A CISO (Chief Information Security Officer) is the executive accountable for an organisation’s information security programme — risk prioritisation, control operation, incident readiness, and board reporting.

In Hong Kong SME contexts the title may be informal (IT manager + outsourced MSSP), but accountability still needs a named owner. HKISG materials that help CISOs brief leadership include the CISO AI Security Briefing and Board Briefing Pack. Public Trust Reviews assess organisational evidence — they do not appoint or certify individuals.