Cybersecurity has long sat with whoever happened to have the competence, often far down the organisation and far from the decisions that determined the outcome. Whoever understood the problem rarely had the mandate to solve it, and whoever had the mandate rarely understood the problem. The Cybersecurity Act changes that arrangement. This chapter is about what that change demands of those who now carry the responsibility.
It opens with why the leadership has to own the question, an argument as much about decision rights as about law. Then follow the five areas of board responsibility, the load bearing structure of the chapter and the closest thing to a checklist a board will get. After that comes the role of strategic adviser, how a security lead translates technical conditions into material a decision can actually be taken on, and the training duty the law places on the leadership. One section compares organisational models for where the security function should sit and what its placement does to its ability to influence, since a function reporting to the very people it is meant to scrutinise rarely scrutinises very hard. Then comes the board agenda in practice, which questions actually belong there, how often and in what form. The chapter also covers the role of the board during a crisis in progress, which needs to be settled beforehand, and what happens when culture work meets a structural wall. How responsibility translates into direction is covered in chapter 9 on cybersecurity strategy, and the numbers in chapter 12.
The reason this is urgent is that supervision has begun. In a review it is the documented decisions and competence of the leadership that are asked for, not the finer points of the technology. The review targets what material the leadership had, which decisions were taken and when. Administrative fines are directed at the organisation, but the question of responsibility reaches further than that and is tested in practice only once something has gone wrong.
This page shows what the chapter covers and why responsibility now sits where it does. The five areas, the agenda and the crisis role in detail are in chapter 8 of the book.
That is the difference between complying with the law and building resilience.
Key insights
- Responsibility sits with the leadership and cannot be delegated away. Tasks can be distributed, the responsibility does not travel with them.
- The Cybersecurity Act requires the leadership to be trained, not merely to take decisions.
- A CISO who reports only technical metrics hands the leadership material it cannot decide on.
- The role of the board during a crisis needs to be settled in advance, or it will be settled at the worst possible moment.
- Culture work reaches a limit when the structure works against it. At that point it is the structure that has to change.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
System tools
Tools for maturity measurement and follow up that stand up in front of a board.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.