What Security Decisions Should a CEO Make? The Ones You Can't Outsource
By Jon Rose, Founder & Managing Partner · · 4 min read
A fractional or virtual CISO can build your security program, implement controls, and advise on technical decisions. But certain decisions require executive judgment that can’t be outsourced.
These fall into three categories: disclosure decisions, budget decisions, and risk tolerance decisions. Your security advisor can inform these choices, but the final call belongs to the management team.
Disclosure Decisions
When you have an incident or near-incident, how far do you go in communicating with customers?
There are legal obligations, regulatory requirements, and contractual commitments that define minimum disclosure. But beyond the legal floor, there’s a gray zone where business judgment takes over.
Maybe the incident didn’t technically trigger notification requirements, but it came close. Maybe you can argue about whether this qualifies as a “breach” under various definitions. Maybe the impact was limited and notification would create more concern than the actual risk warrants.
The decision about how proactive and transparent to be is fundamentally a cultural and business decision. Your CISO can advise transparency (and they almost always should). But the management team has to weigh factors the CISO can’t fully evaluate: fundraising timing, deal closures, competitive dynamics.
Companies that are proactive about communicating tech outages and issues tend to be the same ones that disclose security incidents transparently. Companies that never say anything about problems tend to hide security incidents too.
The pattern is consistent: transparency builds more trust than silence, even when transparency is uncomfortable. But the decision about how much transparency and when to provide it belongs to leadership.
One of our MDR partners won’t give an SLA, but they make everything completely transparent about when their systems fail. That visibility is worth more than a contractual guarantee you’ll never actually collect on.
Budget Decisions
Your CISO can recommend a security budget. They can tell you what tools to buy, what services to engage, and what staffing you need. They can prioritize and sequence investments.
But they don’t know your financial situation. They don’t know what other investments are competing for the same dollars. They don’t know your runway, your cash position, or even your board’s expectations.
The honest conversation between a CISO and executive team is something like this: here’s what we recommend, here’s what happens if we don’t do it, here’s where we could defer if we’re pressed for investment, and here’s what I wouldn’t defer.
Almost never does a regulation say “you must spend $50K on this specific tool.” Regulations say you need to address certain risks, and there are many ways to do that. The CISO provides options and an honest assessment of tradeoffs. The management team makes business decisions about how to allocate resources.
The companies that get this right have CISOs who deliver hard news honestly. They can say here’s the budget we need, and here’s why. Here are the consequences of spending less. The executive team then makes an informed decision.
Risk Tolerance Decisions
This is the most nuanced category. Every business operates with some level of risk. The question is how much risk is acceptable.
Consider a SaaS product with friction in the signup flow. Adding security controls (such as identity verification, fraud detection, captchas) would reduce abuse but also reduce conversion. So the question becomes how much abuse can you tolerate?
For e-commerce, how much fraud do you withstand before adding controls that slow down legitimate purchases?
For B2C products, how much know-your-customer friction do you implement when you’re not legally required to?
These aren’t security decisions. Instead, they’re business decisions with security implications. Your CISO can quantify the risk, show you the metrics, and explain the tradeoffs. But the decision about where to set the tolerance belongs to leadership.
In our experience, B2C and e-commerce companies often reach an equilibrium on risk tolerance before they engage security leadership. They’ve had fraud events, adjusted their controls, and arrived at a level of loss they can live with. The CISO’s job is to illuminate risks they haven’t realized yet and help them make more informed decisions about their tolerance.
Take the checklist: Signs You Need a CISO
An honest assessment of whether your company has outgrown DIY security.
Take the checklist →The question of “how much friction will we accept in exchange for how much security” is a product and growth question, not purely a security question.
What Can Be Outsourced
The flip side is that most operational security decisions can and should be delegated to your security leadership.
Build versus buy decisions. This is whether to use open source or commercial tools, or whether to build internal capability or use managed services. Your CISO has the expertise to evaluate these tradeoffs.
Technical architecture decisions. This looks like how to implement controls, what technologies to use, and how to integrate security into development processes.
Vendor selection. This means evaluating and choosing security tools and service providers.
Policy development. This is creating the documentation, processes, and standards that govern your security program.
Incident response operations. These are the tactical decisions that need to be made during an incident about containment, investigation, and remediation.
Compliance strategy. This is making the decisions around which frameworks to pursue, how to approach audits, and how to satisfy customer requirements.
These decisions benefit from expertise your executive team probably doesn’t have. Delegate them to people who do.
The Partnership Model
The best security programs have clear division between executive decisions and operational decisions.
Executives set risk tolerance, approve budget, and make disclosure decisions. They define the guardrails within which the security program operates.
Security leadership operates within those guardrails. They make technical decisions, build the program, manage vendors, respond to incidents, and advise executives when decisions need to be escalated.
Problems arise when either side enters the other’s lane. You can run into executives making technical decisions they’re not qualified to make or security leaders making business decisions without executive buy-in.
The partnership works when both sides understand what they own and what they don’t.
Your security advisor can build your program and inform your decisions. The decisions about risk tolerance, budget allocation, and disclosure belong to you.
Get a CISO's perspective on your security decisions
A quick conversation to help you figure out what to own, what to delegate, and what to defer.
Talk to a CISOAbout IOmergent
IOmergent is the operating CISO for growth-stage companies. Founded in 2021 by Jon Rose and Brett Wilson, we provide fractional CISO (vCISO) services and Managed Cloud Security to SaaS, fintech and healthtech companies. Our team includes 25+ CISOs, and every CISO on our team has led security programs in-house. We have delivered 100+ engagements for 45+ companies. Fractional CISO engagements typically run $8,000 to $25,000 per month, and most engagements start within 2 weeks. More about us