Why “We Have IT Handling That” is no longer enough to keep organisations secure, resilient and compliant
There is a question that surfaces in board meetings, insurance renewals, due diligence processes, and post-incident reviews more than any other. It is uncomfortable precisely because it sounds simple.
“Who owns cyber security in this organisation?”
In a surprising number of small and medium-sized businesses, the honest answer is – nobody does. Not formally or accountably. There is an IT Director who handles the infrastructure. There is a Head of Compliance who manages the frameworks. There is a senior leader, often the CEO or CFO who steps in when the topic comes up in a board meeting and does their best to project confidence. But there is no single person with the expertise, the mandate, and the accountability to own the organisation’s security posture end to end.
This is not a failure of intent. It is a structural gap that has opened up as the threat landscape has grown faster than the talent market and the budget cycles of most organisations. It is a gap that carries consequences if not addressed. Consequences that are becoming harder to absorb as regulatory expectations increase, insurers tighten their criteria, and customers start asking questions their suppliers cannot answer.
This article sets out what the cyber security leadership gap looks like in practice, why it tends to stay hidden, and how businesses can begin to address it.
What the leadership gap actually looks like
The cyber leadership gap rarely presents as an obvious absence. Most organisations that have it believe, genuinely, that they have it covered. The IT function is capable. The policies exist. The awareness training has been done. There is a firewall, antivirus and endpoint detection.
What is missing is not technology. It is strategic ownership.
A CISO, does something that no amount of tooling can replicate. They translate between the technical reality of the organisation’s security posture and the business language that the board, insurers, regulators, and customers need to hear. They maintain a live risk register that reflects what is actually happening in the environment, not what the policies say should be happening. They prioritise remediation not by what is technically interesting, but by what the business cannot afford to lose. They make sure that when the responsibility question is asked, in an audit, due diligence call, or a board meeting, that there is a coherent, evidenced answer.
Without that leadership, organisations accumulate risk in the gaps. Not dramatic, headline-grabbing risk in most cases. The quieter kind. Policies that exist on paper but have never been enforced. Security controls that were implemented two years ago and have not been reviewed since. Vendors who were assessed at onboarding and never since. A risk register that was created for a certification exercise and now sits in a shared drive, unreviewed.
None of these individually represents a crisis. Together, they represent an organisation that does not know its own exposure and will only find out what it is at a moment of its attackers’ choosing rather than its own.
Why the gap stays hidden
The cyber leadership gap tends to stay hidden because the people who know it exists are also the people who are asked to paper over it. The IT Director who gets asked to present the “cyber update” to the board. The Head of Compliance who adds a security section to the risk register without the technical depth to make it meaningful. The COO who fields the insurer’s questionnaire by calling the IT team and hoping the answers are correct.
From our experience at Cyberfort the most common reasons the security leadership gap stays hidden and the potential impact this is having are:
No baseline
Without a formal security programme and a consistent measurement framework, most organisations do not have an accurate picture of their current posture. They know roughly what controls they have in place. They do not know whether those controls are working, if they are configured correctly, or they cover the attack surfaces that actually matter.
No ownership
When something goes wrong, a phishing campaign, a data subject access request that uncovers a gap, an insurer query that cannot be answered cleanly, it is not immediately clear whose problem it is. The IT team escalates. The compliance team flags it. Leadership is briefed. But nobody has the authority and the expertise to make the decision and own the consequences.
No continuity
Security decisions made in one year are rarely revisited in the next unless something forces them onto the agenda. A control that was fit for purpose when the organisation had fifty staff may be entirely inadequate at two hundred. A supplier relationship that looked low-risk before a business’s data environment expanded may now represent significant exposure. Without ongoing strategic oversight, the security programme drifts.
When the gap becomes visible
The cyber leadership gap tends to become visible in one of several different circumstances which are highlighted and discussed below. The situations described below are the most common ones we see at Cyberfort where cyber security leadership is needed on a fractional basis.
A board accountability question
An investor, a non-executive director, or a regulator asks who is accountable for cyber security and wants a specific name. “The IT team” is not an answer. “We are reviewing our governance arrangements” is not reassuring. The absence of a named, qualified owner is itself a red flag.
An insurance renewal
Cyber insurance questionnaires have become substantially more demanding over the past three years. Insurers now ask detailed questions about governance, patch management processes, privileged access controls, and incident response capability. Organisations without a security leader who cannot answer those questions and evidence the answers, face premium increases, exclusions, or declined renewals.
An enterprise customer questionnaire
Larger customers, particularly in financial services, professional services, and public sector supply chains, increasingly require their suppliers to demonstrate security maturity before onboarding. Security questionnaires that would once have been handled by the IT team now require board-level sign-off on governance arrangements that, in many cases, do not exist.
