833-847-3280
Schedule a Call

Cyber Security and IT: Separate Them

Small and mid-size companies frequently ask how to organize their cyber security assets and responsibilities to best protect their companies. This is more a question of function than of form, and it requires companies to challenge some assumptions about their IT departments as well as the perceptions of cyber security reports.
The immediate action taken by most corporate management teams is to make cyber security the responsibility of the IT shop. It seems a natural fit to place a highly technical and complex function under the direction of the IT Director or CIO.

But the real reason for this decision is that most corporate management teams have a minimal understanding of cyber security, nor dedicate the time it takes to learn it. This is a poorly designed organizational structure that can impede the flow of critical information to the C Suite due to conflictive responsibilities.

There are two key perceptions that need to be addressed. One, a report on cyber security gaps and vulnerabilities (not to mention a breach) is seen by the C-Suite as a damning display of improper planning and a larger threat to the existence of their business. Two, the same report on the cyber security status of an IT architecture is deemed pejorative by Senior IT personnel and seen as a threat to their position due to the exposure of cyber security gaps. This leads to dilution, or even non-disclosure, of key cyber security findings to the C Suite.

Both these perceptions are weak, yet extraordinarily ingrained in corporate management. The C-Suite should understand that most, if not all, IT systems that are connected to the internet are going to have some vulnerabilities and gaps due to flaws in software and applications, not just architecture. They also need to understand that there is a good possibility that they will be, or are, breached, and they need to better prepare to respond to that breach. In most cases, this is not the fault of IT management. Rather, an analysis of their system such as a vulnerability scan or a penetration test offers a chance for the IT director to open the discussion with the C-Suite on the appropriate measures, to include budget, technology, managed services, training etc, required to better prepare the company for a breach response. They should not “white wash” or minimize the results of a report or scan.

The solution: corporate C-Suites should become educated on cyber security threats and shift focus from defense to now identification and response in reaction to a breach. They should not have the unreasonable expectation that technology and training can protect themselves 100% — staff should be required to prepare both a disaster response and crisis response plan. Finally, separate cyber security and IT, placing cyber security either under another C-Suite position due to its criticality or have it report to security where the conflict between reporting cyber security issues and their impact on the IT department does not impede the flow of critical information. These steps will go far in ensuring that cyber security remains a priority and does its job in keeping the C-Suite informed.

Latest Posts

A transparent image used for creating empty spaces in columns
As technology evolves at an unprecedented pace, artificial intelligence (AI) has emerged as a transformative force in cybersecurity. Organizations now use AI to detect and respond to threats faster than ever, but this progress raises an important question: is the human factor still relevant in…
A transparent image used for creating empty spaces in columns
In the complex world of cybersecurity, simple strategies can often make a big difference. One of the most powerful ideas in protecting your organization from cyber threats is as straightforward as it sounds: don’t leave the front door open. Picture this: your company’s network is…
A transparent image used for creating empty spaces in columns
With the rise in cyber threats, data breaches, and evolving regulations, cybersecurity risk management has never been more crucial for businesses. Today, companies are more connected than ever, and every device, user, and application potentially opens a new path for cybercriminals to exploit. From ransomware…
A transparent image used for creating empty spaces in columns
 In today’s increasingly digital world, more businesses are operating entirely online with remote teams and cloud-based infrastructures. As these companies grow, so does the importance of cybersecurity. One question we often get is: “Can online companies get penetration tests?” The answer is a resounding…
A transparent image used for creating empty spaces in columns
In today’s education landscape, cybersecurity is more critical than ever. Schools are no longer just places of learning; they have evolved into hubs of digital information, housing vast amounts of sensitive data. From student records to financial information, the risk of cyberattacks has become a…
A transparent image used for creating empty spaces in columns
 In today’s digital landscape, cybersecurity is not just a luxury but a necessity. As businesses increasingly rely on technology, the importance of safeguarding sensitive data has never been greater. However, for many small and medium-sized businesses (SMBs), the costs associated with cybersecurity services, particularly…
contact

Our Team

Name(Required)
This field is for validation purposes and should be left unchanged.
On Load
Where? .serviceMM
What? Mega Menu: Services