Skip to content
atlas

Grey roles

Also known as: gray roles

Security jobs that sit between technology, management and people - coordinating and translating rather than hands-on engineering.

Draft - this entry has not been reviewed yet.

Formal

Broad, all-round roles in cyber and information security - such as coordinator, project lead, compliance, risk or awareness roles - whose main task is to connect technical specialists, leaders and staff, rather than to run or build systems.

In plain English

Like an interpreter at a meeting between two countries - not the expert on either side, but the reason the two sides understand each other.

In practice

After a test at a Danish housing association finds weak passwords, the person in a grey role turns the 40-page technical report into a one-page decision for the board and a plan the IT department can carry out.

Why it matters

Laws like NIS2 make leaders answerable for security, so organisations need people who can explain technical risk in business terms and keep the work moving.

Technical deep dive

"Grey roles" is not a term defined in any standard or competence framework; it is Danish training and labour-market shorthand for security positions that sit between the purely technical (engineering, operations, forensics) and the purely managerial or legal. The formal frameworks describe the same territory with different vocabulary, and mapping to them is how the roles are specified in job descriptions, training plans and procurement. The most relevant for Denmark is the European Cybersecurity Skills Framework (ECSF), published by ENISA in September 2022, which defines twelve role profiles, each with a mission, main tasks, key skills, knowledge, deliverables and e-competences mapped to the European e-Competence Framework (EN 16234-1).

Several ECSF profiles fall squarely in the grey zone: Cyber Legal, Policy and Compliance Officer (monitoring legal and regulatory requirements and ensuring compliance), Cybersecurity Risk Manager (managing the organisation's cybersecurity risks), Cybersecurity Auditor (assessing conformity against standards and regulation), Cybersecurity Educator (awareness and training programmes) and, at executive level, the Chief Information Security Officer. The US NICE Framework (NIST SP 800-181 Rev. 1 and its published work-role components) groups equivalent work roles under the Oversight and Governance category, including cybersecurity policy and planning, program management, privacy compliance and security awareness. The Danish course roles, such as information security coordinator and compliance and risk coordinator, typically combine parts of two or three of these profiles, which is realistic in small and medium organisations where one person covers what a large firm would split.

The core competence is translation across three registers. Downwards, regulatory text (NIS2 Art. 21, GDPR Art. 32, DORA articles) and standard clauses have to be decomposed into concrete, testable controls that IT operations can implement. Upwards, technical findings such as penetration-test results, vulnerability backlogs or log gaps have to be expressed as risk in business terms: likelihood, impact, cost and options, so that management can make and own decisions, as NIS2 Art. 20 requires. Sideways, the role coordinates HR, procurement, legal and suppliers. Typical artefacts are risk registers, statements of applicability, policies, roadmaps, board papers and supplier assessments.

The main failure mode is insufficient technical literacy. A coordinator who cannot judge whether "MFA implemented" covers administrative accounts, legacy protocols and service accounts will accept paper compliance and misreport risk. Conversely, specialists moved into grey roles without training in risk methods and regulation tend to produce technically correct but undecidable recommendations. Demand for these roles has grown with NIS2, DORA and the CRA, all of which require documented governance, management oversight and evidence, and none of which can be satisfied by technical controls alone.

What to learn first

Everything this builds on, foundations first.

  1. CIA triad
  2. →Compliance
  3. →Governance
  4. →Threat
  5. →Asset
  6. →Vulnerability
  7. →Impact
  8. →Likelihood
  9. →Risk
  10. →Risk management
  11. →Governance, risk and compliance (GRC)
  12. →Grey roles

Relationships

Used with
IT operations

Sources & further reading

Course material

  • Cyber Security Fast Track - Kursuskompendium, Formål med kurset

Reference works

  • ENISA - European Cybersecurity Skills Framework (ECSF)

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Check yourself

Loading…

Atlas is in beta.