A CISO is the person accountable for information security across an organisation, and in a growing number of sectors the role is no longer optional but written into regulation.
The short answer
A CISO, or Chief Information Security Officer, owns security risk for the business. The role covers policy, risk assessment, compliance mapping, incident response, vendor risk and reporting to the board. It is a governance role rather than an engineering one. Indian financial regulators now require regulated entities to designate a CISO, and enterprise buyers ask who holds the role long before any regulator does. Small companies rarely hire one. They assign the accountability and buy the capability.
The word most people miss in that definition is accountable. The role is not about configuring the firewall. It is about answering for whether it was configured correctly.
On this page
What a CISO actually does
The role is often described as technical leadership, which undersells it. Most of the work is translation: turning technical reality into risk the board can act on, and turning regulation into controls engineers can build.
When a CISO becomes mandatory
For most startups the trigger is commercial before it is legal. A security questionnaire asks who owns security, and a blank answer stalls the deal. In regulated sectors the requirement is explicit.
| Trigger | What it requires |
|---|---|
| RBI Information Technology Governance Directions | A designated CISO at banks and at non-banking financial companies in the Middle, Upper and Top NBFC regulatory layers, with a defined reporting line |
| Payment system operator licences | Board-approved information security governance, which in practice means a named owner |
| Securities and insurance regulators | Cyber security frameworks for market intermediaries and insurers designate an accountable security officer |
| ISO 27001 and SOC 2 | No CISO title is mandated, but roles and responsibilities must be assigned and evidenced |
| Enterprise procurement | Vendor questionnaires and due diligence ask for a named security contact and an escalation path |
CISO, Chief Technology Officer and security engineer
These get collapsed into one another constantly, usually because one person is doing all three.
| Role | Owns | Problem when merged |
|---|---|---|
| CISO | Security risk, policy, compliance posture, board reporting | Loses independence if buried inside engineering |
| CTO | Technology strategy and delivery | Shipping speed and security assurance pull in opposite directions on the same calendar |
| Security engineer | Building and running controls | Cannot audit their own work, and does not sit close enough to the board |
| Fractional or virtual CISO | The governance layer, part-time and external | Needs real platform data underneath, or it becomes documentation with nothing behind it |
Why regulators care about the reporting line
The requirement is rarely just that a CISO exists. It is that the CISO can raise an uncomfortable finding without it being overruled by the person whose release it would delay. That is why the directions talk about where the role reports, not only whether the title has been filled.
What lean teams do instead
A full-time CISO is a senior hire, and most companies at seed or Series A cannot justify one against an engineering role. The workable pattern has three parts.
Name the accountability
Usually a founder or the head of engineering, written down, with the escalation path documented. Unnamed ownership fails questionnaires immediately.
Buy the capability
Testing, monitoring, posture management and evidence collection run on a platform rather than depending on someone’s available hours.
Rent the judgement
Fractional or virtual CISO support for the audit-facing and board-facing work, without carrying a full-time salary.
What does not work is treating the title as the deliverable. Appointing someone with no tooling, no risk assessment process and no evidence trail produces an org chart entry and nothing a reviewer can rely on.
How Osto covers the CISO workload
Most of the work a security leader coordinates gets scattered across ten separate tools. Osto runs it in one stack by default. Expert-led VAPT and continuous scanning cover the testing programme, cloud posture management and correlated logging cover monitoring and detection, and multi-factor authentication and access controls cover the identity baseline. Because every module sits in the same stack, the reporting a CISO would otherwise assemble by hand comes out of one dashboard.
The compliance layer is purpose-built for the governance half. Controls map to SOC 2, ISO 27001, the DPDP Act and Indian sectoral frameworks from the same evidence, so one person can hold the role credibly without a team behind them. Osto prepares your evidence and gets you through the review. Where an audit is mandated, it is performed by the accredited or CERT-In empanelled auditor.
Free security assessment
Security leadership without the headcount
Osto runs the testing, monitoring, posture and evidence a security programme needs, in one platform. Your named owner gets a dashboard instead of a second job.
Get a free security assessment Book a platform walkthroughAudit-ready in days · SOC 2, ISO 27001 and DPDP mapped · One platform, everything
Frequently asked questions
What does a CISO do?
A CISO owns information security risk for the organisation. That covers security policy, risk assessment, compliance posture, security operations oversight, incident response, third-party risk and reporting to the board. The role is accountable for outcomes rather than responsible for implementation.
What is the difference between a CISO and a Chief Technology Officer?
The Chief Technology Officer owns technology strategy and delivery. The CISO owns security risk and assurance over that technology. Merging the two creates a conflict, because the same person judges whether their own delivery decisions were safe. Regulators focus on the reporting line for this reason.
Does a startup need a CISO?
Rarely as a full-time hire before scale, but almost always as named accountability. Enterprise security questionnaires and due diligence ask who owns security and how issues escalate. A blank answer stalls deals. Most small teams assign the role internally and support it with a platform and fractional expertise.
Is a CISO legally required in India?
In regulated sectors, yes in substance. The RBI Information Technology Governance Directions require banks and non-banking financial companies in the Middle, Upper and Top Layers to designate a CISO with a defined reporting line, and securities and insurance regulators set comparable expectations. There is no general requirement across all companies.
What is a virtual CISO?
An external, part-time arrangement that supplies the governance and board-facing work of the role without a full-time hire. It fits companies that need credible security leadership for audits and customer reviews but do not yet have the scale to justify the salary. It works only when real platform data sits underneath it.

