Home · Blog
Basics

When does an SME need a CISO? Four triggers from practice

11 September 2026 · 7 min read · ODCUS
Meeting table with a customer security questionnaire and an empty chair at the head, standing for security decisions without an owner in an SME

The question almost never comes from IT. It comes from sales: an important customer sends a security questionnaire, due back in two weeks, and nobody in the building knows who is allowed to sign it. When an SME needs a CISO is decided exactly there. Not by headcount, but by the moment security decisions start arriving regularly with no owner attached.

TLDR

Headcount says little about whether an SME needs a CISO role. The trigger is decisions without an owner: the first serious customer audit, a contract clause with a reporting deadline, an incident that stops operations, a question from the board that nobody answers. Once such decisions repeatedly land with someone who is not allowed to make them, the moment has arrived. A full-time position does not automatically follow.

Why headcount is the worst indicator

The common rule of thumb hangs the need on headcount: a few hundred people, so you need someone for security. Convenient, and close to worthless in practice.

A software firm with 80 people processing data for insurers makes decisions with contractual consequences every month. A manufacturer with 400 people and a regional customer base perhaps makes two a year. In the SME bracket both sit in the same column. Their realities have little to do with each other.

Something else drives the need: who you supply, what data you hold, how much revenue depends on contracts with security written into them. A supplier delivering to banks, hospitals, pharma or public sector buyers inherits their requirements through the contract, regardless of its own size. Anyone supplying only to SMEs without a security organisation of their own inherits nothing and has time.

Most companies that call us do not have a security problem. They have a sizing problem: too many tools, too little overview, too much cost for too little real protection. Which is why in many mandates the licence budget falls first, before anything new is added anywhere.

When does an SME need a CISO?

An SME needs a CISO role as soon as security decisions keep arriving that nobody in the building is allowed or willing to make. In our experience four triggers make this visible. None of them is technical, and none has anything to do with the number of desks.

1. The first serious customer audit. This means the session where somebody walks through your processes with an auditor's eye and wants to see evidence, not the questionnaire purchasing sends out pro forma. A session like that needs a person who is allowed to answer in the room, without making a phone call after every second question. Anyone who looks lost there usually does not lose the audit, but the negotiating position for the next contract round.

2. The contract clause with a deadline. As soon as a customer writes reporting obligations into the contract, security moves out of IT and into the contractual world. In Switzerland the ISG (Informationssicherheitsgesetz, the federal information security act) sets the direction: since 1 April 2025 operators of critical infrastructure report cyberattacks to BACS, the federal cybersecurity office, within 24 hours of discovery (BACS information on the reporting obligation). Deadlines like this get passed down through supply contracts. And a 24-hour deadline then needs someone who decides on a Saturday evening whether to report.

3. The incident that stops operations. An encrypted file server is an IT problem. A stopped production line, waiting customers and an open question about paying a ransom are not. Those hours need someone who is allowed to shut systems down and set priorities. Anyone still looking for that person during the crisis has long since answered the question of timing.

4. The question from the board that stays unanswered. It usually sounds like "are we secure enough" and means "am I carrying a risk here that I do not know about". A list of open tickets does not answer that. What holds up is a short, honest assessment of which risks are being accepted on purpose and which are not. What such an assessment looks like is described in security KPI reporting for management and the board.

Four triggers for a CISO role in an SME: customer audit, contract clause with a reporting deadline, an incident that stops operations and an open question from the board
Four triggers that decide the timing in practice. None of them is a headcount.

One of these triggers on its own is not yet a mandate. If two of them occur within a year, the role already exists. It is simply unfilled, and somebody is carrying it on the side.

What this looks like in a Swiss SME

A supplier in eastern Switzerland, around 180 employees, two plants, customers in medical technology. Four people in IT, the IT manager nine years in the company and technically strong. What set it off was the renewal of a framework agreement: the largest customer required evidence of a working information security management system and a reporting deadline of 24 hours.

The IT manager filled in the questionnaire and had to guess in three places. Who decides whether an incident is reportable? Who is allowed to take a system off the network when that stops a production line? And who carries the risks that are deliberately left in place because the money does more elsewhere? None of these are IT questions. He had them on his desk anyway, because nobody else did.

What was missing there was not technology. The estate was rather too large: two tools with overlapping functionality, plus a licence for a product nobody had opened since the pilot. What was added was leadership. A monthly steering meeting with management and IT, a risk register in which every risk carries a name as its owner, and a person who speaks in the audit walkthrough. The IT manager stayed the IT manager. He simply no longer had to make decisions that were never his to make.

What does postponing the decision cost?

Rarely money on an invoice, mostly time and negotiating position. An unprepared customer audit ties up several weeks across IT and sales. A clause signed without anyone checking whether it can be met becomes expensive at the first disruption. Contracts for tools nobody steers renew quietly for another year.

The alternative has a price too, and it is a known one. A full-time CISO in Switzerland costs between CHF 150'000 and 250'000 per year (salary data from jobs.ch), plus social contributions and several months of searching during which the role sits empty. A mandate starts at CHF 4'900 per month with a minimum term of six months, the packages are listed under pricing and packages. The full calculation, including the costs that appear in no salary band, is laid out in what does a CISO cost in Switzerland.

Both numbers hide the same point. An SME of this size has been spending money on security for a long time already, spread across licences, service providers and projects, only without anyone steering it. The first job of security leadership is therefore usually to point that existing budget at the risks that can stop the business.

When it is genuinely too early

This case exists, and it is more common than a provider might like. A company with 60 employees, customers without a security organisation of their own, no regulated industry, no clauses in the contract: that company does not need a CISO role. What holds up in firms like that is a minimum that gets by on a few hours a year and still settles the accountability question.

That is not a security organisation. It does hold until the first of the four triggers occurs, and it prevents the most common way this fails: that security belongs to nobody and therefore only belongs to somebody once something has happened. The answer to "do we need a CISO now" in such cases is: not yet.

Does it have to be a full-time position?

For most SMEs between 50 and 500 employees, no. The need is unevenly spread. The first months take a lot of time for taking stock, clearing up and the first decisions, after which it settles into a rhythm that a few days a month can cover. That curve fits a permanent hire badly.

There is also a recruiting problem. Experienced security leadership is reluctant to join a company where the role is new, the budget small and the room for manoeuvre undefined. Anyone who searches anyway usually finds someone from the technical side who still has to learn the leadership work. That can turn out well. It then takes two years instead of three months, and the first customer audit does not wait that long.

Common questions

We have never had a security incident. Does that argue against a CISO role?

It says something about the past above all. Many SMEs get through years without structured security work because they were never in an attacker's focus. The more useful question is whether you would notice and classify an incident at all. Anyone who cannot answer that with confidence does not have a good track record, but a thin set of data.

Who should the role report to, IT or management?

Management. Security regularly means setting priorities against day-to-day operations, and whoever reports into operations loses that discussion structurally. This is about the reporting line, not about the quality of IT. The technical collaboration stays untouched and is the larger part of the work anyway.

When is it too late to fill the role?

It never gets too late, only more expensive. Filling the role during a running audit or in the middle of an incident means paying for speed and starting in a situation that leaves little time for fundamentals. The difference between "we have this sorted" and "we are sorting this right now" is obvious to customers and auditors immediately.

If you recognised two of the four triggers while reading, the role already exists in your company. The only open question is who carries it, and whether that is someone allowed to carry it.

Not sure whether a fractional CISO fits your company?

In a free intro call we work out whether senior security leadership on a mandate makes sense for your company, and in what form. Honest answer included, even when it is "not yet".

Book a free intro call