The offer is in your inbox. Title: Chief Information Security Officer. Team: you. The company has 180 people, two enterprise customers sending questionnaires nobody can answer, an IT manager who has been doing security on the side because no one else would, and a CEO who sounds sincere about it being a priority. The salary is a step up. The title is three steps up. You have read the job description four times looking for what is wrong with it.
Nothing in it is wrong. That is the difficulty. Everything that will go wrong is governed by facts the description does not contain.
A one-man CISO role is worth taking when the structure hands you authority and cover in rough proportion to the accountability, and it is a career liability when it does not. The title is not the risk. The risk is being the named person for outcomes you cannot unilaterally control. Four conditions decide which version of the job you are being offered, and all four are knowable in the interview if you ask directly.
The asymmetry you are being asked to absorb
Every security role carries accountability for things other people do. A solo role concentrates it. No deputy, no peer director whose budget overlaps yours, no team whose existence proves the company meant it. Whether engineering patches what you flagged, whether finance approves the spend, whether the CTO delays a launch you called unsafe: you control none of it. You control your advice, your evidence, and the record of what you asked for.
That gap is not automatically unfair. Every executive carries some of it. It turns unfair at one point: when you are named as responsible in contracts, insurance applications, customer attestations and filings, while the people whose decisions determine the outcome can decline you without writing anything down. Naming plus deniability is what ends careers.
The most widely used framework in the field agrees with you about where accountability sits. NIST’s Cybersecurity Framework 2.0 added GOVERN as a function in February 2024, and GV.RR-01 reads: “Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical, and continually improving.” The next subcategory asks that roles and authorities be “established, communicated, understood, and enforced.” A company that quotes CSF 2.0 in its sales deck and still thinks hiring one person transfers accountability has not read it.
Four questions that decide whether a solo security role is survivable
1. Who do you report to, and can that person fund a decision alone? Reporting into a CTO or VP Engineering puts your findings in direct competition with the delivery schedule of the person who owns both. Delivery wins, because that is what they are measured on. Not malice, incentive. A COO, CFO, general counsel or CEO separates the two. Sharper version: can your manager approve a five-figure unbudgeted spend inside a week? If they have to go up two levels, so do you.
2. Is there a written risk acceptance mechanism, and has anyone used it? Ask to see a redacted example. If acceptance exists only as a concept, every risk you raise and cannot fix stays open and attributed to you by default. On paper but never signed is the same as absent. The follow-up that gets the real answer: “When someone decides not to fix something I raise, where is that recorded, and whose name goes on it?” Watch for the pause.
3. Do you have budget authority or only budget requests? Large difference between “we’ll support you on tooling” and a line in the approved plan with your name as owner. Ask for the number, whether the line exists now or next cycle, and what your signing limit is. A solo CISO with no independent spend cannot buy a penetration test without a negotiation, so the test happens when somebody else feels like it.
4. Can you stop a release? The authority question stripped of politeness. Ask plainly: “If I assess that something is not safe to ship, what happens?” A good answer is a defined escalation: you pause, the CTO can override, the override is recorded and goes to the CEO or the board. You do not need a veto. You need a path where overriding you costs someone else something. “We’d talk it through and reach a decision together” means you can be talked past by whoever talks longest.
Two clean yeses and two soft answers is a negotiation. Four soft answers is a different job from the one advertised.
Being the named person: what has actually changed
General information, not legal advice. Whether any of it touches you personally depends on jurisdiction, company type and sector, and facts nobody can assess from a job description. If the role is senior and the company regulated, pay a lawyer for an hour before you sign. Cheapest item in this article.
What has verifiably changed is that regulators now write rules attaching to a named individual rather than to an abstraction called “the company.” The plainest case is the FTC’s Safeguards Rule. At 16 CFR 314.4(a) it requires a covered financial institution to “designate a qualified individual responsible for overseeing and implementing your information security program and enforcing your information security program.” Paragraph (i) makes that person report in writing, at least annually, to the board or equivalent body on programme status and on material matters including risk management and control decisions, service provider arrangements, testing results and security events. The same rule says the institution retains responsibility for compliance and must designate a senior manager to oversee that individual. Use it as your template even where it does not apply to you: a named individual, a written channel to the governing body, and a senior manager above them who owns the outcome. If the other two are missing, ask why.
If the company is public or heading that way, you sit inside its disclosure process. The SEC adopted rules on 26 July 2023 requiring Form 8-K Item 1.05 disclosure of material cybersecurity incidents, generally within four business days of the registrant determining an incident is material. Regulation S-K Item 106 requires annual description of the processes for assessing and managing material cybersecurity risks, plus “the board of directors’ oversight of risks from cybersecurity threats and management’s role and expertise in assessing and managing material risks”, applying from fiscal years ending on or after 15 December 2023. That makes you a contributor to a filed document, and turns materiality into a legal process on a clock rather than a call you make alone.
