Hardening · 10 July 2026 · 4 min read
Who owns security? The governance minimum for a small company
Without a "who", every measure belongs to nobody. How to name an owner, what leadership discusses once a quarter, and the three written rules to start with.
ClearSecurity Vision
You can have MFA, backups and antivirus — if nobody owns them, they quietly decay: the licence expires, the “temporary” exception stays, the new hire never gets the training. Security isn’t a project that ends; it’s a responsibility that needs a person’s name attached.
“Governance” sounds corporate, but in a small company it means three simple things: an owner, a leadership habit, and a few written rules. This guide sets them up in a week, without bureaucracy.
What you need
- A leadership decision that security gets a “who” — with allocated time, not just a title
- One recurring hour per quarter in leadership’s calendar, starting now
- A place where the written rules are accessible to everyone (intranet, shared folder)
Step 1: name the owner
- Pick one person — usually someone from IT or operations, with real power to ask for changes. Part-time is fine; what matters is that it’s one person, named officially, not “we all handle it”.
- Write their mandate briefly: keep track of the measures (inventory, backups, updates, access), flag risks to leadership, coordinate incident response.
- Tell the company: one email from leadership — “X owns security; any suspicion or question goes to them”. Visibility is half the job.
- If the expertise is missing internally, the role can be supported from outside (a consultant, a few hours a month) — but the internal interface stays a person in the company.
Step 2: leadership’s quarterly hour
Security discussed only after incidents is always expensive. Once a quarter, one hour, with a fixed four-question agenda:
- What happened? Incidents, attempts, false alarms — including the small ones, which reveal patterns.
- Where are we exposed? The owner brings 2-3 concrete risks, in business language (“if X leaves, nobody knows the passwords to…”), not jargon.
- What did we promise last time, and what got done? The short list, with status. This is where you see whether governance works.
- What do we decide now? Every decision gets an owner and a deadline. A decision without a deadline is an opinion.
Minutes: half a page, kept. A year in, you have history — and evidence, if anyone asks for it.
Step 3: the first three written rules
You don’t need 20 documents. Three short rules, written in plain language, cover most situations:
- The access and password rule: unique long passwords, a password manager, MFA where available, who approves new access and who closes it on departure — the MFA guide is a natural annex.
- The equipment rule: what’s allowed on work devices, mandatory laptop encryption, automatic updates, what to do if a device is lost.
- The reporting rule: anything suspicious gets reported to the owner immediately, no blame — tied directly to the one-page response plan.
Write them starting from what you already do and want to make official — not from an ideal template nobody will follow. One page per rule is enough; review yearly or on big changes.
Verify the result
- Ask three employees at random: “who owns security here?” and “what do you do if you get a dodgy email?”. If they answer without thinking, governance exists.
- At the second quarterly meeting, look at the decision list from the first: how many got done? Under half = the agenda is theatre, not leadership.
Common mistakes
- An owner with a title but no time. If the role sits “on top of” an already full job, it loses every prioritisation contest. Allocate explicit hours.
- Policies copied off the internet. 30 pages of corporate template nobody has read do more harm than their absence: they create the illusion of coverage.
- The meeting that drifts into tech. Leadership decides about risks and money, not firewall versions. The owner translates.
- Everything depending on one person. The owner takes holidays and resigns like anyone else — the written rules and the meeting history are exactly the safety net for that.
Under NIS2? Then what you’ve just read is the core requirement itself: the law places responsibility for security measures explicitly on leadership, with personal sanctions — and the owner, the meetings and the written rules are that responsibility in concrete form.
One step done. See the full picture.
Answer a few questions across the 8 essential areas — from passwords and backups to suppliers — and get a report by email with your weak spots and next steps.
Start the self-assessment →
newsletter
Get new articles by email.
NIS2 compliance, incident reporting and plain-language security — only when we publish something new. No spam, unsubscribe anytime.