The security officer role: what a CISO does, and how to cover it without one

Published on September 21, 20267 min read
A small-business manager takes on the security-lead role among her many responsibilities, a security badge beside her

One Thursday morning, Sophie B. opens her inbox and finds two near-identical emails: the first asks her to approve a new bank account number for a regular supplier, the second invites her to install an "urgent security update". As the managing partner of an accounting firm, she knows how to read a balance sheet and defend a tax file — not to decide, alone and in three minutes, whether these messages are genuine. And in her firm, no one holds the title of security officer.

The security officer role: a function to cover, not necessarily a job to create

In large groups, this question has a designated owner: the CISO (Chief Information Security Officer, the person in charge of information systems security). They set the protection strategy, arbitrate priorities and answer for it when something goes wrong. But "security officer" describes a function first — a set of decisions that must be made — before it describes a job. An SME of a few dozen people can almost never afford a full-time CISO. Yet, exactly like a large group, it needs that function to be covered.

The most common misunderstanding is to treat security as a purely technical topic, something you "leave to the IT person". A security officer's work actually rests on three legs, and only one is technical.

The technical leg, first. It means understanding common threats — phishing (an email or text message that imitates a trusted party to make you click or pay), ransomware (software that encrypts your files and demands a ransom), weak or reused passwords — and knowing which basic safeguards to put in place. It is the visible part, the one people picture first. It is not the most decisive.

The educational leg, next. The vast majority of incidents start with a human action: one click too many, a shared password, a bank detail changed without a check. No firewall catches that. Here the role is to install simple reflexes across the team, to explain the why without scaremongering, to make the right behaviour feel natural rather than imposed. At Sophie B.'s firm, a single call-back rule before any change of bank details would have defused the first email.

The judgment leg, finally. An SME cannot do everything at once. Someone has to decide what to protect first, how much to spend, and what can wait — translating a technical risk into business terms: "if this client file leaks, here is what it costs us in client trust, and here is what the law requires of us". In a firm that holds the accounting and tax data of hundreds of clients, that judgment is not a luxury: it is professional confidentiality by another name.

What happens when no one holds this function is very concrete, and Sophie B. would recognise it at once: a password to the accounting software shared by the whole team, that nobody dares change any more; backups that exist "somewhere" but that no one has ever tested by restoring them; the account of a colleague who left last year, still active because it was on no one's agenda. None of these situations reflects a lack of technical skill. They reflect a lack of an owner: simple decisions left hanging because there is no one to say "this needs doing, and I'm the one who checks". That is the paradox of the function — it costs little when it is held, and dearly when it is not.

This responsibility is more than good practice, too. The nFADP (the revised Swiss Federal Act on Data Protection, in force since 2023) expects any company holding personal data to take "appropriate" security measures and to report serious breaches to the federal authority. The law never says "hire a CISO"; it simply assumes that, at your organisation, someone owns these decisions. For the concrete steps, the NCSC, the Swiss federal cyber security office, publishes recommendations designed for SMEs. And recognised frameworks such as ISO 27001:2022 or the NIST CSF 2.0 serve as reference points to structure the effort — not a diploma to earn, but a map so no piece is forgotten.

What to take away

  • Security is a function, not a job title: even without a dedicated CISO, someone must own the decisions, or they simply don't get made.
  • It rests on three legs — technical, educational, judgment — and the human share weighs at least as much as the tooling. That is good news for an SME: the essentials aren't bought, they're organised.
  • You don't need to bring everything in-house. You need to know who decides, who executes, and what is non-negotiable.

Steps to put in place this week

1. Name a security point person, even part-time

Designate one person — often a partner or an office manager — as the security point of contact. Their job is not to know everything, but to make sure decisions get made and followed over time. Put it in writing: with no name against the function, it stays orphaned, and "I thought that was handled" becomes the one sentence too many, the one you say after the incident.

2. Write down the three decisions that shouldn't be improvised

Take one page, no more. Note three things: how you validate a change of bank details or an unusual payment (for example a call-back to a known number, never the one in the incoming email); who you call, and in what order, if you suspect an attack; and which data is most sensitive, and therefore first to protect. This isn't a full plan yet — it's the base that prevents improvisation on the day the pressure rises.

3. Frame your external IT provider

Many SMEs entrust IT to an external provider: that's healthy, provided you know what they actually cover. Ask three questions, in writing. Is multi-factor authentication (MFA — on top of the password, a second proof, such as a code sent to your phone) active everywhere? Are backups tested, not merely present? What happens, concretely, if we're attacked on a Friday evening? A responsive provider isn't necessarily proactive about security. Asking these questions is already exercising the security officer function.

Where do you really stand?

Naming a point person, framing a provider, writing down three decisions: these steps cover the function without creating a job. What remains is to know, honestly, where you're solid and where you're relying on trust and habit. That is exactly what the Cyber Passport self-assessment does: it certifies nothing and never declares you "compliant" — it shows you, question by question, what a security officer would look at in your organisation, and where to start. At the end, a clear report you can share with your clients and auditors, to turn a vague worry into an action plan.

You don't need a CISO to start well. You need to decide that security has an owner at your firm — even part-time, even yourself — and to give them a first list of things to look at. The rest is method, and method can be learned.

Topics

  • security officer
  • CISO
  • SME
  • governance
  • Switzerland

Read next

A line-up of cybersecurity professionals, each shown with an emblem of their role: monitoring a screen, testing a lock, advising with a clipboard
AwarenessAug 17, 20267 min read

Cybersecurity roles: who does what?

SOC analyst, pentester, CISO, consultant: a clear guide to cybersecurity roles so your SME knows exactly who to turn to.