## Purpose

This document defines the main cybersecurity responsibilities within the company.

One person may perform several roles in a smaller company. The important point is that each responsibility has a clear owner.

## Leadership

**Leadership is responsible for:**

- Approving cybersecurity priorities
- Providing appropriate resources
- Reviewing significant cyber risks
- Approving major risk acceptance decisions
- Supporting incident response decisions
- Ensuring cybersecurity is treated as a business responsibility

Primary owner: ____________________

Backup: ____________________

## Cybersecurity Coordinator

**The cybersecurity coordinator is responsible for:**

- Coordinating the cybersecurity playbook
- Maintaining the Master Action Tracker
- Coordinating risk reviews
- Following up on security actions
- Coordinating incident preparedness
- Maintaining key security contacts
- Preparing leadership updates

Primary owner: ____________________

Backup: ____________________

## IT / Technical Owner

**The IT or technical owner is responsible for:**

- Device and system security
- Patch management
- Endpoint protection
- Secure configuration
- Account administration
- MFA implementation
- Logging and monitoring
- Backup operations
- Technical incident containment and recovery

Primary owner: ____________________

Backup / MSP: ____________________

## Data and System Owners

**Business owners of important systems and data are responsible for:**

- Confirming who requires access
- Approving access where appropriate
- Reviewing access periodically
- Identifying business criticality
- Supporting recovery priorities
- Confirming restored systems work correctly

System / data owners should be recorded in the relevant inventory.

## HR

**HR is responsible for supporting:**

- Employee onboarding
- Employee offboarding
- Role changes
- Security training coordination
- Employee-related incident handling
- Insider threat escalation where appropriate

HR owner: ____________________

## Finance

**Finance is responsible for:**

- Payment verification controls
- Bank-detail change verification
- Financial system access approval
- Fraud escalation
- Supporting investigation of payment-related incidents

Finance owner: ____________________

## Managers

**Managers are responsible for:**

- Approving appropriate employee access
- Reporting role changes promptly
- Supporting secure onboarding and offboarding
- Escalating suspicious activity
- Preventing unsafe workarounds
- Reinforcing cybersecurity expectations with their teams

## Employees and Contractors

**All users are responsible for:**

- Protecting credentials
- Using MFA correctly
- Using approved systems and tools
- Handling data appropriately
- Keeping devices secure
- Following security procedures
- Reporting suspicious activity promptly
- Reporting security mistakes immediately

## Vendor / MSP Owner

A named internal person should own important third-party relationships.

**Responsibilities include:**

- Approving vendor access
- Knowing what systems the vendor can access
- Maintaining vendor contacts
- Reviewing vendor access
- Confirming access is removed when no longer required
- Escalating vendor-related security issues

Owner: ____________________

## Incident Response Lead

**The incident response lead is responsible for:**

- Activating the incident response process
- Coordinating triage
- Maintaining the incident record
- Coordinating containment
- Escalating to leadership
- Managing external technical support
- Ensuring decisions are documented
- Handing the incident into recovery and review

Primary incident lead: ____________________

Backup incident lead: ____________________

## Recovery Lead

**The recovery lead is responsible for:**

- Coordinating restoration
- Following recovery priorities
- Confirming trusted restore sources
- Coordinating technical and business validation
- Tracking recovery status
- Handing completed recovery into post-incident review

Primary recovery lead: ____________________

Backup: ____________________

## Security Awareness Owner

**The security awareness owner is responsible for:**

- Planning employee training
- Tracking completion
- Coordinating role-based training
- Running or arranging simulations and exercises
- Updating training after incidents and near misses

Owner: ____________________

## Review Frequency

**Cybersecurity ownership should be reviewed:**

- At least annually
- When key personnel change
- When the MSP or major vendors change
- After significant incidents
- When important business systems or responsibilities change

## Practical Rule

Every important cybersecurity responsibility should have one clearly accountable person and a backup wherever practical.
