21.07.2026
Blog
Cyber Security

Information security: Clear lines of responsibility strengthen cyber resilience

Information security rarely fails due to a lack of awareness alone – it is often unclear lines of responsibility, a lack of coordination and undocumented decisions that exacerbate risks. Particularly against the backdrop of regulatory requirements such as NIS2 and KRITIS, it becomes clear that cyber resilience arises where responsibilities are clearly defined, embedded in operational processes and demonstrably put into practice on a day-to-day basis.

Jannik Schonefeld
Security Consultant

Key Takeaways

  • Information security requires clearly defined roles – not just technology.
  • Senior management bears strategic responsibility.
  • The CISO and ISB translate guidelines into effective measures.
  • Business units must embed security into their processes.
  • Clear lines of responsibility strengthen compliance and cyber resilience.

From a misunderstanding to a security risk

“I thought you were in charge of that?!” Everyone has probably heard this phrase at some point in their working lives. Whilst it may sound harmless at first, it can have serious consequences in the field of information security. This is because unclear lines of responsibility are among the most common reasons why security measures come to nothing, risks are identified too late, or valuable time is lost in an emergency.

Why information security is more than just technology

Information security is still often associated primarily with firewalls, access control or technical security solutions. Yet effective security is not achieved through technology alone. It requires clear structures, well-defined roles and a shared understanding of who is responsible for what. It is during audits, security incidents or in the context of regulatory requirements, at the very latest, that it becomes apparent whether responsibilities are actually being fulfilled or merely described on paper.

Information security is a management responsibility

Regulatory requirements such as NIS2, KRITIS or similar provisions make it clear: information security has long since reached the management level. Management teams and executive boards are responsible to supervisory authorities, customers and business partners for establishing appropriate structures, processes and areas of responsibility. NIS2 explicitly underlines this requirement by holding management bodies more accountable for the adequacy and effectiveness of security measures.

This makes information security a strategic governance task. Senior management must approve security policies, assess trade-offs between security, availability and costs, and decide how to manage risks. A traceable risk analysis is particularly important in this regard: if a risk is consciously accepted, this decision should be transparently justified, reviewed and documented. It is equally crucial that sufficient financial, human and technical resources are made available so that security measures are not only decided upon but can also be effectively implemented.

Operational implementation: roles such as CISO and ISB provide guidance

Although overall responsibility remains at management level, operational implementation is usually delegated to specialised roles. These include, for example, the Chief Information Security Officer (CISO) or the Information Security Officer (ISB). They translate legal requirements, standards and internal requirements into concrete measures and oversee the establishment, operation and further development of the Information Security Management System (ISMS). They are often supported by an information security management team, in which representatives from various departments work together. This fosters cross-departmental dialogue on risks, measures and improvements.

Departments bear responsibility for their own processes

Information security only works if responsibility does not end at a central point. Many security measures originate within the departments themselves. One example is access rights management: when staff move to a different department or leave the organisation, their previous access rights must not remain in place. Human resources, line managers and IT must work together seamlessly to ensure that role changes, training and departure processes are implemented securely.

The same applies to other areas: IT management is responsible for technical security measures such as system hardening, network segmentation and multi-factor authentication. Physical security, for example, is the responsibility of security guards or security services. Procurement and supplier management ensure that service providers and suppliers are selected and assessed on a risk-based basis and monitored throughout the contract period. External dependencies in particular can pose significant risks if information security is not integrated into procurement and contractual processes at an early stage.

It is therefore crucial that responsibilities are not only defined but also clearly assigned to a specific department. Equally important is the ability to provide evidence: departments should be able to demonstrate that assigned measures are being implemented – for example, through documentation, key performance indicators or regular reviews. This makes information security measurable, auditable and resilient in day-to-day operations.

Clear accountability strengthens cyber resilience

Information security is a team effort. Tasks can and should be delegated – but this does not mean that responsibility disappears. Effective security is achieved when senior management, security roles and specialist departments work in tandem: with clear responsibilities, transparent decision-making, robust evidence and a culture in which security is an integral part of day-to-day work. It is precisely this combination of governance, processes and active accountability that forms a central foundation for cyber resilience.

For organisations, this means that by clearly defining responsibilities, clarifying interfaces and regularly reviewing security measures, they do more than just reduce compliance risks. They also lay the groundwork for responding more quickly to security incidents, managing risks more effectively and strengthening trust among customers, partners and regulatory authorities.

 

Further information

Cyber Resilience Management

Jannik Schonefeld
Security Consultant

Jannik Schonefeld ist Security Consultant bei Materna und beschäftigt sich mit den Themen AI Security und Sicherheitsaspekten von Large Language Models (LLMs). Sein Fokus liegt auf der Analyse von Angriffen auf KI-Systeme sowie der Entwicklung von Maßnahmen zur Absicherung dieser Modelle.