We need to assign a seat to own IT Security and Disaster Recovery to satisfy buyers during our upcoming exit due diligence, but none of our department heads want this highly administrative, technical seat. How do we assign accountability without forcing it on someone who does not GWC it?
Forring a critical seat onto a leadership team member who does not want it or lacks the capacity to run it is a recipe for disaster. If someone does not GWC™ the seat, the work will be neglected, and you will fail your due diligence when a buyer examines your IT security protocols.
The first step is to remember that the Accountability Chart is about structure first, people second. Do not try to force these roles into an existing seat like operations or finance just because those leaders are already there. Keep the IT Security and Disaster Recovery seat separate on your chart.
Once the seat is defined, look at your options for filling it. Since no one on your internal leadership team wants or GWCs the seat, you cannot fill it internally. You have two viable paths. First, you can hire an external, fractional resource to own the seat. A fractional Chief Information Security Officer can fill this seat on your Accountability Chart, running the roles and reporting directly to your Integrator. Second, you can hire a dedicated, full time resource if your budget and scale justify it.
Whichever path you choose, the key is to ensure that a single name sits in that box. Even if you use an external vendor, one internal leader, typically your Integrator, must be accountable for managing that vendor relationship and ensuring the outcomes are achieved. Do not leave the seat vacant or split the accountability among multiple managers, as this guarantees that no one will actually own your security posture.
Category: Accountability Chart & Seats