Cyber Insights · Episode 16

Do You Need a CISO, or Do You Need Security Leadership?

Ronan Murray & Ian Finlayson
· 31 min
  • Why NIS2 and DORA have changed who is accountable for cybersecurity
  • How a vCISO differs from a full-time CISO, and when the model makes sense
  • What a cybersecurity risk register looks like and why boards need to see it

Prefer your own app? Spotify · Apple Podcasts

About this episode

NIS2 and DORA have changed who is accountable for cybersecurity. Boards are asking questions and regulators want evidence. Hiring a full-time CISO is one answer, but it is not the only one.

Ronan Murray and Ian Finlayson look at the vCISO model: what it involves, how it differs from a full-time CISO, and why it has become a practical route for organisations facing board-level accountability without a dedicated security executive. Ian explains how a vCISO embeds as part of the organisation rather than sitting outside it as a consultant, and why that matters for governance and incident response.

The key thing here is to get the action and momentum underway. If you don't, you're actually moving nowhere.
Ian Finlayson

In this episode

  • Why NIS2 and DORA have changed who is accountable for cybersecurity
  • How a vCISO differs from a full-time CISO, and when the model makes sense
  • What a cybersecurity risk register looks like and why boards need to see it
  • How a maturity gap analysis shows where to focus first
  • Why momentum matters more than perfection when building a security programme
  • What the vCISO does when a cyber incident hits

Highlights

  • The best time to start preparing for NIS2 was three, four years ago. The second best time is now.

    Ronan Murray
  • While they're not a full-time staff member, they're also not just an external consultant. And it's that identity that's very important.

    Ian Finlayson
  • Everyone is on that journey, but everyone also started at the same place. There's no need for anyone to be embarrassed if the maturity level is low.

    Ian Finlayson
  • Helping the business is key, as opposed to going in and auditing the business and judging the business.

    Ronan Murray
Want to see where your gaps are?
Security Posture Review · Assessment
See the Security Posture Review
Ian Finlayson

Got a question about vCISO and security leadership?

Talk to Ian. Ian Finlayson, Chief Security Services Officer at Edge7 Networks, is happy to talk through what this looks like for your environment.

ISO 27001:2022 · ISO 9001:2015 · Cyber Essentials · Networking and security specialists since 2018