CISO: role, responsibilities and tools

Definition, responsibilities, reporting line, salary, fractional CISOs and legal requirements: what you need to know about the head of information security.

· 12 min read
Illustration: a glass silhouette bearing an orange shield

The CISO, or Chief Information Security Officer, is the person who defines and steers an organisation's cybersecurity. They assess risks, set security rules, check compliance with frameworks (ISO 27001, NIS 2, GDPR) and prepare the response to incidents. They advise senior management, which keeps the decision and the accountability.

In France, the role is called RSSI (responsable de la sécurité des systèmes d'information). This guide explains what a CISO actually does, where the role sits in the organisation, what it costs, when to share it and which rules make it essential in 2026.

01

CISO: definition and purpose of the role

The Chief Information Security Officer is responsible for information security across the organisation. In large groups you will also find a head of cybersecurity who oversees several CISOs for subsidiaries or business lines.

The role exists for a simple reason: information security cannot be a by-product of running IT. Someone has to look at the information system from the threat's point of view, measure what the organisation stands to lose and propose reasoned choices. That is how the French government defines the role for its own departments: in interministerial instruction no. 1337/SGDSN/ANSSI of 2022, the CISO "advises and supports" the head of digital in the operational implementation of security, drawing on technical expertise.

The key word is advice. The CISO does not own the risk: senior management accepts, reduces or rejects it. The CISO informs the decision, then makes sure it is applied and recorded.

02

What a CISO does, from governance to crisis management

Job descriptions vary, but six groups of responsibilities come up almost every time.

Governance and security policy

The CISO writes the information security policy and has it approved, then breaks it down into rules and procedures. They run security committees, report indicators to management and own the roadmap. In an ISO 27001 programme, they usually lead the information security management system (ISMS).

Risk analysis and treatment

They carry out risk analyses on sensitive scopes, often with ANSSI's EBIOS Risk Manager method or following ISO 27005, and follow up the resulting treatment plan. For new projects, they build security in from the design stage and, in the public sector, prepare security accreditation files.

Compliance and control

NIS 2, GDPR, DORA in finance, HDS in healthcare, customer requirements: the CISO turns these into measures, organises internal audits and answers external auditors. They also assess suppliers, as a large share of risk now flows through the third-party chain.

Awareness and training

Phishing simulations, onboarding sessions, briefings for executives: security depends on behaviour, and changing it is the CISO's job.

Detection, incidents and crisis management

The CISO organises detection (in-house or with a SOC), incident triage and notification to the authorities where required. During a major cyberattack, they act as the expert in the crisis unit and contribute to the business continuity and recovery plan.

Monitoring

Threats, vulnerabilities, regulatory changes: without monitoring, the security policy freezes. The CISO filters and passes on what really matters to the organisation.

A WEEK IN THE LIFE OF A CISO Five days, five missions
Monday · Governance

Security committee

  • Present the month's indicators to management
  • Get a decision on a policy exception request
  • Update the security roadmap

DeliverableDecisions recorded in the minutes

Tuesday · RISK

Risk analysis workshop

  • Run a workshop with business owners on a new project
  • Identify the priority risk scenarios
  • Propose measures for the treatment plan

DeliverableResidual risks submitted for acceptance

Wednesday · Compliance

Audit preparation

  • Gather evidence for the ISO 27001 audit
  • Review the applicable NIS 2 requirements
  • Analyse a supplier's security questionnaire

DeliverableCompliance action plan up to date

Thursday · Awareness

Campaign and training

  • Launch a phishing simulation
  • Train new joiners on the basic rules
  • Prepare a session for executives

DeliverableCampaign report and targeted actions

Friday · Crisis

Incident and exercise

  • Triage an incident escalated by the SOC
  • Check notification obligations
  • Draw lessons from the crisis exercise

DeliverableLessons learned and corrective measures

A simplified typical week: in reality, incidents and project emergencies often upset the schedule.
03

Who should the CISO report to: IT, the CEO or risk?

The reporting line is debated in every organisation. It is not a matter of status: it determines the CISO's independence and their ability to escalate a risk that IT would rather play down.

In practice, reporting to the CIO remains the most common arrangement. A 2021 survey of its members by the French CISO club CESIN and OpinionWay found that 56% of CISOs reported to the CIO and 23% to general management. Each option has its strengths:

Pros and cons of the main CISO reporting lines
Reports toStrengthsWatch out for
CIOClose to technical teams, measures implemented quickly.Possible conflict between project deadlines and security requirements; escalated risks may be filtered.
CEO / general managementIndependence, direct access to decisions and budget.Risk of losing touch with operations; needs a strong link with IT.
Risk or complianceIntegrated view of enterprise risk, shared language with audit.Can distance security from technical and operational issues.

