Hiring a Cyber Security Manager is a reasonable response when a programme needs help with security.
Someone now attends the governance meetings, maintains the risk register and challenges suppliers. There is a named person to ask about progress.
They still need the organisation to back them.
If design and procurement decisions have already been made, the new manager may have little room to change them. They may have no say over delivery priorities, no access to specialists and several layers of governance between them and a decision. They can end up reporting problems they have no means to fix.
A capable Cyber Security Manager can lead the work and challenge decisions. But senior leaders need to take ownership of risk and give the manager enough authority to act. Security also needs a place in delivery from discovery through to operation.
Securing that support is part of the manager’s job. We cannot expect every client to know how to organise security before they hire someone to help. The manager needs to explain what must change, win senior support and help colleagues put it into practice.
The decisions a security manager cannot make alone
Giving someone a security job title does not, by itself, make a complex programme secure.
Architecture, engineering, commercial, finance, delivery, operations and suppliers all make decisions that affect security. They decide what gets built, which risks the programme takes and which controls it pays for. Their work also determines what evidence is available when assurance is needed.
The Cyber Security Manager can coordinate this work. They cannot make every decision or carry out every task themselves.
The programme needs clear answers to five questions.
- Who ultimately answers for the programme’s security risk and accepts the consequences of a decision?
- Who coordinates or completes each security task?
- Who can change a design, require a problem to be fixed, challenge a supplier or escalate an unacceptable risk?
- Which people and specialist skills are available to do the work?
- Where are decisions made, recorded and funded, and who makes sure they are carried out?
When these arrangements are unclear, a security manager can be held responsible for outcomes without the authority, resources or support to achieve them.
Putting a name against the responsibility has not given them a way to act.
Where the model breaks down
Who owns the risk
Cyber security risk affects the programme itself. It can change costs and schedules, interrupt operations, create legal problems and damage public trust. It can also prevent the programme from delivering what it was set up to do.
A security specialist cannot carry all of that accountability alone.
The UK National Cyber Security Centre’s Cyber Assessment Framework calls for accountability at senior level and appropriate delegation of authority to make decisions. Government Secure by Design guidance also gives responsibilities to Senior Responsible Owners, programme and delivery teams, commercial staff, technical specialists and security professionals.
A security manager can assess a risk and recommend a response. The risk owner needs enough authority to decide what happens, secure the funding and answer for the outcome.
Our practitioners have seen security risks passed around an organisation until someone in the security team is assigned as the owner. That person may have no control over the programme budget or the resources needed to fix the problem. Naming them on the register does not give them either.
Risk should sit with someone who has the authority to fix or accept it. Security specialists should help that person understand the options and their consequences, so they can make an informed decision.
Otherwise, significant risks can move between boards and workstreams without reaching anyone who is both authorised and required to resolve them.
What the manager has authority to do
A programme can give its security manager a long list of responsibilities while denying them the means to carry them out.
For example, a manager may be asked to assure a supplier without joining the commercial discussions. They may be responsible for security architecture but only see the design after approval. Or they may identify a serious weakness without being able to delay a release, obtain funding to fix it or get a risk decision in time.
The security team can then advise, report and escalate, but other people make the decisions that determine the programme’s exposure.
Agree the limits of the manager’s authority before these situations arise.
- Which decisions can the security lead make directly?
- What must be escalated, to whom and within what timeframe?
- Who can formally accept material security risk?
- What happens when security, cost and delivery priorities conflict?
- Can the security lead get the evidence and specialist support needed to judge whether security arrangements work?
If nobody can answer these questions, another appointment will leave the same problems in place.
Our practitioners have been brought in to make changes that an existing security team had wanted for some time. The team lacked the authority, budget or experience of making those changes elsewhere. Securing leadership support helped them do that work without discrediting the team.
When security joins the programme
Security has more scope to help when it is involved in shaping the programme, before decisions are fixed.
By the time a formal assurance gateway arrives, the architecture, suppliers and budget may already be agreed. The delivery model and the way systems connect may be fixed too. Problems discovered at that point cost more to correct and are more likely to be accepted because a change would disrupt delivery.
Secure by Design addresses this by bringing security into the work early and keeping it involved as the service changes. Assurance continues throughout the service’s life, rather than waiting for a final review.
The Cyber Security Manager needs to be involved in each of these areas.
- Discovery and requirements
- Architecture and design decisions
- Procurement and supplier evaluation
- Delivery planning and prioritisation
- Testing and acceptance
- Operational readiness
- Change, vulnerability and incident management
- Decommissioning and disposal
A monthly security meeting is little help if the manager is left out of the conversations where delivery decisions are made.
In our experience, substantial cyber costs can come from late programmes and major changes close to delivery. Earlier security involvement can avoid expensive rework. Planned spending is easier to manage than having to find money for a late change or an incident.
Whether reporting leads to action
Boards, dashboards and regular reports can keep running while the same security problems remain unresolved.
Check what happened after the last report. Did anyone approve funding, change a design or decide how to treat a risk?
A risk register needs owners who can act, agreed treatment and realistic deadlines. Significant risks need a clear route to escalation. A security board needs people with authority to make decisions, and assurance reports should inform investment, design, acceptance or operation. Otherwise, the programme can keep reporting the same problems without resolving them.
Look for these warning signs.