On personal exposure, two facts rather than a prediction. In October 2023 the SEC charged SolarWinds Corporation and its Chief Information Security Officer, Timothy G. Brown, with fraud and internal control failures, alleging they “engaged in a campaign to paint a false picture of the company’s cyber controls environment.” Those were allegations in a contested civil action, not findings of liability, and how it ends is not the point. A sitting CISO was individually named over statements about security posture.
The FTC’s Drizly matter is more concrete, because it is a final order binding an individual. Issued October 2022 and finalised January 2023, it follows the individual respondent, then the company’s CEO, for ten years, to any other business collecting data from 25,000 or more consumers where he is majority owner or is “employed or functions as a Chief Executive Officer or other senior officer with direct or indirect responsibility for information security.” He files compliance reports and tells the FTC when his role in any business changes. An enforceable personal obligation, written to attach to a senior officer responsible for information security, at companies not yet identified, years ahead. Nobody in that matter was a solo CISO, but if you are about to be the only person at a company holding that responsibility, you are the shape such a clause is cut around. Not a reason to refuse the job. A reason to stop treating the title as free.
What to negotiate before you sign
Do this while you have leverage, which is now; after you accept, each item becomes a favour you are asking for. None of it reads as hostile framed as programme design rather than self-protection, and a company that reacts badly to a candidate arriving with a charter has answered question four for free.
- A written charter, one page. What you decide alone, what you recommend, what needs approval above you and from whom, plus the escalation path for a disagreement with engineering. Attach it to the offer letter. A charter nobody signs is a wish.
- A documented risk acceptance process with named approvers. Not a promise to create one. A form, an owner field, a review date, and a rule that acceptance sits with a business owner rather than with security. This is what converts “the CISO knew and did nothing” into “the executive owner accepted this in writing on a stated date.”
- Directors and officers coverage, or equivalent protection. Ask whether the D&O policy covers officers in your role, in writing, from someone who has read it. Ask about indemnification in the employment agreement, whether it survives your departure, and whether defence costs are advanced as incurred. “We’re a startup, we don’t have D&O” is a common and honest answer, and it should move your compensation number.
- An explicit statement of what you are and are not responsible for. Name what is out: physical security, fraud, IT helpdesk, product security engineering, privacy compliance. Ambiguity always resolves toward more scope for the solo person, because there is nobody else for it to land on.
- A budget line, not a promise. A number, in the plan, with your name against it, plus a signing limit. “We’ll figure it out as we go” is a real answer and it means no.
- The title itself. If the four conditions come back weak, consider asking for Head of Security at the same salary: same scope, same money, without a named-officer label at a company that has not built what a named officer needs. Some will find that trade obviously wrong because they want CISO on the CV. Make it a decision rather than a default.
What the job is really like with no security team
You will do very little technical security work. The week fills with programme building: policies that did not exist, a risk assessment nobody asked for, chasing an asset inventory. Then vendor management, because you cannot build anything yourself and every capability arrives as a contract you have to scope, price and defend. Then evidence collection, which is the part that surprises people. At a company selling to enterprises, a large share of the role is security questionnaires, test reports for buyers, insurance renewal applications and audit preparation. It is sales support with a security job title. The rest is influence without staff: persuading an engineering lead to prioritise work that helps nobody’s roadmap, and saying the awkward sentence in the meeting while staying someone people want in the meeting.
Plenty of people love that, and you do see the whole business in a way no enterprise role offers. Others take the job, end up in procurement and spreadsheets instead of the detection engineering they are good at, and are miserable by month five. The role will not reshape itself to suit you. One test: when did you last enjoy writing a document that made somebody else do something? If the answer is never, this is not your job, whatever the title says.
How to make a one-man security function survivable
Adopt a published framework as your backbone on day one. Not because frameworks are magic, but because they make your priorities defensible by somebody else’s authority rather than your opinion. CISA’s Cross-Sector Cybersecurity Performance Goals are the most usable free starting point for a small or mid-sized company: practices with known risk-reduction value, chosen through industry, government and expert consultation, written to “help small- and medium-sized organizations kickstart their cybersecurity efforts”, and described by CISA just as plainly as “not comprehensive.” That stated incompleteness is a feature for you, because a bounded list is something you can be measured against. NIST CSF 2.0 is the heavier option and the right one when customers or regulators expect it; its GOVERN function supplies language for what you cannot fix personally, including risk appetite and tolerance statements (GV.RM-02) and a standardised method for prioritising risks (GV.RM-06).
Buy the hours you cannot personally cover. One person, one sleep schedule. Round-the-clock monitoring, triage at 3am and periodic offensive testing are not things a solo hire delivers by working harder, and pretending otherwise is how the first real incident becomes your fault. Managed detection, a retained incident response provider and scheduled independent testing turn an impossible commitment into a contract with somebody else’s name on it. Raise it before you accept, not after.
