Who decides on cybersecurity?

Cybersecurity is a decision for senior management, not for the IT manager. On this page I explain why, the pattern I see at many companies, and why a certificate on its own does not make you secure.

← Cybersecurity in plain language

Information security is a decision for management, not for IT

When I talk to business owners about cybersecurity, I keep hearing the same reactions. "That's something for our IT department." "IT knows what they're doing, let them decide." "Why am I responsible for something that isn't part of my business?"

Those reactions are understandable. They are just not right.

The questions a security system asks are business questions. Which information can we not do without? How long can we manage without our order management? Which risks do we accept, and which do we not? Your IT manager can prepare many of the answers. The choice between what you protect and what you accept remains a choice for senior management. ISO 27001 asks for exactly that: senior management owns the system.

Senior management owns the system
Who prepares, who decides

Approving is not the same as deciding

The pattern I see most often is subtler. The management team is presented with a well-prepared proposal, finds it sound and approves it. "It's well prepared, let them carry on."

The preparation is not the problem. But if you do not put time into it yourself, you have not really decided. The system then belongs to whoever prepared it, and not to the organisation that has to own it.

A certificate does not prove you are secure

"Once we have the certificate, we're secure." I hear that one regularly too.

A certificate says that an independent organisation confirmed, at a given moment, that your system meets the standard. That is valuable. It says nothing about what happens if nobody uses the system afterwards.

So my advice is simple. Do it properly and make sure your security system is a living part of your organisation, or do not start at all. A system that only exists on paper gives a false sense of security. And sooner or later, that will catch you out.

After the certificate
Only on paper A false sense of security
A living system Part of how your organisation works
A certificate confirms one moment

Next: The road to ISO 27001 in eight steps