Technology and SaaS companies operate under a layered set of security obligations that arrive from three directions: voluntary frameworks that have become commercial baselines, regulatory requirements tied to the data they handle, and contractual obligations embedded in customer agreements. Leadership is accountable for meeting these obligations, yet many organizations lack a clear owner, a coherent sequence for compliance, or a reliable way to measure progress.

This article explains what those obligations are, where they originate, who inside the organization should own them, and what adequate leadership looks like in practice.

What the Obligations Are

Technology and SaaS providers face obligations in three overlapping categories: framework alignment, regulatory compliance and commercial requirements.

The NIST Cybersecurity Framework (CSF) 2.0 is a voluntary tool designed to help organizations reduce cybersecurity risks. While voluntary, the CSF has become a commercial baseline. Customers, auditors and investors increasingly expect technology providers to demonstrate alignment with its five core functions: Govern, Identify, Protect, Detect, Respond and Recover. The framework does not prescribe specific controls, but it does establish outcomes that leadership must be able to articulate and measure.

The NIST Privacy Framework (PF) 1.1 is a companion tool intended to help organizations identify and manage privacy risk. It is structured around similar principles and is designed to integrate with enterprise risk management. Technology companies that collect, process or store personal data are expected to demonstrate privacy risk management, even where no specific regulation applies.

The Federal Trade Commission (FTC) enforces obligations under Section 5 of the FTC Act, which prohibits unfair and deceptive acts. For technology companies, this means two things: if you make privacy or security promises, the FTC requires you to honor them. If you do not make specific claims, you still have an obligation to maintain security appropriate to the nature of the data you possess. The FTC has pursued enforcement actions against companies that failed to implement reasonable security practices, regardless of whether a formal promise was made.

If your company handles specific categories of data, additional regulations apply. The Children's Online Privacy Protection Act (COPPA) governs what websites can collect from children and requires verifiable parental consent. The Gramm-Leach-Bliley Act applies to financial institutions and requires them to explain information-sharing practices and safeguard sensitive data. The Health Breach Notification Rule applies to certain health apps and connected devices, requiring specific steps following a breach. The Fair Credit Reporting Act governs the use, reporting and disposal of consumer credit information.

Technology companies that transfer data internationally face additional obligations. The EU-U.S. Data Privacy Framework, which became effective in July 2023, provides a mechanism for companies to transfer personal data from the EU to the United States. Participation is voluntary, but companies that self-certify must comply with the Data Privacy Framework Principles. Failure to comply may violate Section 5 of the FTC Act. The FTC enforces these obligations and works with EU privacy authorities.

Contractual obligations appear in customer agreements, particularly with enterprise buyers and regulated industries. These often require specific certifications, audit rights, incident notification timelines and evidence of a formal security program. Failure to meet these obligations can trigger breach-of-contract claims, liability and loss of revenue.

Why This Matters Now

The landscape has changed in two significant ways. First, what was once voluntary has become expected. The NIST Cybersecurity Framework and Privacy Framework were designed as voluntary tools, but they are now embedded in procurement requirements, insurance applications and investor due diligence. Technology companies that cannot demonstrate alignment face commercial disadvantage.

Second, regulatory enforcement has intensified. The FTC has made clear that even companies without formal privacy policies have an obligation to maintain reasonable security. Enforcement actions are public, costly and reputationally damaging. Leadership cannot defer these obligations to the IT function and assume compliance.

The consequences of inadequate management are threefold: regulatory action, contractual liability and commercial exclusion. Any of these can be material to the business.

Who Owns This Inside the Organization

These obligations are not technical tasks. They are governance responsibilities that belong to executive leadership. The chief executive and the board are accountable for the organization's risk posture, regulatory compliance and contractual performance. That accountability cannot be delegated, though the work can and must be.

Adequate ownership requires a named executive with authority to make risk decisions, allocate resources and report to the board. In larger organizations, this is typically a Chief Information Security Officer (CISO). In technology and SaaS companies that have not yet reached the scale to justify a full-time security executive, the function is often distributed across the CTO, general counsel and COO, with no single owner and no coherent reporting line.

This is the gap where obligations go unmet. The CTO understands the infrastructure but may not track regulatory developments. General counsel understands contractual liability but may not have visibility into the technical controls. The COO manages operational risk but may not understand the security implications of a new product feature. Without a single executive accountable for the program, work happens reactively, inconsistently and without a way to measure progress.

For organizations facing this gap, [virtual CISO (vCISO) leadership](/vciso/) provides executive ownership of the security program without the cost or commitment of a full-time hire. A vCISO establishes governance, makes risk decisions, aligns the program with regulatory obligations and reports to leadership in business terms.

What Adequate Leadership Looks Like

Adequate leadership over security obligations means five things in practice.

First, there is a named executive accountable for the program. The board and the CEO know who owns security and privacy risk, and that person has authority to make decisions and allocate budget.

Second, there is a documented risk position. The organization has identified which frameworks and regulations apply, assessed current compliance, and documented residual risk in terms leadership can act on. This is not a penetration test report. It is a statement of what the organization is exposed to and why.

Third, there is a governance structure. Policies exist, they are maintained, and there is a process for updating them as the business or regulatory environment changes. Someone is responsible for ensuring that what is written matches what is practiced.

Fourth, there is regular reporting to executive leadership and the board. Security and privacy risk are discussed in business terms, with clear decisions about what risks are accepted, mitigated or transferred. Leadership is not surprised by audit findings, regulatory inquiries or customer questions.

Fifth, there is a plan with measurable progress. The organization knows what needs to be done, in what sequence, and can demonstrate movement over time. This is not a compliance checklist. It is a roadmap tied to business priorities.

What Leadership Should Do Next

If your organization lacks clear ownership of security and privacy obligations, start by answering three questions.

First, who is accountable? Not who does the work, but who makes the risk decisions, reports to the board and owns the outcome. If the answer is unclear or spans multiple people, the gap exists.

Second, what obligations apply? Review the frameworks, regulations and contractual commitments that govern your business. If you are uncertain which apply or what they require, that uncertainty is itself a risk.

Third, can you demonstrate compliance? Not whether you believe you are compliant, but whether you can produce evidence that a customer, auditor or regulator would accept. If you cannot, you have work to do.

Once those questions are answered, the path forward depends on the scale of the gap. If you have a named owner and a documented program, the work is operational. If you do not, the work is structural. You need executive leadership before you need tools or services.

Heights provides virtual CISO leadership to organizations that need executive ownership of security and privacy obligations without a full-time hire. If you are uncertain whether your current structure is adequate, a confidential consultation can help clarify the gap and the options for closing it. That consultation is offered once, at the point where the decision matters. Contact Heights to arrange it.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Talk this through with us

If this raises a question about your own organization, a confidential conversation is the fastest way to get a straight answer.

Schedule a Confidential Consultation