ClearSecurity VISION
EN / RO
← All articles

Hardening · 10 July 2026 · 4 min read

Who owns security? The governance minimum for a small company

Without a "who", every measure belongs to nobody. How to name an owner, what leadership discusses once a quarter, and the three written rules to start with.

ClearSecurity Vision

You can have MFA, backups and antivirus — if nobody owns them, they quietly decay: the licence expires, the “temporary” exception stays, the new hire never gets the training. Security isn’t a project that ends; it’s a responsibility that needs a person’s name attached.

“Governance” sounds corporate, but in a small company it means three simple things: an owner, a leadership habit, and a few written rules. This guide sets them up in a week, without bureaucracy.

What you need

  • A leadership decision that security gets a “who” — with allocated time, not just a title
  • One recurring hour per quarter in leadership’s calendar, starting now
  • A place where the written rules are accessible to everyone (intranet, shared folder)

Step 1: name the owner

  1. Pick one person — usually someone from IT or operations, with real power to ask for changes. Part-time is fine; what matters is that it’s one person, named officially, not “we all handle it”.
  2. Write their mandate briefly: keep track of the measures (inventory, backups, updates, access), flag risks to leadership, coordinate incident response.
  3. Tell the company: one email from leadership — “X owns security; any suspicion or question goes to them”. Visibility is half the job.
  4. If the expertise is missing internally, the role can be supported from outside (a consultant, a few hours a month) — but the internal interface stays a person in the company.

Step 2: leadership’s quarterly hour

Security discussed only after incidents is always expensive. Once a quarter, one hour, with a fixed four-question agenda:

  1. What happened? Incidents, attempts, false alarms — including the small ones, which reveal patterns.
  2. Where are we exposed? The owner brings 2-3 concrete risks, in business language (“if X leaves, nobody knows the passwords to…”), not jargon.
  3. What did we promise last time, and what got done? The short list, with status. This is where you see whether governance works.
  4. What do we decide now? Every decision gets an owner and a deadline. A decision without a deadline is an opinion.

Minutes: half a page, kept. A year in, you have history — and evidence, if anyone asks for it.

Step 3: the first three written rules

You don’t need 20 documents. Three short rules, written in plain language, cover most situations:

  1. The access and password rule: unique long passwords, a password manager, MFA where available, who approves new access and who closes it on departure — the MFA guide is a natural annex.
  2. The equipment rule: what’s allowed on work devices, mandatory laptop encryption, automatic updates, what to do if a device is lost.
  3. The reporting rule: anything suspicious gets reported to the owner immediately, no blame — tied directly to the one-page response plan.

Write them starting from what you already do and want to make official — not from an ideal template nobody will follow. One page per rule is enough; review yearly or on big changes.

Verify the result

  • Ask three employees at random: “who owns security here?” and “what do you do if you get a dodgy email?”. If they answer without thinking, governance exists.
  • At the second quarterly meeting, look at the decision list from the first: how many got done? Under half = the agenda is theatre, not leadership.

Common mistakes

  • An owner with a title but no time. If the role sits “on top of” an already full job, it loses every prioritisation contest. Allocate explicit hours.
  • Policies copied off the internet. 30 pages of corporate template nobody has read do more harm than their absence: they create the illusion of coverage.
  • The meeting that drifts into tech. Leadership decides about risks and money, not firewall versions. The owner translates.
  • Everything depending on one person. The owner takes holidays and resigns like anyone else — the written rules and the meeting history are exactly the safety net for that.

Under NIS2? Then what you’ve just read is the core requirement itself: the law places responsibility for security measures explicitly on leadership, with personal sanctions — and the owner, the meetings and the written rules are that responsibility in concrete form.

newsletter

Get new articles by email.

NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.