. The data protection officer has to be independent of whoever determines how personal data is processed, so in most structures they cannot be the CISO. Appointing the security lead as data protection officer because they are the nearest available expert is a common and defective arrangement.

External CISO, virtual CISO or CISO as a service

The three names describe the same arrangement: an outside professional performing part of the role on a fraction of a full-time schedule, usually for organisations that need the function but cannot justify or fill a full-time hire. It is a real arrangement and, in many cases, a sensible one.

What it covers well is the work that does not exist yet: writing the policy that is missing, assembling the risk register for the first time, preparing an ISO 27001 certification or an ENS alignment, and being the technical interlocutor when a customer or an insurer sends a questionnaire.

What it does not cover, and this is what decides whether the arrangement works, is authority and accountability. The work can be contracted; who answers cannot. NIS2 makes the management body responsible for approving and overseeing the risk management measures, and that responsibility is not subcontracted along with the service. An external CISO with no access to the people who decide budget and priorities produces documents, not security.

The second failure is sizing. A few hours a month is enough to keep a management system alive and not enough to build one, and confusing the two is the usual way a certification arrives late.

When one is needed

The signals are about decisions rather than size. Security decisions are being taken by default because nobody owns them. An obligation requires a named responsible person. A customer, an auditor or an insurer asks who answers for this and there is no short answer. Or there is more security work than the head of IT can prioritise on top of their own.

What is not a signal is buying a tool. If the underlying problem is that nobody answers for this, the answer is a name rather than a product.

Asperis does not offer this service

This entry exists because the search exists, not because we sell the role: Asperis does not offer an external CISO or CISO as a service, and this page is not an indirect way of offering it. If you arrived looking for that service, it is not here.

What we do is the technical half a CISO, internal or external, has to pull on in order to decide: turning an assumed risk into a measured one and writing the result so that it can be prioritised, with the scope, the impact and the order on the table. Alongside whatever vulnerability management the organisation already runs, it is the technical evidence a management system uses to show its controls work.

Want to see how we work at Asperis Security?

Schedule a 30-minute call with one of our experts. We’ll review your stack, agree on scope, and tell you what’s worth pentesting first.