An advent calendar that never ends · Door 276 / 365 · Sat Oct 3
← The blog
October 3, 2026 · 3 min read · Olaf Jacobson

Who owns security at your company? A practical guide for growing teams

Ask a growing company who owns information security and you'll usually get a pause, then a list.

IT handles the laptops. The privacy officer does GDPR. A managed service provider runs the firewall. Finance worries about suppliers. Management signs off on a policy once a year. Everyone does a piece, and nobody holds the whole thing.

That's not a people problem. It's a structure problem, and it gets expensive the moment a customer sends a security questionnaire, an auditor asks for evidence, or something actually goes wrong.

Five signs nobody owns security

  • Security questionnaires take weeks. Every big customer asks the same questions, and every time someone has to hunt down the answers.
  • "We should get ISO 27001" has been on the list for a year. Everyone agrees, nobody has the time to lead it.
  • You're not sure whether new rules apply to you. In Europe, NIS2 widened the group of companies with security obligations considerably, and if you sell to European customers, their requirements become yours.
  • Risks live in people's heads. There's no single list of what could go wrong, how likely it is and who's handling it.
  • Management hears about security only when something breaks. No regular report, no clear picture of whether things are getting better.

If three or more sound familiar, the gap isn't tools. It's ownership.

The usual options, and the missing one

Hire a full-time security lead. The right move eventually, but it's a senior hire, hard to find, and often more than a growing company needs on day one.

Ask IT to "also do security". Common and understandable, but security governance (risk, compliance, suppliers, reporting) is a different job from running systems, and it tends to lose to whatever is on fire that day.

Bring in an external security office. This is the option many teams don't know exists: an outside team that takes ownership of the whole picture, coordinates everyone already doing a piece, and reports to management on a fixed rhythm. You get the structure of a security department without building one.

How an external security office works: CybearSquad as an example

CybearSquad, based in Rijswijk in the Netherlands, does exactly this. Their line is simple: "Your Security Office. Without building one."

What that covers in practice:

  • One point of ownership across security governance, risk management and compliance, connecting the work your IT team, privacy officer, suppliers and service providers already do.
  • Frameworks, including ISO 27001, NIS2, GDPR, NEN 7510 for healthcare, and AI governance, which is quickly becoming its own discipline.
  • A clear start: a baseline and the key risks within 30 days, a roadmap with clear owners within 60.
  • A steady rhythm afterwards: ongoing oversight, with management reporting every quarter.

The point isn't to take over every technical task. It's to make sure the right things happen, in the right order, with someone accountable for the whole.

If you recognised your company in the five signs above, their site explains how they work and what a first 60 days look like.

Why they're on our blog

CybearSquad was one of the very first businesses behind a door on The Daily Door, and the first to own two days in a row, which earned them the 🔥 Back-to-Back badge on our leaderboard. We liked what they do enough to write about it.

Disclosure: CybearSquad has owned dates on The Daily Door. They didn't pay for this post.


Want your business behind a door? Every day of the year has one, and bidding starts at $1. Pick your date.