10+1 tasks every CISO should perform each year
10+1 tasks every CISO should perform each year
The role of the Chief Information Security Officer (CISO) does not end with preparing cybersecurity policies or successfully completing a NIS2 audit. Maintaining an organization’s cybersecurity compliance requires continuous oversight: controls must be operated, risks and vulnerabilities regularly assessed, changes monitored, and time-sensitive obligations fulfilled.
The CISO’s role is primarily to monitor, oversee and coordinate. The CISO does not necessarily perform every technical or operational task, but is responsible for monitoring their proper implementation, identifying deviations and initiating action where necessary.
Below, we have collected 10+1 key tasks that require the CISO’s regular attention throughout the year.
1. Review cybersecurity policies and procedures
An organization’s operations and IT environment are constantly changing, so previously established policies and procedures cannot be considered final. The introduction of a new system, a change of service provider, organizational restructuring, a new site or the outsourcing of a process may all require the related policies and procedures to be updated. Changes in legal and regulatory requirements must also be reflected in the organization’s cybersecurity documentation.
One of the CISO’s primary responsibilities is to regularly verify whether the cybersecurity documentation continues to reflect the organization’s actual operations and applicable requirements. Where necessary, the CISO initiates updates to the relevant policies and procedures.
2. Verify compliance with internal policies
Having appropriate documentation alone does not ensure effective cybersecurity. It is not enough to define a process; it must also operate in practice as prescribed.
The CISO should therefore regularly verify, for example, whether access rights are granted, modified and revoked in accordance with the established process, whether privileged access is properly managed, whether changes are appropriately authorized, and whether external access is provided in line with internal requirements.
Operational execution may be the responsibility of other roles within the organization, but the CISO is responsible for overseeing whether the defined controls actually operate as intended and whether identified deviations are properly addressed.
3. Review cybersecurity risks
The results of a previous risk assessment cannot be considered valid indefinitely. The introduction of a new IT system, supplier, technology or business process, as well as changes in the threat landscape, may create new risks.
The CISO is responsible for ensuring that cybersecurity risks are reviewed regularly, appropriate risk treatment measures are defined and their implementation is monitored. If an action is not completed or the residual risk exceeds the level accepted by the organization, the CISO is responsible for raising the issue and, where necessary, initiating a management decision.
4. Monitor vulnerabilities and their remediation
New vulnerabilities are discovered continuously, so the organization must ensure that it receives timely information about security risks affecting its relevant electronic information systems and system components.
The CISO plays an active role in this process: among other sources, the CISO receives cybersecurity notifications from the National Cyber Security Center (NKI), monitors relevant vulnerability information and ensures that it reaches the appropriate technical owners.
The task does not end with identifying vulnerabilities. Identified issues must be assessed and prioritized, necessary remediation must be implemented, and vulnerabilities that cannot be eliminated require an appropriate risk treatment decision.
The CISO is responsible for overseeing this process and, in particular, ensuring that critical vulnerabilities are not left without appropriate action.
5. Review access rights and permissions
Employees’ roles, responsibilities and access requirements may change over time, while previously granted permissions can easily remain in place. Regular access reviews are therefore an essential security control.
The CISO should verify that the organization performs the required access reviews, properly manages privileged and external access, and revokes permissions that are no longer justified in a timely manner. The CISO is also responsible for ensuring that granted permissions comply with the organization’s information security requirements.
This does not mean that the CISO is responsible for the technical administration of user accounts. The CISO’s responsibility is to verify that the access management process operates according to the established rules and that its execution can be properly demonstrated.
6. Oversee cybersecurity training obligations
Maintaining cybersecurity awareness is an ongoing responsibility. Employees should know, among other things, how to recognize and report security events, how to use access credentials securely and which cybersecurity rules apply to them.
The CISO is responsible for monitoring whether the required training is delivered at the appropriate time and with the appropriate content, whether the relevant employees participate, and whether completion is documented and can subsequently be demonstrated. At the same time, this responsibility goes beyond simply fulfilling training requirements: the objective is to continuously improve security awareness throughout the organization and strengthen a culture that supports secure operations.
The CISO must also keep their own professional knowledge up to date and fulfil the continuing training requirements associated with the role.
7. Verify the operation of the incident management process
An incident management procedure serves its purpose only if it also works effectively during an actual security event. The CISO should therefore regularly verify that employees know where and how to report security events, reports reach the appropriate person, events are assessed, and incident handling begins in time where necessary.
It is particularly important to establish an effective process for identifying and escalating significant incidents. Where a regulatory reporting obligation arises, the CISO is responsible for ensuring that the required notifications are submitted within the legally defined deadlines and with the required content.
Who oversees CISO responsibilities in your organization? Discover our outsourced CISO service and entrust the continuous monitoring of your cybersecurity responsibilities to experienced professionals. OUTSOURCED CISO SERVICE → |
8. Maintain communication with cybersecurity authorities
The CISO’s role in communicating with cybersecurity authorities is not limited to incidents. Regulatory requests, data submissions, changes to registered information or regulatory inspections may also require the CISO’s involvement.
