An operating model, not merely a job title
An information security manager connects business priorities, technology dependencies, regulatory obligations and the threat environment. The role creates value when executives receive a clear risk view, teams understand their responsibilities, and material security actions have owners and deadlines.
A Virtual CISO performs essentially the same function through an external or part-time model. It may carry a stronger strategic emphasis, but often includes practical coordination of the ISMS, incidents, suppliers, audits, training and customer assurance requests.
Six signs that the role is already needed
For regulated organisations, direct executive accountability reinforces this need. DORA assigns the management body ultimate responsibility for ICT risk, while NIS2 requires management involvement in approving and overseeing cybersecurity measures. Executives do not need to become technical specialists; they need a reliable governance mechanism and decision-ready information.
- Security work is spread across several teams, but no one owns the overall priorities and progress.
- Customer questionnaires, audits or regulatory deadlines repeatedly become urgent one-off projects.
- Executives receive technical findings but cannot see business impact, residual risk or the decisions required.
- Supplier, cloud and material technology decisions are made without consistent security input.
- Policies and risk registers exist, but control ownership, evidence and review are not managed continuously.
- Incidents recur without lessons being converted into concrete changes to processes, technology or training.
Which engagement model fits?
The mandate should be explicit: which decisions the role prepares or makes, where it reports, which teams it coordinates and how results are measured. Without this, an external leader can become another adviser producing recommendations without ownership of delivery.
- A permanent role fits organisations with substantial daily workload, a dedicated team and extensive internal coordination.
- A part-time or outsourced information security manager fits when consistent leadership is needed but a full-time role is not yet justified.
- A project model fits a defined objective such as ISO 27001 implementation, DORA or NIS2 readiness, an audit or recovery of a stalled security programme.
- A transition model maintains governance while a permanent security leader is being recruited.
What the first 90 days should deliver
A strong initial phase does not create dozens of policies simply because a template list says they are missing. It first identifies the decisions the organisation must make and the controls that matter most to its services and risk.
- A view of material services, information assets, dependencies and obligations.
- An updated priority risk register expressed through scenarios executives can understand.
- A prioritised 6–12 month roadmap with owners, dates and dependencies.
- A clear cadence for incidents, suppliers, vulnerabilities, access, training and control evidence.
- A concise executive report separating facts, decisions, progress and accepted residual risk.
What good looks like
After several months, there should be fewer unexpected urgent tasks, clearer control ownership and a better executive understanding of where risk is reducing, where it remains and what decision is needed. Documents matter as evidence of operating governance, not as an end in themselves.
If the service is measured only by the number of documents produced, the wrong outcome is probably being measured. Better indicators include faster decisions, closure of material gaps, operating controls, incident readiness and the management body’s ability to accept residual risk consciously.
Official sources
Glesum