Cybersecurity stakeholders are the people, groups and organisations that influence cyber risk, own or depend on digital assets, implement security controls, respond to incidents, or may be affected when systems or data are compromised.
Cybersecurity is not owned by the security team alone. A cyber project may involve senior leaders deciding risk appetite, business teams owning critical services, technical teams protecting systems, employees using those systems, suppliers providing important technology, and legal, communications and regulatory stakeholders who become essential when an incident occurs.
Table of Contents:
- Cybersecurity stakeholder list
- 1. Govern: leadership, ownership and cyber risk
- 2. Identify: assets, systems, data and dependencies
- 3. Protect: people who design and operate controls
- 4. Detect: monitoring and threat stakeholders
- 5. Respond: cyber incident stakeholders
- 6. Recover: continuity and restoration stakeholders
- Users, customers and people affected
- Suppliers, partners and external stakeholders
- Example cybersecurity stakeholder list
- Cybersecurity stakeholders that are often missed
- Questions to identify cybersecurity stakeholders
- Quick cybersecurity stakeholder checklist
- What to do next
Cybersecurity stakeholder list
The groups below follow the Govern, Identify, Protect, Detect, Respond and Recover lifecycle used by the NIST Cybersecurity Framework 2.0. This is useful for stakeholder identification because it prompts you to look beyond the people who install security controls and include decision-makers, business owners, incident teams, suppliers and recovery stakeholders.
Create your own cybersecurity stakeholder list
Tick the stakeholders that apply to your organisation, cyber programme or security project. You can select them all, clear the list, download your selection as an Excel workbook, or copy it ready to paste into Google Sheets.
The Excel file is created on your device. The spreadsheet library is loaded only when you click Download Excel, so it does not add to the initial page load. The workbook also contains a Resources worksheet with useful StakeholderMap.com links.
Govern
- Board and directors
- Executive sponsor
- Chief Information Security Officer (CISO)
- Chief Information Officer (CIO)
- Chief Technology Officer (CTO)
- Business owners
- Enterprise risk management
- Cyber risk or security governance committee
- Finance and budget owners
- Procurement
- Legal
- Compliance
- Data protection and privacy
- Internal audit
Identify
- Asset owners
- System owners
- Application owners
- Service owners
- Data owners
- Data stewards
- Enterprise architects
- Solution architects
- Network and infrastructure teams
- Cloud platform owners
- Configuration and asset management teams
- Vulnerability management
- Third-party risk management
- Business continuity teams
Protect
- Security architects
- Security engineers
- Identity and access management (IAM)
- Network security
- Cloud security
- Endpoint security
- Application security
- DevSecOps teams
- Software developers
- Database administrators
- IT operations
- Backup administrators
- Security awareness and training teams
- Human Resources
Detect
- Security Operations Centre (SOC)
- Security analysts
- Security monitoring teams
- Threat intelligence teams
- Threat hunting teams
- SIEM and logging platform owners
- Fraud teams
- Network operations centre
- Managed detection and response provider
- Managed security service provider
Respond
- Cyber Security Incident Response Team (CSIRT)
- Incident manager
- Technical incident lead
- Digital forensics specialists
- Security analysts
- IT infrastructure teams
- Application support
- Legal team
- Data Protection Officer
- Corporate communications and PR
- Customer services
- Human Resources
- Senior management
- Cyber insurance contacts
Recover
- Business continuity management
- Disaster recovery teams
- Service owners
- Business process owners
- IT infrastructure and cloud teams
- Backup and recovery teams
- Application owners
- Supplier support teams
- Facilities and physical security
- Finance
- Communications
- Customer services
- Senior leadership
- Post-incident review owners
1. Govern: leadership, ownership and cyber risk
Cybersecurity starts with decisions about responsibility and acceptable risk. Governance stakeholders decide what must be protected, how much risk the organisation is prepared to accept, where money should be invested and who is accountable for cyber outcomes.
Board and directors
Boards and directors need enough visibility of cyber risk to challenge management, understand material exposures and make decisions about priorities and investment. Cybersecurity should therefore be connected to organisational governance rather than treated as a purely technical issue.
Executive sponsor
A major cyber programme or security improvement project often needs an executive sponsor who can secure resources, resolve cross-functional issues and support changes that affect the wider organisation.
CISO, CIO and CTO
The CISO normally leads or coordinates the organisation's security strategy and risk approach. The CIO and CTO may own much of the technology estate on which that strategy depends, so responsibilities and decision rights need to be clear.
Business owners
Business owners understand the services, processes and information that matter to customers and operations. They help security teams judge the real business impact of a cyber risk rather than looking only at technical severity.
Risk, legal, compliance, privacy and audit
These stakeholders help connect cybersecurity with enterprise risk, contractual duties, privacy obligations, regulatory expectations and independent assurance.
2. Identify: assets, systems, data and dependencies
You cannot manage cyber risk effectively without knowing what the organisation depends on. Identification stakeholders know where important assets are, who owns them, how they connect and what would happen if they became unavailable or untrustworthy.
