In many companies, information security is still treated as an IT issue. As a result, it gets delegated.

→ To the IT department.
→ To external service providers.
→ To “someone who takes care of it.”

What gets overlooked in the process:
Security is not a technical issue.
Security is a business decision.

The good news:
The independent repair shop just around the corner.
A quick look, parts ordered, installed by the afternoon.
And they even threw in a really good cup of coffee for free.

The reality for business leaders?
NIS-2 is fundamentally changing the landscape:
→ Personal liability becomes a reality
→ Responsibility can no longer be delegated (spoiler: it never really could be in the first place!)
→ Ignorance is no defense

Anyone who still believes they can “outsource” information security is losing control over one of the biggest risks facing their company.

The key point?
Resilient companies do things differently:
→ They manage information security from the CEO’s office
→ They embed the issue at the executive level
→ They make informed risk decisions

Because in the end, it’s not about firewalls or tools. It’s about:

  • Business models
  • Delivery capability
  • Reputation
  • Ensuring business continuity

In plain language:
Information security belongs on the executive board’s agenda.
Not in the server room.

Who in your company is REALLY responsible for information security?

Tags

Share post

More articles

The wiper blades on my leased vehicle were worn out.The car had been sitting for six months before I took delivery—low mileage,visibility is now limited. Lease includes maintenance & wear and tear; wiper blades are...
This question is often asked by novices who are dealing with ISO 27001 for the first time. What is an Internal Audit? An internal audit is a self-audit to verify three key points by an...
Numerous details about people, their purchases and other sensitive details could be accessed unprotected on the web for months, as Der Spiegel (German content) prominently reports on its website. A service provider had inadequately secured...