Back to blog
CISO Management9 min read

Solo CISO
How to Run an Ambitious Security Program with a Lean Team

RSSIPME ETIPilotageRessourcesOrganisation

Most CISOs at SMEs manage their entire security program with 1–3 people. This is not inevitable — it is a method and tooling problem. 4 operational levers to regain control.

Key takeaways

  • In SMBs, a CISO often runs all of security with 1–3 people: being overstretched is a method problem, not a courage one.
  • Four operational levers (risk-based prioritisation, automation, targeted outsourcing, tooling) help regain control.
  • A steering platform centralises signals and automates reporting, so a lean team focuses on high-impact decisions.

"I'm the only one who knows all this. What if I leave tomorrow?"

That's what a CISO told me during a demo. He manages cybersecurity for a 1,200-person company. Alone. With, for 18 months, a part-time intern and an outsourced SOC provider.

He manages risks in an Excel file. Incidents in a Teams channel. Compliance in a SharePoint that only he really understands. COMEX reports rebuilt from scratch every quarter.

The real problem: the security program relies entirely on one person's memory and availability. When they take vacation, the company's cybersecurity does too.

The real state of the French SME CISO in 2026

  • 68% of French SMEs have no full-time CISO.
  • The average ratio is 1 security profile per 400–600 users in French SMEs (ANSSI benchmark: 1 per 150).
  • 80% of SME CISOs spend more than 4 hours per week on manual data consolidation and reporting that could be automated.

What "working alone" actually costs

A CISO who spends 30% of their time consolidating data in non-dedicated tools wastes the equivalent of 2.5 to 3 months of work per year on low-value tasks. At €80,000/year (total employer cost), that's between €16,000 and €20,000 of qualified work spent on copy-paste and slide formatting.

The average recruitment time for an experienced CISO in France is 4 to 7 months. During that period — who manages the program? Who responds to the NIS2 auditor? Who tracks open action plans?

4 levers for the CISO who does more with less

Lever 1 — Structure to delegate

Delegation doesn't start with recruitment. It starts with documentation. Clear processes allow business security referents, the outsourced SOC, and interns to take over whole sections of the program.

Lever 2 — Manage by risks, not by tools

Identify the 10 most probable risk scenarios for your organization, assign an owner to each, and track progress on remediation plans — not tickets and alerts. This repositioning has a secondary benefit: when you present to the board, you speak the language of management.

Lever 3 — Automate reporting before improving it

Reporting should be the natural output of continuous management, not a monthly project in itself. If you spend 4 to 6 hours a month building your COMEX report, you have a tooling problem — not an analysis problem.

Lever 4 — Outsource what doesn't belong to you

Keep internal

  • Risk management & treatment plans
  • Relationship with board / executive team
  • Action plan coordination
  • NIS2, GDPR compliance preparation

Can be outsourced

  • 24/7 monitoring (outsourced SOC or MDR)
  • Penetration testing & technical audits
  • Employee cybersecurity training
  • Threat intelligence & vulnerability monitoring

What CISOs who manage well do differently

They have a permanent dashboard, not a quarterly report

A CISO who "does their reporting" every quarter doesn't have visibility — they have snapshots. The difference with a CISO who manages continuously: they can answer any question about their program at any time, without preparation. That's not a discipline question. It's a tooling question.

They quantify residual risks rather than hiding them

When management asks "are we safe?", the temptation is to reassure. CISOs who build lasting trust answer differently: "Here is our current risk level, here is what is covered, here is what is not yet covered, and here is why it is — or is not — acceptable."

The one-question test

Could someone else manage your program if you took 3 weeks of vacation tomorrow?

If the answer is no, it's a method problem. And often, it's also a tooling problem. Eyako is the platform designed for CISOs at SMEs who manage alone, or almost alone. It centralizes what was scattered, structures what was ad hoc, and automates what was manual.

Frequently asked questions

How can a CISO manage security alone at a mid-market company?+
By combining 4 levers: structuring to delegate (process documentation), managing by business risks rather than technical alerts, automating reporting, and outsourcing technical execution (SOC, penetration tests) while keeping governance internal.
What is the recommended cyber team ratio for an SME?+
ANSSI recommends 1 security profile per 150–200 users. In reality, the average in French SMEs is 1 per 400–600. This gap can be compensated by appropriate tooling and a structured organization.
What security functions can be outsourced at an SME?+
24/7 monitoring (outsourced SOC or MDR), penetration testing and technical audits, employee cybersecurity training, and threat intelligence can be outsourced. However, governance, risk management, the relationship with management, and compliance preparation must remain internal.

Manage alone — without being alone.

See how Eyako helps SME CISOs structure their security program with lean teams.

Request a personalized demo
Solo CISO: How to Run an Ambitious Security Program with a Lean Team | Eyako