Whatever the choice, two safeguards matter more than the org chart: direct access to management when a serious risk arises, and a regular security committee where decisions are taken and recorded. NIS 2 points the same way by placing accountability for cybersecurity with management bodies.

04

CISO, CIO, DPO, risk manager: who does what?

These four roles work on neighbouring topics, which creates overlaps and sometimes blind spots. The comparison below sums up the question each one asks, its reference text and its deliverables.

Comparison CISO, CIO, DPO, risk manager

CISO Protects the information system in line with the risks, and proves it.

CIO Builds and runs the information system to serve the business.

DPO Monitors GDPR compliance and advises on personal data protection.

Risk manager Maps all of the company's risks, cyber included, for senior management.

Comparison of the CISO, CIO, DPO and risk manager roles
Criterion CISOCIODPORisk manager
Key question Are we protected in line with the threats?Does the IS deliver the expected service?Is personal data processed lawfully?Which risks could stop us reaching our objectives?
Scope Information and IS securityProjects, infrastructure, applications, IT budgetPersonal data processingAll risks: financial, operational, legal, cyber
Usually reports to CIO or general managementGeneral managementGeneral management or legalGeneral management or finance
Reference texts NIS 2, ISO 27001, security policy, sector rulesContracts, service levels, IS architectureGDPR (Articles 37 to 39 for the DPO)ISO 31000, regulator and audit requirements
Deliverables Security policy, risk analyses, action plans, dashboardsIT master plan, projects, operationsRecord of processing, DPIAs, data subject responsesRisk map, control plans
Watch out for Becoming the sole owner of the riskTrading off deadlines and security without the CISOConflicts of interest (combined roles)Reducing cyber to one line on the risk map

One point deserves emphasis: combining the CISO and DPO roles. The GDPR requires the data protection officer to be free of conflicts of interest, and the European guidelines on DPOs list heads of IT among the roles likely to create one. In small organisations where combining roles is unavoidable, at least document how decisions are separated.

05

CISO skills and career paths

The CISO is rarely the best technician on the team, and that is not what is expected. They need to understand architectures, threats and controls well enough to challenge teams, but their effectiveness rests mainly on three qualities:

  • Translating technical risk into business risk: a vulnerability means nothing to an executive committee, three days of halted production does.
  • Negotiating with IT, business units and procurement without acting as a censor.
  • Structuring: risk analysis methods, ISO 27000 standards, project management, change management.

Career paths vary: engineering degrees or specialised master's programmes (ANSSI certifies courses under the SecNumedu label), but also system administrators, auditors or consultants who moved into governance. The most sought-after certifications are ISO 27001 Lead Implementer or Lead Auditor, CISSP and CISM. ANSSI tracks the profession in its cybersecurity jobs observatory, whose 2025 edition includes a dedicated focus on CISOs.

06

CISO salary in France: what the surveys say

Figures found online often come from job boards with no published method. The most reliable reference in France is the survey carried out by CESIN with OpinionWay. According to its latest edition, reported by Le Monde Informatique in September 2024:

  • the median salary of responding CISOs is €90,000 gross per year, up from €89,200 in 2020;
  • average fixed pay rises from €82,000 in companies under 1,000 employees to €135,000 in those with over 50,000;
  • 71% received variable pay in 2023;
  • pay rises with seniority, from €71,000 (under five years) to €118,000 (over twenty years).

These figures describe CESIN members, who mostly work in large companies. A CISO at an SME, a local authority or a hospital usually earns less, and public-sector pay scales apply to civil servants.

07

Fractional or outsourced CISO: who is it for?

Not every organisation has the workload or budget for a full-time CISO. A fractional CISO (also called a virtual CISO or vCISO) works a few days a month for several clients. French local authorities often share one through an IT syndicate or a purchasing group, and hospitals in the same regional hospital group can share a CISO.

Three models for the CISO function
ModelSuited toPlan for
Full-time in-house CISOMid-sized and large companies, regulated entities with a large IS.A team or local relays depending on size; a dedicated budget.
Fractional CISOSMEs, growing mid-sized companies, local authorities, medium-sized hospitals.An internal contact, a clear engagement letter, tools accessible remotely.
Fully outsourced functionVery small or early-stage organisations.Keep decisions and knowledge of the context in-house.