Asset, system, application and service owners
Owners help establish which systems are critical, who relies on them, what information they process and which security decisions require business approval.
Data owners and stewards
Data stakeholders understand the sensitivity, use, retention and business importance of information. They may also know which systems and suppliers create, store or exchange that data.
Architecture, infrastructure and cloud teams
Architects and platform teams understand technical dependencies that may not be obvious from an organisational chart, including shared services, integrations, identity platforms, networks and cloud environments.
Vulnerability and third-party risk teams
These stakeholders identify weaknesses and external dependencies that can change the organisation's exposure, including suppliers with privileged access or technology that supports critical services.
3. Protect: people who design and operate controls
Protection stakeholders design, implement and maintain safeguards intended to reduce the likelihood or impact of cyber incidents.
Security architects and engineers
Security architects translate risk requirements into technical design. Security engineers implement and operate controls across infrastructure, applications, identities and data.
Identity and access management
IAM teams manage how users, administrators, services and suppliers gain access to systems. They are particularly important where projects change authentication, privileges or joiner-mover-leaver processes.
Network, cloud, endpoint and application security
These teams protect different parts of the technology estate and often need to coordinate changes rather than implement controls independently.
Developers and DevSecOps
Software teams are cybersecurity stakeholders whenever systems are developed, configured or integrated. Security requirements may affect architecture, code, deployment pipelines, secrets, dependencies and release processes.
Employees, HR and security awareness
Employees are part of the organisation's security environment. HR and awareness teams can be important when controls affect onboarding, training, acceptable use, access changes or disciplinary processes.
4. Detect: monitoring and threat stakeholders
Detection stakeholders identify unusual behaviour, investigate alerts and help the organisation understand whether an event is an error, misuse or genuine security incident.
Security Operations Centre and security analysts
SOC teams monitor systems and investigate alerts. They need access to useful logs, clear escalation routes and enough context to understand what normal behaviour looks like for important services.
Threat intelligence and threat hunting
These specialists help the organisation understand relevant threats and look proactively for signs of compromise that may not have triggered standard alerts.
Managed security providers
Where monitoring or detection is outsourced, the managed provider becomes a key stakeholder. Responsibilities for escalation, evidence, communication and handover should be clear before an incident happens.
5. Respond: cyber incident stakeholders
A serious cyber incident quickly becomes an organisational issue rather than a security-team issue. Technical containment may happen alongside legal decisions, customer communications, regulatory reporting, workforce management and executive crisis decisions.
Cyber incident response is cross-functional
Your stakeholder map should identify the people needed during an incident before the incident happens. Include decision-makers, technical responders, business continuity, legal, privacy, communications, HR and customer-facing teams as appropriate.
CSIRT, incident manager and technical lead
The incident response team coordinates the investigation and response. A clear incident manager or central coordinator helps keep technical findings, actions, decisions and communications aligned.
Legal, privacy and compliance
These teams may need to assess contractual duties, evidence handling, privacy impacts, notification requirements and communications with regulators or other authorities.
Communications, PR and customer services
If customers, staff, partners or the public are affected, communications stakeholders need accurate information and a clear route to the incident team. Customer-service teams may also experience a sudden increase in enquiries.
Senior management
Senior leaders may need to make decisions about shutting down services, switching to manual workarounds, notifying important stakeholders, accepting temporary risk or funding urgent recovery work.
- crisis management team;
- business continuity lead;
- law enforcement contacts where appropriate;
- regulators or supervisory authorities;
- cyber insurance broker or insurer;
- external incident response specialists;
- external legal advisers; and
- critical suppliers and partners.
6. Recover: continuity and restoration stakeholders
Recovery is about restoring important services safely and in the right order. The fastest technical recovery is not always the best business recovery, so service owners and business continuity stakeholders need to be involved.
Business continuity and disaster recovery
These teams coordinate alternative processes, recovery priorities, dependencies and return-to-service plans.
Service and business process owners
Owners help determine which services should be restored first and what level of degraded operation is acceptable while recovery continues.
Infrastructure, cloud, application and backup teams
Technical recovery may depend on clean environments, restored identities, backups, supplier support, rebuilt applications and validation that systems are safe to reconnect.
Post-incident review owners
After recovery, someone needs to coordinate lessons learned, actions and accountability so the organisation actually improves rather than simply returns to normal operations.
Users, customers and people affected by cybersecurity
Cybersecurity projects can affect people who are not members of the security or IT teams. New controls may change how employees work, while cyber incidents can affect customers, partners, patients, students, citizens or other people whose services or information depend on the organisation.
- employees;
- system users;
- privileged users and administrators;
- remote workers;
- contractors;
- customers;
- clients;
- members of the public;
- people whose personal data is held;
- business partners;
- employee representatives or trade unions;
- accessibility and inclusion specialists; and
- people who depend on critical services.
Suppliers, partners and external cybersecurity stakeholders
Cyber risk often crosses organisational boundaries. Suppliers may host systems, process data, provide remote support, manage security services or supply software and hardware that becomes part of the organisation's attack surface.
