Solo CISO
How to Run an Ambitious Security Program with a Lean Team
Most CISOs at SMEs manage their entire security program with 1–3 people. This is not inevitable — it is a method and tooling problem. 4 operational levers to regain control.
Key takeaways
- In SMBs, a CISO often runs all of security with 1–3 people: being overstretched is a method problem, not a courage one.
- Four operational levers (risk-based prioritisation, automation, targeted outsourcing, tooling) help regain control.
- A steering platform centralises signals and automates reporting, so a lean team focuses on high-impact decisions.
"I'm the only one who knows all this. What if I leave tomorrow?"
That's what a CISO told me during a demo. He manages cybersecurity for a 1,200-person company. Alone. With, for 18 months, a part-time intern and an outsourced SOC provider.
He manages risks in an Excel file. Incidents in a Teams channel. Compliance in a SharePoint that only he really understands. COMEX reports rebuilt from scratch every quarter.
The real problem: the security program relies entirely on one person's memory and availability. When they take vacation, the company's cybersecurity does too.
The real state of the French SME CISO in 2026
- 68% of French SMEs have no full-time CISO.
- The average ratio is 1 security profile per 400–600 users in French SMEs (ANSSI benchmark: 1 per 150).
- 80% of SME CISOs spend more than 4 hours per week on manual data consolidation and reporting that could be automated.
What "working alone" actually costs
A CISO who spends 30% of their time consolidating data in non-dedicated tools wastes the equivalent of 2.5 to 3 months of work per year on low-value tasks. At €80,000/year (total employer cost), that's between €16,000 and €20,000 of qualified work spent on copy-paste and slide formatting.
The average recruitment time for an experienced CISO in France is 4 to 7 months. During that period — who manages the program? Who responds to the NIS2 auditor? Who tracks open action plans?
4 levers for the CISO who does more with less
Lever 1 — Structure to delegate
Delegation doesn't start with recruitment. It starts with documentation. Clear processes allow business security referents, the outsourced SOC, and interns to take over whole sections of the program.
Lever 2 — Manage by risks, not by tools
Identify the 10 most probable risk scenarios for your organization, assign an owner to each, and track progress on remediation plans — not tickets and alerts. This repositioning has a secondary benefit: when you present to the board, you speak the language of management.
Lever 3 — Automate reporting before improving it
Reporting should be the natural output of continuous management, not a monthly project in itself. If you spend 4 to 6 hours a month building your COMEX report, you have a tooling problem — not an analysis problem.
Lever 4 — Outsource what doesn't belong to you
Keep internal
- ✓Risk management & treatment plans
- ✓Relationship with board / executive team
- ✓Action plan coordination
- ✓NIS2, GDPR compliance preparation
Can be outsourced
- →24/7 monitoring (outsourced SOC or MDR)
- →Penetration testing & technical audits
- →Employee cybersecurity training
- →Threat intelligence & vulnerability monitoring
What CISOs who manage well do differently
They have a permanent dashboard, not a quarterly report
A CISO who "does their reporting" every quarter doesn't have visibility — they have snapshots. The difference with a CISO who manages continuously: they can answer any question about their program at any time, without preparation. That's not a discipline question. It's a tooling question.
They quantify residual risks rather than hiding them
When management asks "are we safe?", the temptation is to reassure. CISOs who build lasting trust answer differently: "Here is our current risk level, here is what is covered, here is what is not yet covered, and here is why it is — or is not — acceptable."
The one-question test
Could someone else manage your program if you took 3 weeks of vacation tomorrow?
If the answer is no, it's a method problem. And often, it's also a tooling problem. Eyako is the platform designed for CISOs at SMEs who manage alone, or almost alone. It centralizes what was scattered, structures what was ad hoc, and automates what was manual.
Frequently asked questions
How can a CISO manage security alone at a mid-market company?+
What is the recommended cyber team ratio for an SME?+
What security functions can be outsourced at an SME?+
Manage alone — without being alone.
See how Eyako helps SME CISOs structure their security program with lean teams.
Request a personalized demo