When an IT manager also carries security responsibilities

An IT manager can carry security responsibilities where the applicable rules and organisational scale allow it. The issue is how the organisation manages conflicts of interest and obtains independent challenge.

A combined role knows the systems and can act quickly. It also asks the same team to assess controls it designed and operates. Establish direct reporting to management, explicit risk acceptance authority and independent review proportionate to the risk. Do not infer concealment or incompetence from the combined title.

For financial entities, DORA Article 5(4) contains specific requirements for the independence of the ICT risk control function, with an exception for microenterprises. Check those requirements before choosing a staffing model. Proportionality is not a substitute for the applicable rule.

What the role does to the person holding it

A security leader must connect technical evidence with decisions under uncertainty. That requires both competence and a reporting environment in which inconvenient findings can be discussed.

Our research paper on technical and psychological approaches to governance addresses those dimensions. The practical application is to examine how concerns reach management, who can act on them and whether the person raising a problem receives a useful response.

Do not measure a healthy reporting culture by the volume of bad news alone. Examine a real escalation: the evidence, decision, owner and follow-up. A quiet meeting can reflect low activity, poor information or a reporting failure; it does not prove which.

When a full-time CISO makes sense

A full-time role can be justified by a continuous decision workload, a team to lead, complex dependencies or sustained customer and supervisory engagement. Headcount alone is a weak decision rule.

Define the decisions the CISO owns and those the role advises on. Residual risk is accepted by the authorised business or management owner within the agreed governance model; the CISO does not automatically accept every risk personally.

Compare the cost of delayed or unsupported decisions with the cost of permanent availability. Financial regulation does not, by itself, prove that every entity needs the same full-time staffing arrangement. Check mandatory role requirements and the actual workload.

What a fractional or external CISO can and cannot do

An external or fractional role works when it is positioned as an independent reporting line, not as extra IT capacity.

It can: build the framework and the risk register; write the policies and then verify that they actually hold; prepare for and sit in the supervisory dialogue; deliver the management-body training; act as a counterweight to IT without that costing anyone a career; and say out loud the thing an employee cannot afford to say.

It cannot: assume the statutory responsibility of the management body; be on site in the first twenty minutes of every incident, unless that is exactly what was contracted; run your internal politics for you; or replace an internal owner for day-to-day operations. An external role supplies judgement and structure, not presence.

It fails in three ways. First: the company wanted someone to blame rather than someone to advise — then the first uncomfortable recommendation ends the relationship. Second: there is no internal recipient with the authority to act, so the recommendation becomes an archive. Third: access is limited to what IT chooses to show, which turns every conclusion into a hypothesis.

The three arrangements, compared

Arrangement Useful strengths What must be designed explicitly
Combined IT and security role System knowledge and close connection to execution Conflicts of interest, independent review and direct management reporting
Full-time CISO Sustained availability and leadership across recurring decisions Mandate, resources, authority and the division of risk ownership
External or fractional CISO Specialist capacity and an independent perspective Agreed availability, access to evidence, internal execution and escalation

The external role can carry defined operational responsibilities and contractual obligations. It does not transfer the management body’s statutory accountability. An incident-response retainer and a part-time advisory role also provide different availability; write down which one you are buying.

What nobody can take off your hands

NIS2 Art. 20 is short and blunt. The management body approves the cybersecurity risk-management measures, oversees their implementation, and can be held liable for infringements. Its members are required to follow training that lets them identify risks and assess risk-management practices, and the entity is to offer comparable training to employees on a regular basis.

For essential entities, Art. 32(5) goes further. Where the enforcement measures under Art. 32(4) have proved ineffective, the authority sets a deadline for the entity to remedy the deficiency. If the entity still does not act, the authority may suspend a certification or authorisation, and may request a temporary prohibition on a person discharging managerial responsibilities at chief executive officer or legal representative level from exercising managerial functions in that entity. It runs only until the deficiency is remedied, and Art. 33 withholds the power for important entities — but it exists, and it is addressed to a person, not to the legal entity.

Delegation needs a defined scope and a retained accountable owner. For local applicability and transition provisions, see NIS2 in Bulgaria; for sector-specific overlap, see DORA and NIS2.

What to do first

  1. Record who accepts which risks, within what authority and with what escalation limits.
  2. Ensure management receives an evidence-based security report and independent challenge where required.
  3. Give security a scheduled agenda item, decisions, owners and follow-up.
  4. Deliver management training appropriate to the role and applicable duties; retain participation and learning evidence.
  5. Test an escalation through a realistic example and check whether it reaches a decision-maker.
  6. Agree incident decision authority and deputies, including outside normal working hours.

Use the policy adoption guide to check whether the resulting structure works in everyday decisions.

When comparing proposals, use the vCISO cost and monthly scope guide to distinguish expert capacity, deliverables and availability.

The boundary

This article is about accountability structure, not employment law and not directors' and officers' insurance. How duties are allocated among members of the management body, how they are delegated internally, and where personal liability lands are matters of Bulgarian company and employment law. That is a conversation with a lawyer, not with a security adviser.

It also does not settle whether your specific entity falls in scope, or which supervisory authority is competent for it. An external role does not change who the regulator addresses: it addresses the entity and its management body.

If you want the structure to exist before someone outside asks for it, start with ongoing support and external roles — it sets out what a fractional role covers and what stays inside.

Note: this is general information, not legal advice. Applicability depends on the specific entity, activity, licence, size, group structure and national implementation.