Sicra Header Logo
  • Careers
  • About us
  • People
EnglishNorsk
Talk to us
  1. Knowledge
  2. Insights
  3. Blog
Blog
15.06.2025
min read

NIS2 is coming – but who really owns the responsibility for security?

The NIS2 directive is approaching – and more organizations should consider how responsibilities for information security are distributed
<span id="hs_cos_wrapper_name" class="hs_cos_wrapper hs_cos_wrapper_meta_field hs_cos_wrapper_type_text" style="" data-hs-cos-general-type="meta_field" data-hs-cos-type="text" >NIS2 is coming – but who really owns the responsibility for security?</span>
Sicra_Portrait_Crop_1200x1500px_4808
Oddbjørn SkaugeChief Information Security Officer
Proactive CISO who focuses on good and simple solutions for information security.

The EU directive NIS2 is approaching. Many Norwegian organizations are now trying to map out what it will mean for them, but many haven’t even begun the journey!

For some, it’s about establishing solid security across their entire IT landscape. Others have security in place but lack documentation and governance.

For both, it comes down to creating clarity around one fundamental question:

Who actually has responsibility for information security?

The answer is often more unclear than one might think.

More requirements, but the same capacity

NIS2 imposes increased requirements for governance, risk assessment, preparedness, and reporting – even for organizations that have previously operated under the radar. At the same time, we see that internal resources in many organizations are not growing in line with the requirements.

This means that security work often becomes “something you do on the side.” An IT manager is given responsibility for security in addition to everything else. Some measures are initiated – but without a holistic plan, prioritization, or structure.

It’s understandable, but also risky.

Why it's not enough to “distribute the responsibility”

Distributing security responsibility across different functions can work in theory. In practice, we often see that:

  • No one has overall ownership – a security strategy is missing.

  • Measures are random – there’s a reaction to what’s urgent, but little preventive work.

  • Regulations and threats remain abstract – because no one has the role of monitoring and translating them into the organization's context.

  • The board and management are not involved or do not receive sufficient insight – and therefore lack the basis to make informed decisions.

CISO for hire: A pragmatic alternative

You may not need a full-time security leader. But you need someone to take responsibility for the bigger picture – for a few hours a week or during a transitional phase.

Through our CISO for hire service, Sicra offers experienced advisors who act as the organization’s security leader – without you having to hire someone. We can assist with:

  • Security posture analysis

  • Short term and long term cyber security strategy

  • Closing security gaps

  • Plans to meet NIS2 and other relevant requirements

  • Establishing or further developing an ISMS (Information Security Management System)

  • Reporting to management and the board

  • Incident response and contingency planning

NIS2 is not just a compliance exercise

It’s about trust, reputation, and the ability to withstand unforeseen events. For many organizations, NIS2 will be a wake-up call – and an opportunity to clean up, gain structure, and create a long-term security plan.

But that plan needs an owner.

Are you already working on NIS2 preparations, but lack a clear responsible party?

We’re happy to have a non-binding conversation to explore how a CISO for hire could support your organization.

🔗Read more about Sicra's CISO-for-hire service here >

Need Assistance?

We are happy to have a non-binding conversation.
Contact us

Explore more

Cybersecurity as a competitive advantage – trust as a strategic investment
Blog

Cybersecurity as a competitive advantage – trust as a strategic investment

Security that provides trust – and a competitive advantage.
Security training for employees: Building real awareness
Blog

Security training for employees: Building real awareness

Safety training is effective when it is realistic, customized, and continuous.
When is the right time to hire a CISO?
Blog

When is the right time to hire a CISO?

Tech blog
Cybersecurity
Spreading security responsibility is understandable, but rarely effective and risky.
10 security measures your business should have in place before the holidays
Blog

10 security measures your business should have in place before the holidays

Tech blog
Cybersecurity
10 measures that better prepare your business for the summer holiday.

Tailored cybersecurity for institutions and enterprises that allows for innovation, growth, and fearless performance.

Get in touchCall us +47 648 08 488
Stay updated
Receive the latest news

Links
SustainabilityFAQPartnersCertifications and awardsCareerPress & brand
Contact

Tel: +47 648 08 488
E-mail: firmapost@sicra.no

Rosenholmveien 25, 1414
Trollåsen. Norway

Follow us on LinkedIn
Certifications
iso27001-white
ISO 27001 compliance
miljofyrtarnlogo-hvit-rgb
Eco-Lighthouse
Sicra Footer Logo
Sicra © 2024
Privacy Policy