The CISO should monitor the cybersecurity obligations applicable to the organization, coordinate the necessary professional responses and ensure that notifications and data submissions falling within the CISO’s responsibilities are completed properly and on time.
Simply appointing a regulatory contact person is not sufficient. The necessary information, responsibilities and internal communication channels should also be defined in advance.
9. Monitor deficiencies and corrective actions
Audits, GAP analyses, risk assessments, vulnerability assessments, incidents and internal reviews may all result in actions that need to be addressed.
Effective follow-up requires a clear owner and deadline for each action, followed by verification of implementation and the supporting evidence.
The CISO’s coordination and oversight role is particularly important in this area. An action should not be considered closed simply because its deadline has passed or the responsible person has marked it as completed. It should also be verified that the required control has actually been implemented, operates effectively and can be demonstrated.
If an action is delayed or is not implemented properly, the CISO is responsible for raising the issue and, where necessary, escalating it to management.
10. Regularly inform management
Some cybersecurity risks cannot be managed solely at CISO or IT level. Issues requiring additional resources, investment, organizational changes or risk acceptance decisions require management involvement.
The CISO should therefore regularly inform management about the organization’s cybersecurity status, significant risks, incidents, critical vulnerabilities, outstanding actions and compliance issues.
The CISO’s responsibility does not end with identifying a problem. Where its resolution exceeds the CISO’s authority, the issue must be escalated to the appropriate decision-making level.
+1. Know about everything!
The CISO can only monitor and oversee what they know about. Ensuring an effective flow of information is therefore just as important as regularly reviewing individual security controls.
Internal processes should be designed to ensure that the CISO is informed in a timely manner about any change, event or decision that may affect cybersecurity.
This may include, for example, when:
- a new electronic information system or application is introduced;
- the operation or infrastructure of an existing system changes significantly;
- someone is granted privileged access;
- a user’s or role’s access rights change significantly;
- a new external service provider or supplier is granted access to the organization’s systems or data;
- a critical vulnerability or other significant security weakness is identified;
- a cybersecurity event or incident occurs;
- a new technology or IT service is introduced;
- a required security measure is not implemented or is not completed by the specified deadline;
- an organizational, technological or supplier-related change occurs that may affect the security of an electronic information system.
This does not mean that the CISO must approve every IT or business decision. However, the organization must ensure that the information necessary for the CISO to perform their responsibilities reaches them in time.
This is particularly important for an outsourced CISO. Periodic meetings alone are not sufficient if a change occurs between meetings that requires immediate assessment or action.
Organizations should therefore define in their internal policies and processes which events must be reported to the CISO, by whom, through which channel and within what timeframe.
The CISO’s responsibility must be accompanied by appropriate visibility. To effectively oversee the organization’s cybersecurity operations, the CISO needs to know about every event and change that may have a material impact on them.
The CISO does not do everything – but is responsible for ensuring that the necessary tasks are completed
Meeting cybersecurity requirements requires cooperation between several areas of the organization. The system administrator may install security updates, HR may initiate the offboarding process, a manager may approve access, an external specialist may perform a vulnerability assessment, and IT may handle and restore systems affected by an incident.
The CISO’s role is different.
The CISO is responsible for continuously monitoring and overseeing whether defined cybersecurity processes operate properly, controls are implemented, deviations are addressed, necessary actions are completed on time, and all of this is properly documented and auditable where required.
The CISO does not have to perform every task personally, but must ensure that the necessary tasks are not left undone.
To fulfil this responsibility, the CISO also needs appropriate authority, access to information and cooperation across the organization.
Preparation for the next audit starts when the previous audit ends
NIS2 compliance does not end with a successful cybersecurity audit. Established controls must continue to operate, be regularly performed, reviewed and documented, and adapted to organizational and technological changes.
The CISO is responsible for overseeing this process between audit cycles.
If this does not happen, a significant backlog can accumulate before the next audit: overdue reviews, expired action items, undocumented controls, outdated risk assessments or recurring activities that cannot be demonstrated.
Preparation for the next audit therefore does not begin a few months before the auditor arrives. It starts as soon as the previous audit is completed.
Do you need an outsourced CISO? Discover our service and ensure the continuous fulfilment of your CISO responsibilities. OUTSOURCED CISO SERVICE → |
| Related NIS2 Services | ||||
NIS2 Audit Correction Based on the audit report, we identify and prioritize the necessary corrective actions and support their implementation to help your organization achieve compliance. Learn more → | FEATURED SERVICE Outsourced Chief Information Security Officer (CISO) Experienced information security expertise to support continuous NIS2 compliance and preparation for the next audit cycle. Learn more → | NIS2 Preparation Assessment, GAP analysis, action planning, and expert support for structured implementation of NIS2 requirements and successful audit preparation. Learn more → | ||


