Security is decided in the boardroom, not the server room
In most organisations, information security is still something handled by somebody else, somewhere further down the structure. Responsibility, meanwhile, has moved upwards: regulation and owners now expect the board and the executive team to account for risk, priorities and control. Here is what owning security actually involves as a leader, and why it does not require you to become a technologist.
The question that exposes the governance model
Ask two questions in the same meeting. First: who owns the finances here? The answer comes back as a role, a rhythm and a set of documents: the finance director, the quarterly report, the budget process, the audit, the board's own review of it. Second: who owns information security? The answer usually comes back as a person's name, and that person sits in IT.
The difference is not that one matters more than the other. It is that one has a governance model and the other has an individual. People leave, become overloaded, or get it wrong. A governance model withstands all three, because it distributes decisions, records them and makes them possible to check.
Information security ending up with "the one who is good with computers" is rarely a deliberate choice. It is an inheritance from a time when IT was something the business used rather than something the business was made of.
One in fifty
Berigo's owner and head of practice, Roger Ison-Haug, has researched the relationship between the number of adverse cyber incidents and the competence of senior leadership. One finding is easy to state and hard to dismiss: among Norway's 50 largest companies, measured by the Kapital list, one company had leaders with a formal education in cyber security. Across the Forbes Global 500, the figure was around ten out of 500.
"There is a gap between senior executives' responsibility and their actual competence in cyber security."
Those numbers do not describe incompetent leaders. They describe an expectation that was never set. For decades we have treated formal financial literacy as a given at the top of an organisation, and built the whole governance model around it: reporting lines, audit, a board able to read the figures. The equivalent expectation in security barely exists, while the responsibility has travelled in the opposite direction.
An organisation chart that never caught up
IT and security were historically treated as support functions, often sitting under the finance department alongside other costs to be kept down. That was a reasonable place for them at the time. Today information technology is a precondition for the business existing at all: production, delivery, the customer relationship and the cash flow all sit in systems.
The business has moved. In many organisations the governance model has not. The result is that an existential dependency gets the same attention as an operating cost.
Nobody is asking the board to become technologists
This is where the misunderstanding arises that makes many leaders step back: the belief that owning security requires technical depth. It does not.
A board does not keep the ledger. It reads the accounts, understands what the figures mean for strategy, recognises when something looks wrong, and asks questions the finance director has to be able to answer. Nobody asks the board to do the bookkeeping. They ask it to govern.
The requirement in security is the same, no more and no less. Executives are not technologists, but they own the strategic choices and objectives: which risks the business will live with, what gets prioritised, what it should cost, and what will be measured. A specialist further down the organisation cannot make those calls. Not for want of skill, but for want of mandate.
Four things leadership genuinely owns
- Risk appetite and materiality. How much downtime, data loss or disruption to delivery can the business absorb before the strategy itself is at risk? Without an agreed answer, every individual risk becomes a judgement call somewhere down the organisation, and prioritisation is left to chance.
- Prioritisation. No organisation closes every finding. Deciding what is fixed now, what is deferred and what is accepted is a business decision with consequences, and it belongs where those consequences land.
- Budget and expected return. The security budget is often the only budget a board approves without asking what it is meant to deliver. The question is not merely what it costs, but what it buys, and what would change with a fifth more or a fifth less.
- Measurement and follow-up. A small set of indicators that says something real about exposure and delivery: not blocked emails, but time to recover, coverage across critical systems, and progress against objectives leadership itself has set.
The job description has already been written
What makes this concrete is that the duties of senior management are already written down, in regulation and standards most organisations deal with anyway. The requirements are not technical. They describe a way of working.
- NIS2, Article 20. The management body must approve the organisation's cyber risk management measures, oversee their implementation, and can be held liable for breaches. The same article requires members of the management body to undergo training themselves. The competence requirement is personal, not organisational. The directive is EEA-relevant and is to be transposed into Norwegian law; for many organisations, though, the requirements arrive first through contracts with customers and group companies in the EU.
- ISO/IEC 27001:2022, clause 5. The standard places a set of duties directly on top management: ensuring the security policy and objectives are compatible with the strategic direction of the business, ensuring the requirements are built into ordinary processes, making the necessary resources available, and assigning roles and authority, including who reports on the state of things to management itself.
- ISO/IEC 27001:2022, clause 9.3. The management review is not a briefing. The standard specifies what goes into it: the status of earlier decisions, changes in the risk picture and in what interested parties require, measurement and audit results, nonconformities and corrective actions, the status of the risk treatment plan, and it must end in decisions. If the organisation runs an information security management system, the agenda for the board's security item already exists.
- GDPR, Article 5(2). The accountability principle: the controller must not only comply, but be able to demonstrate compliance. Compliance that cannot be evidenced does not count as compliance.
- ISO/IEC 42001 and the EU AI Act. The pattern repeats in artificial intelligence. The AI management system standard is built on the same frame as 27001, with the same duties for top management. The AI Act adds a requirement that organisations developing or deploying AI ensure a sufficient level of AI literacy among those operating the systems on their behalf (Article 4).
None of these requirements is about technology. They are about who decides, how often, on what basis, and what can be produced afterwards.
A better buyer, a tougher reviewer
The practical consequence is that leadership has to become a better buyer and a tougher reviewer of what it has bought.
A weak buyer gets whatever the supplier has on the shelf. A weak reviewer gets reports written to reassure. Both cost money without reducing risk, and both become visible afterwards: in an audit, in an inspection, or on the day something actually happens.
A good buyer knows what the business is protecting and why, states the requirements in business terms, and buys outcomes rather than products. A good reviewer asks for a handful of figures over time, compares them with what was promised, and refuses to accept amber as a permanent state.
Competence is not the same as a course
The common response is to send the executive team on a half-day course. Structured training has real value: it gives leadership a shared vocabulary, and under NIS2 it is, as noted, a personal duty. But a certificate is not the same as control, because the problem is rarely a shortage of information. It is the absence of a working method.
What works is repetition within the rhythm leadership already has: a standing item with the same questions every quarter, a risk appetite that is formally adopted and reviewed, and exercises in which the executives themselves have to decide under uncertainty, not as technical training, but as leadership practice. After two or three rounds, a board starts to hear the difference between an answer that holds and an answer that merely reassures. That is where real control begins.
It starts with the questions
None of this needs a programme or a project to begin. It needs a few questions that cannot be answered with a slide, and the discipline to ask the same questions again next quarter.
At that point security stops being an item for noting and becomes a matter of governance. That is the entire point.