How to Stifle Open Source Without Banning It
Benedikt Langer
6 Min. Read The sharpest argument against China’s top open AI comes from a man at OpenAI. Dean Ball, ...
In many companies, the CISO is seen as the person responsible for security. This view only appears to relieve the executive board. Since the NIS2 Directive, responsibility now explicitly rests with the management bodies and cannot be delegated away. Managed Security Services address capacity issues, not liability issues. Those who confuse the two buy operational relief while overestimating legal protection.
Key Takeaways
Related:Cloud Sovereignty Becomes a Boardroom Issue/Who Is Liable When an AI Agent Acts?
What is a Managed Security Service? A Managed Security Service transfers selected security tasks to a specialized provider, known as a Managed Security Service Provider. Typical services include round-the-clock monitoring, threat detection, and initial incident response. The provider supplies technology, processes, and expert staff that a single company often cannot maintain on a permanent basis.
The familiar pattern goes like this: there’s a CISO, so security is taken care of. This pattern has lost its footing with the implementation of NIS2. The directive explicitly obliges governing bodies to approve risk measures, monitor their implementation, and undergo training themselves. It does not name the CISO as the addressee; instead, it addresses the executive management. With NIS2, security shifts from a functional role into the realm of leadership responsibility.
In Germany, this requirement has been in force since December 2025 through the national implementation law. It provides for personal fines for members of the executive level, capped at half a million euros, and in severe cases, a temporary ban on managerial activity. Those who read this as mere red tape are underestimating its impact. Personal liability reshapes executive priorities more profoundly than additional training formats ever could.
This is where the misunderstanding arises. Many organizations respond to the pressure by hiring a service provider and consider the issue resolved. You can outsource operations, but the duty to know what is being secured – and whether the measures are effective – remains with leadership. A contract with a provider is not an exclusion of liability; it’s a tool that must be actively managed.
Managed Security Services are growing because the operational gap is real. Sixty percent of security managers now cite the skills shortage as their biggest concern, ahead of sheer headcount. In the EU alone, around 300,000 skilled workers are missing. A continuously staffed in-house Security Operations Center is simply unaffordable for most companies below conglomerate size.
This gap is sensibly filled by a service provider. They pool scarce experts across many customers and operate round-the-clock monitoring that a single company can rarely sustain long-term. Crucially, though, is the clear division between what can be outsourced and what must remain in-house.
| Function | Best Handled by MSSP | Remains In-house |
|---|---|---|
| 24/7 monitoring | Yes, leveraging economies of scale | Escalation paths |
| Threat detection | Yes, tools and processes | Business context |
| Security strategy | No, only advisory | Full ownership |
| Compliance evidence | Supporting documentation | Executive accountability |
| Liability under NIS2 | Not transferable | Fully retained in-house |
The final row decides the model. A provider can take over the work, supply the evidence and react quickly in an emergency. The duty to demonstrate to regulators that appropriate measures were decided and monitored rests with the executive team itself. Overlook this line and you’ve outsourced while believing you’re covered.
The separation leads to a sober operating model. Security leadership stays in-house, often as a CISO or, in smaller firms, as an outsourced virtual CISO with a clear mandate. They define what needs protecting, with what priority and against which risks. The provider then implements these directives in operations and reports back.
For this model to hold, two prerequisites – often missing in governance – are essential. First, an internal owner with both mandate and time to steer the provider. An MSSP without a counterpart in-house delivers reports that nobody reads. Second, clearly defined escalation routes. When an attack strikes at 3 a.m., it must be settled in advance who decides internally and who gets notified. That call cannot be made during the incident.
Whether a managed security service brings relief or creates a new risk depends less on the provider than on your own preparation. The following patterns separate one from the other.
The difference between the columns isn’t a matter of budget. It’s a matter of clarity about what you’re actually buying. A managed security service is an extension of your security operations, not a substitute for executive decision-making. Treat it as such, and you’ll gain real relief. Expect more, and you’ll buy risk with an invoice.
No. NIS2 holds the governing bodies personally liable for approving and monitoring security measures. Operational tasks can be delegated to a Managed Security Service Provider, but responsibility and liability remain with management. A contract is not an exclusion of liability.
Especially when a continuously staffed in-house Security Operations Center is unaffordable and a skills shortage prevents internal coverage. The provider consolidates scarce expertise and delivers 24/7 monitoring. For companies below corporate scale, this is often the only realistic path to robust operations.
The security strategy, management of the provider, definition of escalation paths, and compliance evidence for regulators. One internal person with authority is needed to oversee the provider. Without this counterpart, the provider’s reports remain ineffective.
A virtual CISO is an outsourced security leadership role operating on a mandate basis rather than as a full-time employee. For smaller companies unable to fund a dedicated CISO, it brings leadership competence in-house. A clear mandate is essential so the role can steer – not just advise.
Who in-house will oversee this provider, and what evidence will they receive for our compliance report? If the answer isn’t settled before signing, outsourcing lacks a counterpart. The contract then shifts the problem rather than solving it.
Read more on Digital Chiefs
Digital ChiefsTechnical Debt: Why the Board Must Act NowDigital ChiefsData Spaces: Where Smart Industry and Smart City ConvergeDigital ChiefsZero Trust Requires Process Knowledge, Not Just ToolsMore from the MBF Media Network
Image source: AI-generated (June 2026)