A fractional CISO only works if their output stays in the organisation when they are not there. Without a shared framework, a shared action plan and a record of decisions, every visit starts from scratch. This is one of the cases where a governance, risk and compliance platform makes the difference.

08

Is a CISO mandatory? NIS 2, public sector, healthcare

There is no general legal requirement in France to appoint a CISO. Several frameworks nevertheless make the role all but essential.

NIS 2

Directive (EU) 2022/2555 does not mention the CISO, but its Article 20 requires management bodies to approve cybersecurity risk-management measures, oversee their implementation and undergo training. Article 21 lists the expected measures, starting with policies on risk analysis and information system security. Steering all this without an identified security function is not realistic. In France, the bill transposing the directive was still awaiting debate in the National Assembly in early October 2026, after yet another postponement; our compliance campaigns module shows how to track its requirements.

French ministries and state public bodies

Instruction no. 1337/SGDSN/ANSSI, part of the French state's digital security governance framework, requires each ministry's head of digital to appoint one or more CISOs. State public bodies must name a digital security contact, set up a dedicated organisation and assess their security level every year.

Healthcare facilities

To access funding under the French CaRE programme, the national digital health agency (ANS) requires facilities to show, among the prerequisites, "the existence of a security officer" and a security policy, with an org chart showing the CISO (Domain 1 bis webinar, February 2026).

ISO 27001

The standard does not require a specific job title, but it requires top management to assign and communicate information security responsibilities. In practice, almost all certified organisations appoint a CISO.

09

The CISO's toolkit: from spreadsheets to a GRC platform

Technical tools (firewalls, EDR, SIEM, vulnerability management) usually belong to operations teams. The CISO's own tools are steering tools: requirement frameworks, risk analyses, assessment questionnaires, action plans and dashboards.

Many CISOs start with spreadsheets. That works for one scope and one auditor. It breaks down as soon as you need to consolidate several sites, chase dozens of action owners, track suppliers or show the history of a decision. That is what a GRC platform is for: linking requirements, risks, measures and evidence so that indicators are calculated from up-to-date data.

Phinasoft was built for this work. The platform brings together five modules that share the same data: risk analysis, with an EBIOS RM module certified by ANSSI; frameworks and security policies versioned in the policies editor; compliance campaigns by site or subsidiary; vendor risk management on a dedicated portal; and GDPR. Business contributors are guided, so the CISO does not have to explain everything themselves. To see how it works on your own scopes, you can request a demo.

Summary

01

A pilot, not an operator

The CISO sets the security strategy, proposes trade-offs and checks they are applied. Decisions and accountability remain with senior management.

02

A cross-functional role

Governance, risk analysis, compliance, awareness and crisis management: the CISO works with IT, the DPO, business units and procurement.

03

A role that is becoming essential

NIS 2, French government rules and healthcare programmes all make an identified security function indispensable, whether in-house or fractional.

Frequently asked questions about the CISO

What does CISO stand for?

CISO stands for Chief Information Security Officer. In France the role is called RSSI. The CISO defines and steers an organisation's cybersecurity policy: risk analysis, security rules, compliance, awareness and incident preparedness. Senior management remains accountable for the decisions.

What is the difference between a CISO and a CIO?

The CIO builds and runs the information system: projects, infrastructure, IT budget and service quality. The CISO makes sure that system is protected in line with the risks and checks that security rules are followed. The CIO aims for availability and performance, the CISO for risk control: the roles complement each other but should not be merged.

Can the CISO also be the DPO?

It is not recommended. The GDPR requires the data protection officer to be free of conflicts of interest. European guidelines on DPOs list heads of IT among the roles that raise concerns, because they decide on the means of processing. In a small organisation, at least document how the roles are separated.

How much does a CISO earn in France?

According to a CESIN survey carried out with OpinionWay and published in September 2024, the median salary of CISOs who are members of the club is €90,000 gross per year. It varies widely with company size, from an average fixed salary of €82,000 below 1,000 employees to €135,000 above 50,000 employees.

What is a fractional CISO?

A fractional or virtual CISO is an experienced security leader who works a few days a month for several organisations, usually through a consultancy or as a freelancer. The model suits SMEs, mid-sized companies and local authorities that need security leadership but cannot fund a full-time post. It requires an internal contact and shared tools.

Is a CISO mandatory?

No general law requires every company to appoint a CISO. But French ministries and their public bodies must organise a security chain that includes CISOs, healthcare facilities must show they have a security officer to access some funding, and NIS 2 requires management to oversee measures that presuppose an identified security function.

A platform and service that adapt to you

Our platform is designed for fine-tuned configuration and broad adaptability to your needs.