05.06.2026
8 min read

In many companies, the CISO is seen as the person responsible for security. This view only appears to relieve the executive board. Since the NIS2 Directive, responsibility now explicitly rests with the management bodies and cannot be delegated away. Managed Security Services address capacity issues, not liability issues. Those who confuse the two buy operational relief while overestimating legal protection.

Key Takeaways

  • Responsibility cannot be delegated. NIS2 requires the executive board to personally approve and monitor security measures. While they may outsource operations, liability remains in-house.
  • The MSSP provides capacity, not mandate. An external provider delivers continuous monitoring and scarce expertise. Security strategy and its governance remain in-house.
  • Outsourcing only works with internal governance. Strategy and accountability stay internal; operations and scaling can go external. Drawing this line cleanly brings relief without loss of control.

Related:Cloud Sovereignty Becomes a Boardroom Issue/Who Is Liable When an AI Agent Acts?

Why liability is shifting away from the CISO role

What is a Managed Security Service? A Managed Security Service transfers selected security tasks to a specialized provider, known as a Managed Security Service Provider. Typical services include round-the-clock monitoring, threat detection, and initial incident response. The provider supplies technology, processes, and expert staff that a single company often cannot maintain on a permanent basis.

The familiar pattern goes like this: there’s a CISO, so security is taken care of. This pattern has lost its footing with the implementation of NIS2. The directive explicitly obliges governing bodies to approve risk measures, monitor their implementation, and undergo training themselves. It does not name the CISO as the addressee; instead, it addresses the executive management. With NIS2, security shifts from a functional role into the realm of leadership responsibility.

In Germany, this requirement has been in force since December 2025 through the national implementation law. It provides for personal fines for members of the executive level, capped at half a million euros, and in severe cases, a temporary ban on managerial activity. Those who read this as mere red tape are underestimating its impact. Personal liability reshapes executive priorities more profoundly than additional training formats ever could.

500.000 Euro
personal fine that executive management may face under the German NIS2 implementation law, in addition to corporate penalties.
Source: NIS2 Implementation Act (NIS2UmsuCG), in force since December 2025

This is where the misunderstanding arises. Many organizations respond to the pressure by hiring a service provider and consider the issue resolved. You can outsource operations, but the duty to know what is being secured – and whether the measures are effective – remains with leadership. A contract with a provider is not an exclusion of liability; it’s a tool that must be actively managed.

What the MSSP Handles and What Stays In-house

Managed Security Services are growing because the operational gap is real. Sixty percent of security managers now cite the skills shortage as their biggest concern, ahead of sheer headcount. In the EU alone, around 300,000 skilled workers are missing. A continuously staffed in-house Security Operations Center is simply unaffordable for most companies below conglomerate size.

This gap is sensibly filled by a service provider. They pool scarce experts across many customers and operate round-the-clock monitoring that a single company can rarely sustain long-term. Crucially, though, is the clear division between what can be outsourced and what must remain in-house.

Function Best Handled by MSSP Remains In-house
24/7 monitoring Yes, leveraging economies of scale Escalation paths
Threat detection Yes, tools and processes Business context
Security strategy No, only advisory Full ownership
Compliance evidence Supporting documentation Executive accountability
Liability under NIS2 Not transferable Fully retained in-house

The final row decides the model. A provider can take over the work, supply the evidence and react quickly in an emergency. The duty to demonstrate to regulators that appropriate measures were decided and monitored rests with the executive team itself. Overlook this line and you’ve outsourced while believing you’re covered.

How Hybrid Control Works Without Losing Oversight

The separation leads to a sober operating model. Security leadership stays in-house, often as a CISO or, in smaller firms, as an outsourced virtual CISO with a clear mandate. They define what needs protecting, with what priority and against which risks. The provider then implements these directives in operations and reports back.

For this model to hold, two prerequisites – often missing in governance – are essential. First, an internal owner with both mandate and time to steer the provider. An MSSP without a counterpart in-house delivers reports that nobody reads. Second, clearly defined escalation routes. When an attack strikes at 3 a.m., it must be settled in advance who decides internally and who gets notified. That call cannot be made during the incident.

Where outsourcing helps – and where it holds you back

Whether a managed security service brings relief or creates a new risk depends less on the provider than on your own preparation. The following patterns separate one from the other.

What holds you back
  • Outsourcing under the assumption that liability disappears with it
  • No internal stakeholder responsible for managing the provider
  • Escalation paths defined only during an active incident
  • Contract without clear reporting and evidence requirements
What helps
  • Strategy and accountability remain visible in-house
  • A designated point of contact with authority over the provider
  • Escalation paths defined and tested in advance
  • Contracts that deliver proof for compliance verification

The difference between the columns isn’t a matter of budget. It’s a matter of clarity about what you’re actually buying. A managed security service is an extension of your security operations, not a substitute for executive decision-making. Treat it as such, and you’ll gain real relief. Expect more, and you’ll buy risk with an invoice.

Frequently Asked Questions

Can a company outsource its NIS2 liability to a service provider?

No. NIS2 holds the governing bodies personally liable for approving and monitoring security measures. Operational tasks can be delegated to a Managed Security Service Provider, but responsibility and liability remain with management. A contract is not an exclusion of liability.

When is a Managed Security Service worthwhile?

Especially when a continuously staffed in-house Security Operations Center is unaffordable and a skills shortage prevents internal coverage. The provider consolidates scarce expertise and delivers 24/7 monitoring. For companies below corporate scale, this is often the only realistic path to robust operations.

What must remain in-house despite outsourcing?

The security strategy, management of the provider, definition of escalation paths, and compliance evidence for regulators. One internal person with authority is needed to oversee the provider. Without this counterpart, the provider’s reports remain ineffective.

What is a virtual CISO?

A virtual CISO is an outsourced security leadership role operating on a mandate basis rather than as a full-time employee. For smaller companies unable to fund a dedicated CISO, it brings leadership competence in-house. A clear mandate is essential so the role can steer – not just advise.

Which question should come before every MSSP contract?

Who in-house will oversee this provider, and what evidence will they receive for our compliance report? If the answer isn’t settled before signing, outsourcing lacks a counterpart. The contract then shifts the problem rather than solving it.

Image source: AI-generated (June 2026)

Further Reading

Share this article:

Also available in

More Articles

18.07.2026

How to Stifle Open Source Without Banning It

Benedikt Langer

6 Min. Read The sharpest argument against China’s top open AI comes from a man at OpenAI. Dean Ball, ...

Read Article
17.07.2026

The data claim already applies to existing fleets

Benedikt Langer

9 Min. read time The right to access readily available product data has been in effect since September ...

Read Article
17.07.2026

NIS2 liability for management boards applies despite registration

Tobias Massow

9 Min. read time As of late May 2026, around 11,000 affected companies in Germany still lack BSI registration-and ...

Read Article
15.07.2026

Token-OPEX: Inference Controls, Not the Seat Budget

Angelika Beierlein

9 Min. read time Token costs aren’t a line item in SaaS contracts. They’re variable OPEX per workflow-and ...

Read Article
15.07.2026

Hardware Outperforms Software Deals – Rethinking Capital Expenditure Priorities

Benedikt Langer

9 Min. read time IBM reports a 7% decline in infrastructure for Q2, while distributed infrastructure ...

Read Article
14.07.2026

The Bill for Ten Years of Island Solutions

Benedikt Langer

8 min read For a decade, industry has bought point solutions: one system per machine, one standard per ...

Read Article
A magazine by Evernine Media GmbH