There is a person in your business who never applied for the security job but has it anyway. They know the wifi password. They keep the spare laptop in a drawer. When the copier vendor calls, they take it. When a new hire starts Monday, they are the one creating the email account at 7:30 in the morning. In most small businesses we work with in Denton County, that person is the office manager, the operations lead, or the owner’s right hand.
At a large company, that work belongs to a CISO, short for chief information security officer, a senior executive whose entire job is deciding how the business protects its information. You do not have one, and honestly you probably do not need one. What you have instead is a capable, non technical person holding a stack of decisions nobody wrote down. That is not a failure of leadership. It is the normal shape of a growing company. The failure is leaving that person there with no list and no public backing from the owner.
Name the Role Out Loud
The first fix costs nothing. Say it in a staff meeting, in plain words: “Dana handles accounts and access. If you need software, a login, or a device, you go through Dana.” Two sentences. Now the job exists officially instead of by accident, and everyone else stops guessing who to ask.
This matters more than it sounds. Until the role is named, your office manager is doing security work in the gaps between everything else, with no cover when someone pushes back. CISA’s Cyber Essentials Starter Kit puts the starting point squarely with leadership, advising leaders to approach cyber as a business risk and to develop a culture of awareness that encourages employees to make good choices online. That does not happen because a spreadsheet exists. It happens because the owner says it in front of people.
Responsibility Without Authority Is a Trap
Here is where most small businesses get it wrong. They hand over the responsibility and keep all the authority. Then they are surprised when things slip. If the person holding the keys cannot actually stop anything, they are not managing risk. They are absorbing blame. Four kinds of authority make the difference:
- The power to say no. If a manager wants a new app installed on twelve computers this afternoon, your office manager needs to be able to say “not until we look at it” without it turning into a fight they lose by default.
- The power to slow a payment down. This one is worth real money. The Federal Trade Commission advises small business staff to take five before responding to a suspicious message, and to verify by calling the client, company, or colleague at a phone number they know to be genuine. That call takes two minutes. It only happens if the person making it is allowed to delay a payment the owner appears to have requested.
- The power to spend a small amount of money. A password manager seat, a hardware security key, a replacement charger. Give them a standing limit so the safe option is never the slow option.
- The power to escalate directly. When something looks wrong, they call the owner directly. No chain of command between a problem and the person who can act on it.
The Short List They Should Actually Own
Ownership only works when the list is short and written down. Here is the list we hand to office managers, and it fits on one page:
- The account roster. A simple record of who has an account, in what system, and whether they still work here. CISA’s Cyber Essentials guidance recommends maintaining inventories of network connections including user accounts, vendors, and business partners.
- Onboarding and offboarding. New person gets exactly the access their job needs. Departing person loses all of it the same day. CISA recommends developing IT policies and procedures that address changes in user status such as transfers and terminations, which is the polite way of saying the biggest gap in most small businesses is the account of someone who left last spring.
- Access requests. CISA advises granting access and admin permissions based on need to know and least privilege, and asks the useful question of whether marketing really needs access to financial transactions. Your office manager should be the person who asks it.
- The approved software list. What tools we use, what we pay for, and what nobody should be signing up for on a company card. This is the single best defense against shadow IT, the tools your staff adopt quietly because the official option is annoying.
- The vendor sheet. Who to call for the phones, the internet, the accounting software, and your IT provider, with account numbers and who is authorized to make changes.
- The report channel. One clear answer to “I clicked something weird, who do I tell?” It should be their name, and the answer should never involve embarrassment.
What Should Never Land on Their Desk
Delegation goes wrong when it turns into abandonment. Some work a non technical person should not own, no matter how willing they are. Handing it over is not empowerment. It is setting someone up to fail quietly.
- Firewall and network configuration. This needs someone who does it every week, not someone reading a support article between phone calls.
- Proving backups actually restore. Confirming a backup ran is not the same as confirming it works. Testing a restore is technical work.
- Leading an incident. CISA advises leaders to drive development of an incident response and disaster recovery plan that outlines roles and responsibilities, and to test it often. Your office manager can be first to notice and first to call. They should not be alone in the room deciding what happens next.
- Signing off on insurance or contract security terms. The FTC recommends including security provisions in vendor contracts and establishing processes to confirm vendors follow your rules rather than taking their word for it. That is an owner decision.
How the Owner Backs Them Up in Public
Authority granted privately is not authority. The staff has to see it. A few specific moves, all of them free:
- Take the first loss yourself. The first time your office manager slows down one of your own requests, thank them where people can hear it. That single moment sets the rule better than any policy document.
- Never reverse them in front of the requester. If you disagree, take it offline. Overruling them publicly teaches everyone to route around them.
- Put it in the job description and pay for it. If it is real work, it belongs in the role and in the compensation conversation. Free extra duty is how good people quietly burn out.
- Give them a partner. They should have someone technical to call before they guess. That is the point of an outside IT provider, and it is why we treat the office manager as our primary contact.
The Bottom Line
Your office manager already is your CISO. The only question is whether they are doing that job with a list and authority, or doing it by accident with neither. Naming the role, handing over six specific responsibilities, keeping the deeply technical work with people who do it for a living, and backing them publicly is one meeting and one page. It is also one of the highest return changes available, because cybersecurity stopped being optional long before most companies got around to hiring for it.
If you want help writing that one page, we do this constantly. We will sit down with your office manager, sort out what belongs to them and what belongs to us, and give both of you something clear to work from. Contact us today.
Sources:

Comments are closed