Empty board table with unused stop lever, key, silent handset and sealed folder — Motto x Beyond Chiefs

When the CISO Search Fails: Who Holds the Four Security Exits While the Seat Is Empty

A failed CISO search leaves four security exits unnamed — stop, override, incident command, written risk acceptance. Recovery starts by naming who holds each while the seat is empty. The next CV is not the first decision. Neither the German Stock Corporation Act nor § 38 BSIG creates a statutory CISO right.

Christian Pobbig and Beyond Chiefs work from Hamburg on AI Executive Search in DACH. This is not a hire guide. The worked example is a German AG, not Austria or Switzerland, and not every GmbH.

Management does not pause because the title is empty

The Vorstand manages the company under its own responsibility. Only a natural person can sit on it (§ 76 (1) and (3) sentence 1 AktG). A CISO title is not a Vorstand seat. An empty CISO title does not move management and does not pause it.

What is empty is four security exits, not the title

BC frame (INFERENCE). While the title is empty, the Vorstand or Geschäftsführung names in writing who may:

  1. Stop a release, a change, or a connection.
  2. Override an operator decision that would leave a known exposure in place.
  3. Incident command — classify, and if in scope release the filing the entity still owes.
  4. Written risk acceptance — residual risk recorded; the organ accepts or overrules. The organ remains the final decider on residual-risk acceptance.

That is organisational practice, not a statutory veto. Double-hatting the IT lead or the organ “until we find someone” is the failure mode, not the protocol. Interim without those four names repeats the original error and is not the first decision.

The first written act is who holds the four exits tonight

The first writing after the failed search is that naming — not a new brief. An unnamed picture of residual risk, or a picture filtered only through the CIO, is an information-basis problem: the duty of care assumes the Vorstand member could reasonably believe they were acting on adequate information for the good of the company (§ 93 (1) AktG). No holding that a given CISO line is unlawful. No statutory CISO on the Vorstand. ISB and CISO are not the same.

If the entity is in scope, the clock does not wait for the ISB

§ 38 BSIG applies to management of particularly important and important entities: they implement the § 30 risk-management measures and monitor that implementation; members regularly attend training so they can recognise and assess IT-security risks (§ 38 BSIG). It is silent on a CISO office, a veto, a reporting line, and any duty to refill a failed search. A failed search does not pause subsection 1. NIS2 Article 20 is the parent of that organ duty — approve, oversee, liability, training — not a CISO title rule (Directive (EU) 2022/2555).

On a significant incident the entity — not the empty seat — owes an early notice without undue delay, at the latest within 24 hours of knowledge, and an incident report within 72 hours; a closing report follows at the latest one month after that notification. The duty applies at the earliest once the reporting path exists (§ 32 BSIG). BSI treats knowledge as the moment an employee of the entity, during working time, learns of the incident — not when the ISB is told, and not when the CISO seat is filled. Responsibility for the filing stays with the entity (BSI, NIS-2 reporting).

Those are external clocks for in-scope entities, not an internal recovery calendar. Outside particularly important and important entities they do not run. Who classifies and who releases the filing still has to be named if the clock is running. Operational work may be delegated; overall responsibility and supervision stay with management (BSI management briefing).

The organ decides residual risk in writing — no CISO duty, no refill duty

The statute creates no CISO right and no duty to rerun the search. Where the legislator wanted a named coordinator, it wrote one: the head of the BSI performs the tasks of the federal coordinator for information security (§ 48 (1) BSIG). On 22 July 2026 the BSI named Claudia Plattner CISO Bund for the federal administration — the seat is filled, not an empty public office, and § 48 does not staff a GmbH (BSI, 22 Jul 2026).

UK practice, not German law: “CISO (or equivalent)” and board dialogue do not turn a supervisory board into incident command (UK DSIT). The Aufsichtsrat does not become incident command. A double hat is not the cure.

The page on when the four exits must leave the CIO span is a different moment. The page on AI judgment in the CIO seat is not a security vacancy. Same organ logic, separate contracts.

FAQ

### Must the search restart at once?

No. The first decision is who holds the four exits tonight. Search may follow.

### Does the vacancy make the CEO a statutory CISO?

No. The vacancy grants no new stop right. It only forces the existing organ duties not to stay unnamed.

### Does § 32 apply to every house?

No. Only to particularly important and important entities, and at the earliest once the reporting path exists.

---

Draft. Not live without Christian. No service CTA.

Recent Blog Posts

Empty board table, blank minutes, unused violet stop ring

Agentic AI: five questions the board must ask

Team Beyond Chiefs
Read More
Open blank evidence binder with unused purple wax seal and pen — Motto x Beyond Chiefs

AI Act Article 4: What Management Must Be Able to Prove About AI Literacy

Team Beyond Chiefs
Read More

AI Agents: Transforming Global Business in 2025 | Complete Guide

AI as CEO? 6 Costly Misconceptions About AI Leadership That Companies Must Avoid

CONTACT Us

Leading the Future with AI-Driven Leadership

contact us