
# CISO Reporting Line: When Security Judgment Must Leave the CIO Span
The question is not whether the chart says “CISO to CEO” or “CISO to CIO.” It is whether a stop still works when the release is supposed to ship tonight — and whether that security judgment then sits as a named owner in front of the Vorstand, who can accept it or overrule it in writing.
Christian Pobbig and Beyond Chiefs work from Hamburg on AI Executive Search in DACH. This piece names the break, not the box on the chart. The law binds the organ and is silent on CISO rights.
A reporting line into the CIO can hold day-to-day work, budget, and delivery. It fails in the moment the same ticket would have to ship and stop the shipment. Then the delivery owner filters the picture the Vorstand uses as its information basis.
That is not a ban on every CIO line. It is the test: does the stop still work when the deadline is tonight? If not, judgment has already left the CIO span — only without a name, without writing, and without a recipient.
To protect independence, the information security officer (ISB) should sit with top management. Integration into the IT department can create role conflicts, because control of security measures would then not be free of influence. Conflicts need a direct reporting path to leadership so they can be decided quickly. The ISB investigates security incidents and reports status to leadership (BSI Lerneinheit 2.4).
Grundschutz++: the ISB must be organisationally independent, should report to leadership, and should not sit under the IT lead — competing roles of execute versus check/approve (BSI Grundschutz++ guide).
ISB ≠ CISO. “CISO” is an organisational title. The BSIG does not create a CISO office. “Should” is not a finding that every CIO line is illegal.
Management bodies of particularly important and important entities implement and monitor the risk-management measures under § 30. Personal liability toward the entity follows applicable company law; the BSIG applies only where company law has no such rule. Management must regularly attend training to recognise and assess IT-security risks and their impact on services (§ 38 BSIG).
§ 38 is silent on CISO, veto, kill-switch, and reporting line. It binds the organ. It does not staff tonight’s stop. NIS2 Article 20 is the parent of that organ duty — management bodies approve cybersecurity risk-management measures, oversee implementation, can be held liable, and train — and it also does not say “the CISO reports to the board, not the CIO” (Directive (EU) 2022/2555 Art. 20). DORA stays sector-scoped (financial entities) and is not exported here to general industry.
§ 38 (3) management training is not AI Act Article 4. Literacy proof stays another page.
BC frame (INFERENCE) — written delegation, not a statutory veto. Judgment must leave the CIO span when one of these four exits is live:
A significant security incident triggers, externally, an early notice within 24 hours and an incident report within 72 hours once the reporting channel exists; a final report follows within one month, subject to conditions (§ 32 BSIG). Those are external notification clocks for in-scope entities — not an invented internal SLA, and not automatically every Mittelstand house. Who commands tonight is practice. The external clock is law when it applies.
The Vorstand installs a monitoring system so developments threatening the going concern can be recognised; listed companies: an adequate internal control system and risk-management system (§ 91 (2) and (3) AktG). The duty of care requires an adequate information basis (§ 93 (1) AktG). A picture filtered only through the CIO is an information-basis problem (INFERENCE) — not proof that every CIO line is unlawful.
Reports to the Aufsichtsrat remain the Vorstand’s job; important occasions go to the chair (§ 90 AktG). The Aufsichtsrat supervises; management measures cannot be transferred to it (§ 111 (1) and (4) AktG). The German default is not “the CISO reports to the Aufsichtsrat.” The Aufsichtsrat does not run the incident.
GmbH: Geschäftsführung, not automatically an Aufsichtsrat. Austria and Switzerland are analogies, not copy-paste.
The AI reporting line between Vorstand and Aufsichtsrat is a different contract: which AI facts the Vorstand reports to the Aufsichtsrat. This piece is the security judgment that must leave the CIO span. The same sections (§ 90, § 111) are the organ boundary — not a merge. The CISO is not the owner of the AI report.
### Does the law forbid a reporting line to the CIO?
No. BSI says the ISB should not sit under the IT lead. § 38 binds management and is silent on the line. What is not illegal is the box; what is unresolved is the conflict when stop and delivery sit in the same person.
### Does every organisation need a CISO?
No. The BSIG does not create a CISO office. ISB and CISO are not the same. What is missing when a stop has no name is the judgment — not automatically a vacancy.
### May the CISO report directly to the Aufsichtsrat?
Not as the German default. The Vorstand reports; the Aufsichtsrat supervises and does not run management.
---
Draft. Not live without Christian. No service CTA.




.webp)