BOOK A CALL

CISO vs. IT Security Manager: What Changes at Board Level

ciso insights Sep 08, 2026

Many scaling businesses believe they already have security leadership because they have an IT security manager, or an IT manager who has picked up security as part of a broader technical role. It is an understandable assumption, and it is usually wrong, not because the person in that role isn't capable, but because the CISO function and the IT security manager function are not the same job at different levels of seniority. They are different jobs.

What an IT security manager does

An IT security manager is, rightly, focused on operations: keeping systems patched, managing firewalls and endpoint protection, running access provisioning, responding to day-to-day technical alerts. This work is essential, it is also almost entirely inward-facing and tactical. It answers the question "are our systems currently secure", not the question "is our business's security posture acceptable given what we do and who we serve".

What changes when the role becomes a CISO

A CISO operates one level up, and the difference is not seniority for its own sake, it is a difference in what the role is accountable for.

Risk in business terms, not technical terms. An IT security manager reports incidents and system status. A CISO reports risk: what could go wrong, what it would cost the business if it did, and what is being done about it in priority order. That is a commercial judgement, not a technical one.

Strategy and roadmap ownership, not just operations. A CISO sets the direction: where the business's security investment should go over the next twelve to twenty-four months, and why. An IT security manager executes within whatever direction already exists, but rarely owns setting it.

A seat at board reporting, not a summary passed up through someone else. This is the change that matters most in practice. Boards increasingly expect direct visibility into security posture, particularly around funding events, customer procurement, and regulatory exposure. An IT security manager's update, however good, usually arrives filtered through IT leadership, several steps removed from board language and board priorities. A CISO reports risk directly, in the language a board already uses for every other kind of business risk.

External accountability. When a customer's procurement team sends a security questionnaire, or an investor's due diligence team asks pointed questions, they expect answers from someone who owns the strategy, not someone who can describe what the firewall does. A CISO is the credible answer to "who is responsible for this", in a way an IT security manager's title was never designed to be.

Why this distinction matters more as a business scales

At a smaller scale, folding security into an IT manager's remit is a reasonable trade-off, the exposure is limited and the cost of dedicated leadership is hard to justify. That changes as a business grows past roughly £8m in revenue: more customer data, more suppliers, more regulatory surface area, more scrutiny from investors and enterprise buyers. The risk profile changes faster than most businesses update who is accountable for managing it.

The result is a common and costly mismatch: a business whose actual security risk now requires board-level strategic ownership, still being managed at an operational level by someone whose job was never designed to carry that responsibility. It is not a reflection on the IT security manager. It is a structural gap that only a CISO-level role, even a fractional one, is built to close.

What this looks like in practice

Adding CISO-level leadership does not mean replacing the IT security manager, it means adding the layer above them: someone who sets strategy, owns the risk register, reports to the board, and gives the IT security manager clear priorities to execute against, rather than leaving them to set both the strategy and deliver it alone.

For most £2m-£20m businesses, this is exactly the gap a fractional CISO is built to fill, senior enough to own the board relationship, without the cost of a full-time executive seat.

Get actionable advice every Saturday

The CTO’s Playbook

Join 3,267 CEOs, COOs & developers already getting actionable advice, stories, and more.