A merger or acquisition
Security due diligence has become a standard part of the M&A process. A target organisation with no security programme, no risk register, and no governance framework represents a discount to valuation and a material integration risk. Acquirers who find this out during diligence are rarely forgiving.
A post-incident review
After a security incident, a phishing compromise, ransomware attempt, or a data breach, the question that follows is always – what was the governance arrangement that allowed this to happen? The absence of a security leader means the answer is, at best, complicated.
A new regulatory obligation
GDPR, NIS2, DORA, the ICO’s guidance on accountability, each of these creates specific governance obligations that cannot be met by an IT team alone. They require documented processes, named accountabilities, and evidence of ongoing oversight.
A new executive with a risk mandate
A new CEO, CFO, or COO who comes from a more security-mature environment and discovers the governance gap on arrival. These individuals tend to move quickly, because they understand the exposure they have just inherited.
What good Security Leadership provides
It is worth being clear about what a senior security leader actually does, because the gap is sometimes described in terms of credentials “we don’t have a CISO” rather than a leader .
A CISO, or an equivalent senior security leader , provides four things that cannot be replicated by tooling, frameworks, or occasional consultancy.
Strategic context
The ability to understand the business’s risk appetite, its commercial priorities, and its threat profile, and to translate those into a security programme that protects what actually matters rather than what a framework says should be protected.
Governance
The policies, processes, and oversight mechanisms that ensure the organisation’s security programme operates consistently, is reviewed regularly, and is aligned to current risk rather than historical assumption.
Board communication
The ability to present security risk in language that a board can act on, not as a list of technical vulnerabilities, but as a business risk with financial, operational, and reputational dimensions, prioritised and costed.
Accountability
A named, qualified individual who owns the outcome. When something goes well, that accountability creates credibility. When something goes wrong, it creates the capacity to respond effectively rather than scrambling to identify who is responsible.
The Economics of the Problem
A senior CISO for a UK mid-market business now commands a salary of £120,000+. Add employer’s National Insurance, pension contributions, recruitment costs, and the management overhead of a direct report, and the all-in cost of a full-time hire comfortably exceeds £150,000 per year.
For organisations in the £20m to £100m revenue range, the market where the governance gap is most common and most acute, that is a significant financial commitment. Many organisations in this revenue range do not need a full-time CISO. They need the output of one: strategic oversight, governance, board reporting, and the ability to field the questions that arise from insurers, regulators, and customers with confidence.
The fractional model has emerged as a direct response to this economics problem. Rather than committing to a full-time hire that the organisation may not fully utilise, organisations can access senior security expertise on an ongoing, structured basis, maintaining the continuity, the accountability, and the strategic oversight that the gap creates, at a fraction of the cost.
Understanding the business value of a vCISO
The value of a fractional security leadership model lies not just in the expertise it provides, but in the structure it imposes. An effective engagement creates the governance mechanisms that allow an organisation to operate with appropriate security maturity, rather than simply providing advice on demand.
A well-structured vCISO engagement with a specialist MSSP typically progresses through the following stages.
Step 1 — Onboarding and Current State Assessment
The engagement begins with a structured review of the organisation’s current security posture – existing controls, policies, governance arrangements, risk register, and any historical audit or assessment findings. The objective is to establish an honest baseline, not a polished picture, but an accurate one.
Step 2 — Governance Framework and Risk Register
With a baseline established, the engagement moves to building or rebuilding the governance structures that the organisation needs. This includes a live risk register that reflects the actual environment, a suite of policies that are enforced rather than archived, and the governance mechanisms that ensure ongoing oversight.
Step 3 — Security Roadmap
The governance framework is paired with a prioritised roadmap, the specific actions, in order, that will move the organisation from its current posture to its target posture. This is not a theoretical framework. It is a practical plan with named owners, clear priorities, and measurable outcomes.
Step 4 — Ongoing Leadership, Board Reporting, and Governance Oversight
The ongoing engagement provides the continuity that makes the model work. Regular leadership sessions, monthly or quarterly board reporting, active oversight of the risk register and roadmap, and the capacity to respond to the external triggers, the insurance renewal, customer questionnaire, or regulatory enquiry as they arise.
The Question to Ask
The cyber leadership gap is not a technology problem. It is not solved by deploying another tool or achieving another certification. It is solved by answering one question clearly ’Who is responsible for security in this organisation, and what does that responsibility actually mean?’
If that question does not have a clean answer, or if the answer is a name followed by a long explanation of everything else that person is also responsible for, it may be worth understanding what a structured approach to closing that gap would look like. It is also probably time to engage with a specialist MSSP who has the skills, knowledge and expertise to fill your businesses security leadership gap before it’s too late.
For more information about Cyberfort’s vCISO service and how it can help your organisation build its security strategy and achieve its objectives, email us at [email protected] and one of our experts will be in touch.





