- The same high risks appearing month after month without movement
- Actions assigned to teams that cannot fund or prioritise them
- Risks marked as accepted without a clearly authorised risk owner
- Supplier evidence is collected without being properly checked or questioned
- Security reporting dominated by document completion rather than security outcomes
- Governance meetings repeatedly deferring decisions to another forum
The evidence needs to reach someone who can decide what to do, and that decision needs to be carried out. Recording the risk is only the beginning.
Which skills the programme needs
A large or sensitive programme usually needs several security skills as well as someone to coordinate the work.
Depending on its scope, it may need security architecture, risk management, assurance, testing, vulnerability management, supplier assurance, data protection, incident preparation and operational support. Different specialists may be needed at different stages, and the amount of work will change as delivery progresses.
One Cyber Security Manager cannot cover every discipline. Urgent delivery work can push assurance aside, while specialist questions wait for attention. Meetings and reporting consume time the manager needs for other work. The programme becomes dependent on one person.
This does not necessarily require a large permanent team. It requires access to the right skills when the work needs them, with clear responsibility for each task.
The manager needs influence and the team needs trust
A security manager spends a good deal of time asking the organisation to change. Being technically correct will not secure the budget or change a supplier contract. They need to work with the people who control those decisions and explain what needs to happen.
Colleagues also need to want the team’s help. If security is seen as a function that catches people out or assigns blame, they will avoid it. The team should be a trusted adviser that helps people understand their options and get the work done with less uncertainty.
Security teams need to report facts fearlessly and escalate when necessary. They also need to help people deal with problems early. You should leave a security meeting knowing what to do next and glad the team is on your side, rather than carrying another list of problems to solve alone.
If asking security for help repeatedly makes the work harder, that deserves attention. The team should help colleagues understand the safer course and how to follow it.
What effective programme security looks like
| A weak programme model | An effective programme model |
|---|---|
| Security is assigned to one named individual | Senior accountability and delivery responsibilities are explicit |
| The security team reports risks | Authorised owners make timely, recorded risk decisions |
| Security reviews completed designs | Security shapes requirements, architecture and procurement |
| Assurance is concentrated around gateways | Evidence and assurance are maintained throughout delivery |
| One person is expected to cover every discipline | The security lead can draw on appropriate specialist capability |
| Suppliers interpret requirements independently | Consistent requirements and evidence expectations apply across the supply chain |
| Progress is measured by documents and meetings | Progress is measured by decisions, risk reduction and delivery outcomes |
The Cyber Security Manager has an important role in putting these arrangements in place and maintaining them. They should not be expected to cover for their absence indefinitely.
Questions to ask before relying on the appointment
Use these questions to check whether the manager has what they need.
- Who holds senior accountability for cyber security risk?
- Who has authority to accept a material security risk?
- Can the security lead escalate directly to those decision makers?
- Is security involved before architecture, procurement and supplier decisions are fixed?
- Are security responsibilities defined across programme, technical, commercial and operational teams?
- Does every significant risk have an authorised owner, treatment decision and deadline?
- Are suppliers held to consistent security requirements and evidence standards?
- Is assurance continuous, or does it intensify only before a gateway or approval?
- Can the security manager access the specialist capability needed to deliver the work?
- Would the programme’s security governance continue to function if that manager were unavailable tomorrow?
Unclear answers suggest a problem with how security works in the programme. Recruitment alone may not resolve it.
Where external support can help
Some programmes have a strong internal security lead but not enough people to cover every workstream. Others need expertise for one phase, an independent assessment of risk or extra support during mobilisation, procurement or assurance.
External support can add capacity during a transformation programme and reduce it afterwards, without permanently increasing the internal team. It can also bring fresh experience where an organisation has worked in the same way for years.
A long serving manager may know the organisation exceptionally well without having made the proposed change elsewhere. Asking them to persuade a new CEO to change how the organisation works can be a great deal to ask of one person. An external practitioner can bring experience from organisations that have already made that change, supporting the internal lead rather than replacing their knowledge.
A specialist security partner can help in these circumstances.
- A prime needs experienced ownership of a defined cyber workstream
- The internal security lead needs delivery capacity rather than more oversight
- The programme needs specialist skills or people with security clearance
- Assurance activity has uncovered a gap that must be resolved quickly
- Delivery demand fluctuates and a large permanent function would be disproportionate
- Programme leadership needs independent challenge or a clearer view of its exposure
- Security needs to be embedded across multiple suppliers and delivery teams
Be clear about what the partner will own and deliver. Their work should bring security into delivery and help the programme manage its risk. Another layer of advice will achieve little if nobody has the means to act on it.
Give the manager a fair chance to succeed
A Cyber Security Manager gives the programme someone to lead the security work and challenge its decisions.
The organisation must still decide who owns risk, give people authority to act and involve security before delivery decisions are fixed. It needs to cover gaps in specialist skills and act on the evidence assurance produces.
That needs to be part of the programme’s normal work.
The manager should help build those arrangements, with leadership behind them. External support can help where the internal team needs more capacity, experience or support in making the case to senior leaders.
Before relying on the appointment, ask whether the manager can get decisions made and changes carried out. If they cannot, filling the role has not resolved the programme’s security problem.
Need experienced cyber security support for a complex programme or one with demanding security requirements? Talk to Wuluf about taking responsibility for a workstream, filling a gap in specialist skills or improving how security is governed and delivered.

