Glossary

Chief Information Security Officer (CISO)

C-level executive responsible for overall information security strategy and compliance.

A

B

C

The Chief Information Security Officer is the senior executive responsible for establishing and maintaining an organisation's information security vision, strategy and programme. The CISO oversees risk assessments, security architecture, incident response, compliance with regulations and frameworks, and security awareness across the organisation.

Modern CISOs must balance technical expertise with business acumen, translating complex security risks into business terms for board-level reporting. They play a pivotal role in frameworks like ISO 27001, where top management commitment is a mandatory requirement, and are increasingly held accountable for regulatory compliance under GDPR, NIS2 and the EU AI Act.

D

E

F

G

H

I

J

K

L

M

N

O

P

Q

R

S

T

U

V

W

Z

Frequently asked questions

What does a CISO do?
A Chief Information Security Officer owns the information security strategy: setting policy, running risk management, overseeing controls and incident response, and reporting security posture to executive management and the board.
Does NIS2 require a CISO?
NIS2 does not mandate the job title. It does make management bodies accountable for approving and overseeing cybersecurity risk-management measures under Article 20, and requires them to follow training — so the responsibility exists regardless of who holds it.
What is a virtual or fractional CISO?
An external specialist who performs the CISO role part-time across one or more organisations. It is a common arrangement for smaller companies that need the accountability and expertise without a full-time hire.