Scope ruthlessly, and publish what you dropped. Pick three outcomes for the year. Write down what you are not doing and why, send it to your manager, get it acknowledged. An unpublished decision to defer something looks identical to negligence afterwards. A published one is a prioritisation call your manager saw.
Document every risk as you raise it. One register, one line per risk, business consequence in plain language, a named owner who is not you, the decision, the date. Email a monthly summary to your manager and keep it. Not paranoia and not adversarial: it is the discipline the Safeguards Rule expects of a qualified individual reporting to a board, and the only thing that helps if the story later becomes “nobody told us.”
What the role does to your career, both ways
If it goes well, this is one of the fastest CV upgrades in security. Built a programme from nothing, ran vendor selection and a budget, presented to executives and probably a board, carried an audit through to a clean report, handled an incident. That set is rare, it reads as seniority, and it is what the next company hiring its second or third security leader wants.
If there is a serious breach, the picture is less bleak than folklore suggests. Security leaders survive breaches routinely, and the profession understands that being breached is not proof of incompetence. What decides whether you come out intact is the record: did you identify the risk beforehand, did you propose a treatment, did somebody else decline it in writing, was your response competent. A dated register and a signed acceptance keep you employable. A year of undocumented verbal warnings is a story nobody can verify.
The worst outcome is neither. It is the quiet one: two years at a company that never funded the programme, where you fought for tooling you never got and this year’s report says what last year’s said. Nothing to point at in an interview. “They wouldn’t fund anything” is true, sounds like an excuse, and cannot be proved. The observation candidates need most and want least is this one: a solo security role at a company that will not resource it damages your career more than not taking it. Turning it down costs one opportunity. Taking it costs two years and leaves you explaining a hole in your evidence.
The decision rule, and the answers that should end the interview
Take it if three of the four conditions are solid and the fourth is being fixed with a date attached, if there is a budget line rather than goodwill, and if you genuinely want a programme and governance job. Negotiate hard and then decide if the conditions are mixed but the reporting line is right and your manager can spend money: those two are hardest to change later, and most of the rest can be built in ninety days once they are in place.
Walk away on any of these, and people say all of them out loud:
- “We need someone to own security so the leadership team doesn’t have to worry about it.” Accountability transfer, offered as a benefit.
- “Budget? Bring us a business case and we’ll look at it.” No line, no authority, and you pitch from zero every time.
- “You’d report to the VP of Engineering but you’d have complete independence.” The second half does not survive the first quarter.
- “We’ve never formally accepted a risk, we just use judgment.” Every open risk defaults to you.
- “The last person left after about eight months.” Ask why. A vague answer, or two turnovers in the role, means the structure is the problem and you are next to find out.
- “We mostly need the certification for a customer deal by March.” Fine as a project, dangerous as a role. Ask what the job is in month thirteen.
- Anyone who cannot say who signs the cyber insurance application, or what it currently attests to.
Watch for the opposite signal too, because the good version of this job exists and is easy to miss. A CEO who says “we know this is underfunded, here is the number we have set aside, and here is what we want in eighteen months” is offering something better than a larger company with a nicer title. Underfunded and honest is workable. Well-resourced and evasive is not.
You are not deciding whether you are good enough for the title. You are deciding whether the company has built a role a competent person can succeed in. Interview nerves push candidates toward the first question when the second decides the next two years.
If you do take it, the day-one problem is the same for everybody: you cannot be the security operations centre, the testing function and the compliance evidence machine at once. That is the gap AB7 Solutions fills. We run SOC monitoring and out-of-hours detection cover, so the 3am alert has a name on it that is not yours; we do VAPT and penetration testing alongside firewall and server security work, which produces the independent test reports customer security reviews and insurance renewals keep demanding; and we do security recruitment and contract staffing for the point where the answer is a second pair of hands rather than another tool. Send us the scope you have been handed and we will say which parts are worth buying and which you should keep, including the cases where the honest answer is one analyst and a tighter alert set, not a managed service. Call +1 321 341 7733, email ab@ab7solutions.com or director@ab7solutions.com, or start at www.ab7solutions.com.
Sources: NIST, Cybersecurity Framework 2.0 (NIST CSWP 29, 26 February 2024), subcategories GV.RR-01, GV.RR-02, GV.RM-02 and GV.RM-06; CISA, Cross-Sector Cybersecurity Performance Goals; US Securities and Exchange Commission, final rules on cybersecurity risk management, strategy, governance and incident disclosure (26 July 2023) and SEC charges SolarWinds and CISO Timothy G. Brown (30 October 2023; allegations in a contested action); Federal Trade Commission, In the Matter of Drizly, LLC and James Cory Rellas, decision and order (October 2022, final January 2023); 16 CFR 314.4, FTC Safeguards Rule, paragraphs (a) and (i).