TL;DR: I’m an Information Security Manager for a 1,600-employee international organization with a relatively high-risk profile. Our central security team consists of me and two security engineers, despite continued growth through acquisitions, increasing regulatory obligations, and an expanding workload. After months of discussions, management has decided not to increase security headcount. I’m trying to understand where the line is between accepting business risk and accepting personal professional responsibility.
I’m the Information Security Manager for an international organization of around 1,600 employees. We operate across multiple countries in a relatively high-risk industry with a significant amount of business-critical IT.
Our central security function consists of me and two security engineers supporting multiple companies within the group.
We’re a holding company that continues to grow through acquisitions. Newly acquired companies often have security maturity levels that are significantly below the standards expected by the holding company, requiring considerable effort to bring them up to an acceptable baseline.
As the organization has grown, I’ve repeatedly argued that cybersecurity needs to scale accordingly. I developed a proposal for a centralized shared security services organization that would provide governance, security engineering, operational security, and compliance support across the group. As part of that proposal, I also requested an additional Information Security Officer role to strengthen governance and help meet our growing regulatory obligations, including NIS2.
Over the past several months I’ve spent a great deal of time working with senior management to explain why additional security capacity is necessary. Together with external advisors, we’ve explained the operational impact of our growth, our regulatory obligations, and the practical realities of managing security for an organization of this size.
We didn’t stop at high-level discussions. We broke our work down into individual activities, identified the bottlenecks, quantified the backlog, prioritized the work, and demonstrated exactly what can and cannot realistically be delivered with our current team.
The proposal hasn’t been formally rejected, but this week I was informed that there are no plans to invest in additional security headcount in the foreseeable future.
I fully understand that cybersecurity is about managing risk rather than eliminating it. I also understand that every organization has limited budgets and competing priorities.
What I’m struggling with is where my own professional responsibility ends.
At this point, I feel I’ve done everything I reasonably can: documented the risks, presented realistic solutions, involved external experts, communicated the consequences, and made management aware of the growing gap between business growth and our ability to manage cyber risk.
Despite that, there is now more critical work than our team can realistically deliver. As the person ultimately responsible for information security, I’m increasingly uncomfortable carrying accountability for risks that I know we simply don’t have the capacity to address.
I’m not looking to criticize my employer or argue that every security request should automatically be approved. I’m genuinely interested in hearing from other Information Security Managers, CISOs, and security leaders who have faced similar situations.
- At what point do you feel you’ve fulfilled your professional duty?
- How do you distinguish between business risk that management is entitled to accept and professional responsibility that you shouldn’t continue to own?
- Is thorough documentation of risks and management decisions enough, or is there a point where the right professional decision is simply to move on?
I’d genuinely appreciate hearing how others have navigated this.