CISO (Chief Information Security Officer)

CISO reporting line and core security responsibility areas

A CISO is the person accountable for information security across an organisation, and in a growing number of sectors the role is no longer optional but written into regulation.

  • Glossary
  • Governance

The short answer

A CISO, or Chief Information Security Officer, owns security risk for the business. The role covers policy, risk assessment, compliance mapping, incident response, vendor risk and reporting to the board. It is a governance role rather than an engineering one. Indian financial regulators now require regulated entities to designate a CISO, and enterprise buyers ask who holds the role long before any regulator does. Small companies rarely hire one. They assign the accountability and buy the capability.

The word most people miss in that definition is accountable. The role is not about configuring the firewall. It is about answering for whether it was configured correctly.

What a CISO actually does

The role is often described as technical leadership, which undersells it. Most of the work is translation: turning technical reality into risk the board can act on, and turning regulation into controls engineers can build.

Board or founders CISO Accountable for security risk Policy and governance Risk and compliance Security operations Incident response Third-party risk Regulators expect the reporting line to sit outside the team that builds and ships the systems.
Swipe to see the full diagram. In a small company one person may cover every box. The accountability still has to be named.

When a CISO becomes mandatory

For most startups the trigger is commercial before it is legal. A security questionnaire asks who owns security, and a blank answer stalls the deal. In regulated sectors the requirement is explicit.

TriggerWhat it requires
RBI Information Technology Governance DirectionsA designated CISO at banks and at non-banking financial companies in the Middle, Upper and Top NBFC regulatory layers, with a defined reporting line
Payment system operator licencesBoard-approved information security governance, which in practice means a named owner
Securities and insurance regulatorsCyber security frameworks for market intermediaries and insurers designate an accountable security officer
ISO 27001 and SOC 2No CISO title is mandated, but roles and responsibilities must be assigned and evidenced
Enterprise procurementVendor questionnaires and due diligence ask for a named security contact and an escalation path

CISO, Chief Technology Officer and security engineer

These get collapsed into one another constantly, usually because one person is doing all three.

RoleOwnsProblem when merged
CISOSecurity risk, policy, compliance posture, board reportingLoses independence if buried inside engineering
CTOTechnology strategy and deliveryShipping speed and security assurance pull in opposite directions on the same calendar
Security engineerBuilding and running controlsCannot audit their own work, and does not sit close enough to the board
Fractional or virtual CISOThe governance layer, part-time and externalNeeds real platform data underneath, or it becomes documentation with nothing behind it

Why regulators care about the reporting line

The requirement is rarely just that a CISO exists. It is that the CISO can raise an uncomfortable finding without it being overruled by the person whose release it would delay. That is why the directions talk about where the role reports, not only whether the title has been filled.

What lean teams do instead

A full-time CISO is a senior hire, and most companies at seed or Series A cannot justify one against an engineering role. The workable pattern has three parts.

Name the accountability

Usually a founder or the head of engineering, written down, with the escalation path documented. Unnamed ownership fails questionnaires immediately.

Buy the capability

Testing, monitoring, posture management and evidence collection run on a platform rather than depending on someone’s available hours.

Rent the judgement

Fractional or virtual CISO support for the audit-facing and board-facing work, without carrying a full-time salary.

What does not work is treating the title as the deliverable. Appointing someone with no tooling, no risk assessment process and no evidence trail produces an org chart entry and nothing a reviewer can rely on.

How Osto covers the CISO workload

Most of the work a security leader coordinates gets scattered across ten separate tools. Osto runs it in one stack by default. Expert-led VAPT and continuous scanning cover the testing programme, cloud posture management and correlated logging cover monitoring and detection, and multi-factor authentication and access controls cover the identity baseline. Because every module sits in the same stack, the reporting a CISO would otherwise assemble by hand comes out of one dashboard.

The compliance layer is purpose-built for the governance half. Controls map to SOC 2, ISO 27001, the DPDP Act and Indian sectoral frameworks from the same evidence, so one person can hold the role credibly without a team behind them. Osto prepares your evidence and gets you through the review. Where an audit is mandated, it is performed by the accredited or CERT-In empanelled auditor.

Free security assessment

Security leadership without the headcount

Osto runs the testing, monitoring, posture and evidence a security programme needs, in one platform. Your named owner gets a dashboard instead of a second job.

Get a free security assessment Book a platform walkthrough

Audit-ready in days · SOC 2, ISO 27001 and DPDP mapped · One platform, everything

Frequently asked questions

What does a CISO do?

A CISO owns information security risk for the organisation. That covers security policy, risk assessment, compliance posture, security operations oversight, incident response, third-party risk and reporting to the board. The role is accountable for outcomes rather than responsible for implementation.

What is the difference between a CISO and a Chief Technology Officer?

The Chief Technology Officer owns technology strategy and delivery. The CISO owns security risk and assurance over that technology. Merging the two creates a conflict, because the same person judges whether their own delivery decisions were safe. Regulators focus on the reporting line for this reason.

Does a startup need a CISO?

Rarely as a full-time hire before scale, but almost always as named accountability. Enterprise security questionnaires and due diligence ask who owns security and how issues escalate. A blank answer stalls deals. Most small teams assign the role internally and support it with a platform and fractional expertise.

Is a CISO legally required in India?

In regulated sectors, yes in substance. The RBI Information Technology Governance Directions require banks and non-banking financial companies in the Middle, Upper and Top Layers to designate a CISO with a defined reporting line, and securities and insurance regulators set comparable expectations. There is no general requirement across all companies.

What is a virtual CISO?

An external, part-time arrangement that supplies the governance and board-facing work of the role without a full-time hire. It fits companies that need credible security leadership for audits and customer reviews but do not yet have the scale to justify the salary. It works only when real platform data sits underneath it.