Corporate governance · 3 September 2026
The cybersecurity questions a CEO must not delegate
There are decisions that cannot be left only to the technical team: who can stop production, what residual risk was approved, and who speaks on the day of the incident.
By Rafael Núñez Aponte. Published on 3 September 2026. Updated on 4 September 2026.
Original text in Spanish. Read the original Spanish version

A CEO does not have to read logs. They have to be able to sleep knowing what residual risk they accepted. That is not delegated to a dashboard full of green lights. It is sustained with a few questions, repeated, uncomfortable and dated.
The ones I would not leave in an appendix
- What is the process that, if it falls, prevents us from operating?
- When was the last real restoration of backups, not the last “successful” job?
- Who can shut down production and on what criterion?
- What third-party data do we have that we would not know how to explain to a regulator?
- What is our position on paying a ransom, in writing?
- Which AI tool is used with company data without a contract?
- Whom do we call in the first hour, and who stays outside that room?
- What would we say today, if we had to speak in public at 18:00?
What must not be delegated and what may
Delegating operations is inevitable. Delegating the question that defines residual risk is abdication. The CISO must have budget, access to the board and permission to deliver bad news. The CEO must have the discipline to ask in the language of business. When those two conditions exist, the organisation stops improvising ethics in the middle of extortion.
Signs that the question has already been delegated too far
- The security report arrives in a language the board cannot vote on.
- No one at the table can say, in a sentence, which is the critical process.
- The last restoration test is a screenshot, not an exercise with an owner.
- The position on ransom, spokespersonship and shutting down systems is not written.
- Internal AI is discussed as innovation and not as surface.
References
- NIST Cybersecurity Framework 2.0. NIST. Accessed: 2026-09-04. Las preguntas que un CEO no debe delegar se plantean como gobierno del riesgo residual (identificar, proteger, detectar, responder y recuperar), no como un inventario técnico que sustituya al CISO.