- cloud service providers;
- Software as a Service (SaaS) providers;
- managed service providers;
- managed security service providers;
- managed detection and response providers;
- software vendors;
- hardware vendors;
- telecommunications providers;
- payment providers;
- data processors;
- outsourcing partners;
- security consultants;
- penetration testing and assurance providers;
- external auditors;
- incident response providers;
- cyber insurers and brokers;
- industry bodies and information-sharing groups;
- regulators;
- law enforcement; and
- critical customers and business partners.
Example: stakeholders for a ransomware resilience programme
Imagine an organisation launches a programme to reduce the operational impact of ransomware. The programme includes stronger identity controls, improved backups, better monitoring, incident exercises and recovery planning.
| Area | Example stakeholders |
|---|---|
| Govern | Board sponsor, CISO, CIO, business owners, enterprise risk, finance, legal and internal audit |
| Identify | Service owners, asset owners, data owners, architecture, infrastructure, cloud and third-party risk teams |
| Protect | IAM, endpoint security, network security, security engineering, IT operations, backup teams and HR |
| Detect | SOC, security analysts, threat intelligence, logging platform owners and managed detection provider |
| Respond | CSIRT, incident manager, IT, legal, privacy, communications, customer services and senior management |
| Recover | Business continuity, disaster recovery, service owners, infrastructure, applications, cloud, backups and suppliers |
| Affected | Employees, customers, partners and people whose information or access to services may be affected |
| External | Cloud providers, software vendors, incident response specialists, cyber insurer, regulators and critical partners |
Cybersecurity stakeholders that are often missed
Security teams, IT and senior management usually appear quickly on the stakeholder list. Before you finish, check specifically for:
- business owners of critical services;
- data owners and data stewards;
- identity and access management teams;
- backup and recovery teams;
- business continuity and disaster recovery;
- procurement and third-party risk management;
- suppliers with privileged or remote access;
- managed security and monitoring providers;
- developers and DevSecOps teams;
- HR and employee representatives;
- corporate communications and PR;
- customer-service teams;
- privacy and data protection;
- cyber insurance contacts;
- customers and partners affected by outages;
- people whose personal information is held; and
- post-incident action owners.
Questions to identify cybersecurity stakeholders
Work through your systems, risks and incident lifecycle rather than starting from a blank organisation chart.
Who governs cyber risk?
- Who is accountable for cybersecurity?
- Who decides how much cyber risk is acceptable?
- Who approves investment?
- Who owns enterprise risk, legal, privacy and compliance decisions?
- Who provides independent assurance?
What needs to be protected?
- Who owns critical services, systems and applications?
- Who owns important or sensitive data?
- Who understands technical dependencies?
- Which suppliers are essential to those services?
Who implements security?
- Who controls identities and privileged access?
- Who manages networks, cloud, endpoints and applications?
- Who develops or configures software?
- Who trains employees and manages security policies?
Who detects problems?
- Who monitors alerts and logs?
- Who investigates unusual behaviour?
- Who provides threat intelligence?
- Which monitoring services are outsourced?
Who responds when something goes wrong?
- Who coordinates the incident?
- Who contains and investigates it?
- Who makes critical business decisions?
- Who handles legal, privacy, regulatory and communications issues?
- Who communicates with customers, staff and partners?
Who restores services?
- Who decides recovery priorities?
- Who owns backups and restoration?
- Who provides technical and supplier support?
- Who decides when a service is safe to return?
- Who owns lessons learned and improvement actions?
Quick cybersecurity stakeholder checklist
- Board and directors
- Executive sponsor
- CISO
- CIO / CTO
- Business owners
- Enterprise risk management
- Legal and compliance
- Privacy / Data Protection Officer
- Internal audit
- Asset and system owners
- Data owners
- Architecture
- Infrastructure and cloud
- IAM
- Security architects and engineers
- Developers and DevSecOps
- IT operations
- Security awareness / HR
- SOC and security analysts
- Threat intelligence
- CSIRT and incident manager
- Digital forensics
- Business continuity
- Disaster recovery
- Backup and recovery teams
- Communications / PR
- Customer services
- Employees and system users
- Customers and people affected
- Procurement
- Third-party risk management
- Cloud and SaaS providers
- Managed security providers
- Critical suppliers and partners
- Cyber insurer
- Regulators
What to do next
Once you have identified your cybersecurity stakeholders, you can:
- add them to a stakeholder register;
- carry out a stakeholder analysis;
- identify who owns each important cyber risk, asset, control and recovery decision;
- create a stakeholder map;
- clarify who must be consulted or informed during a cyber incident; and
- plan how you will engage your stakeholders.
For related checklists, see IT project stakeholders, software development stakeholders, AI stakeholders and the 105 stakeholder checklist. You can also browse all specialist pages in the Stakeholder Lists hub.
Summary
A complete cybersecurity stakeholder list extends well beyond the CISO and security team. It should include the people who govern, identify, protect, detect, respond and recover, together with business owners, users, people affected, suppliers, partners, assurance teams and regulators.
Use the selectable checklist on this page to create a tailored list for your own organisation or project, then prioritise those stakeholders through stakeholder analysis.

