Empty CIO desk, board table, unused violet incident key and sealed folder — Motto x Beyond Chiefs

CISO Reporting Line: When Security Judgment Must Leave the CIO Span

# CISO Reporting Line: When Security Judgment Must Leave the CIO Span

The question is not whether the chart says “CISO to CEO” or “CISO to CIO.” It is whether a stop still works when the release is supposed to ship tonight — and whether that security judgment then sits as a named owner in front of the Vorstand, who can accept it or overrule it in writing.

Christian Pobbig and Beyond Chiefs work from Hamburg on AI Executive Search in DACH. This piece names the break, not the box on the chart. The law binds the organ and is silent on CISO rights.

The break is the judgment, not the box on the chart

A reporting line into the CIO can hold day-to-day work, budget, and delivery. It fails in the moment the same ticket would have to ship and stop the shipment. Then the delivery owner filters the picture the Vorstand uses as its information basis.

That is not a ban on every CIO line. It is the test: does the stop still work when the deadline is tonight? If not, judgment has already left the CIO span — only without a name, without writing, and without a recipient.

BSI: the ISB should not sit under the IT lead — and needs a direct path for the conflict

To protect independence, the information security officer (ISB) should sit with top management. Integration into the IT department can create role conflicts, because control of security measures would then not be free of influence. Conflicts need a direct reporting path to leadership so they can be decided quickly. The ISB investigates security incidents and reports status to leadership (BSI Lerneinheit 2.4).

Grundschutz++: the ISB must be organisationally independent, should report to leadership, and should not sit under the IT lead — competing roles of execute versus check/approve (BSI Grundschutz++ guide).

ISB ≠ CISO. “CISO” is an organisational title. The BSIG does not create a CISO office. “Should” is not a finding that every CIO line is illegal.

§ 38 binds management; it does not staff the night shift

Management bodies of particularly important and important entities implement and monitor the risk-management measures under § 30. Personal liability toward the entity follows applicable company law; the BSIG applies only where company law has no such rule. Management must regularly attend training to recognise and assess IT-security risks and their impact on services (§ 38 BSIG).

§ 38 is silent on CISO, veto, kill-switch, and reporting line. It binds the organ. It does not staff tonight’s stop. NIS2 Article 20 is the parent of that organ duty — management bodies approve cybersecurity risk-management measures, oversee implementation, can be held liable, and train — and it also does not say “the CISO reports to the board, not the CIO” (Directive (EU) 2022/2555 Art. 20). DORA stays sector-scoped (financial entities) and is not exported here to general industry.

§ 38 (3) management training is not AI Act Article 4. Literacy proof stays another page.

Four exits: stop, override, incident command, written risk acceptance

BC frame (INFERENCE) — written delegation, not a statutory veto. Judgment must leave the CIO span when one of these four exits is live:

  1. Stop — halt a release or change the delivery owner wants tonight.
  2. Override — security judgment overrules a CIO preference on a live control; otherwise residual risk stays unnamed.
  3. Incident command — who isolates, who notifies the Vorstand, who owns the external § 32 fact if the entity is in scope.
  4. Written risk acceptance — Vorstand or Geschäftsführung accepts or overrules in writing; the CISO records the security position. The Aufsichtsrat is informed as an organ, not substituted.

A significant security incident triggers, externally, an early notice within 24 hours and an incident report within 72 hours once the reporting channel exists; a final report follows within one month, subject to conditions (§ 32 BSIG). Those are external notification clocks for in-scope entities — not an invented internal SLA, and not automatically every Mittelstand house. Who commands tonight is practice. The external clock is law when it applies.

The Vorstand accepts or overrules in writing; the Aufsichtsrat is informed

The Vorstand installs a monitoring system so developments threatening the going concern can be recognised; listed companies: an adequate internal control system and risk-management system (§ 91 (2) and (3) AktG). The duty of care requires an adequate information basis (§ 93 (1) AktG). A picture filtered only through the CIO is an information-basis problem (INFERENCE) — not proof that every CIO line is unlawful.

Reports to the Aufsichtsrat remain the Vorstand’s job; important occasions go to the chair (§ 90 AktG). The Aufsichtsrat supervises; management measures cannot be transferred to it (§ 111 (1) and (4) AktG). The German default is not “the CISO reports to the Aufsichtsrat.” The Aufsichtsrat does not run the incident.

GmbH: Geschäftsführung, not automatically an Aufsichtsrat. Austria and Switzerland are analogies, not copy-paste.

Boundary to the AI reporting line

The AI reporting line between Vorstand and Aufsichtsrat is a different contract: which AI facts the Vorstand reports to the Aufsichtsrat. This piece is the security judgment that must leave the CIO span. The same sections (§ 90, § 111) are the organ boundary — not a merge. The CISO is not the owner of the AI report.

FAQ

### Does the law forbid a reporting line to the CIO?

No. BSI says the ISB should not sit under the IT lead. § 38 binds management and is silent on the line. What is not illegal is the box; what is unresolved is the conflict when stop and delivery sit in the same person.

### Does every organisation need a CISO?

No. The BSIG does not create a CISO office. ISB and CISO are not the same. What is missing when a stop has no name is the judgment — not automatically a vacancy.

### May the CISO report directly to the Aufsichtsrat?

Not as the German default. The Vorstand reports; the Aufsichtsrat supervises and does not run management.

---

Draft. Not live without Christian. No service CTA.

Recent Blog Posts

Empty board table, blank minutes, unused violet stop ring

Agentic AI: five questions the board must ask

Team Beyond Chiefs
Read More
Open blank evidence binder with unused purple wax seal and pen — Motto x Beyond Chiefs

AI Act Article 4: What Management Must Be Able to Prove About AI Literacy

Team Beyond Chiefs
Read More

AI Agents: Transforming Global Business in 2025 | Complete Guide

AI as CEO? 6 Costly Misconceptions About AI Leadership That Companies Must Avoid

CONTACT Us

Leading the Future with AI-Driven Leadership

contact us