833-847-3280
Schedule a Call

Cyber Security and IT: Separate Them

Small and mid-size companies frequently ask how to organize their cyber security assets and responsibilities to best protect their companies. This is more a question of function than of form, and it requires companies to challenge some assumptions about their IT departments as well as the perceptions of cyber security reports.
The immediate action taken by most corporate management teams is to make cyber security the responsibility of the IT shop. It seems a natural fit to place a highly technical and complex function under the direction of the IT Director or CIO.

But the real reason for this decision is that most corporate management teams have a minimal understanding of cyber security, nor dedicate the time it takes to learn it. This is a poorly designed organizational structure that can impede the flow of critical information to the C Suite due to conflictive responsibilities.

There are two key perceptions that need to be addressed. One, a report on cyber security gaps and vulnerabilities (not to mention a breach) is seen by the C-Suite as a damning display of improper planning and a larger threat to the existence of their business. Two, the same report on the cyber security status of an IT architecture is deemed pejorative by Senior IT personnel and seen as a threat to their position due to the exposure of cyber security gaps. This leads to dilution, or even non-disclosure, of key cyber security findings to the C Suite.

Both these perceptions are weak, yet extraordinarily ingrained in corporate management. The C-Suite should understand that most, if not all, IT systems that are connected to the internet are going to have some vulnerabilities and gaps due to flaws in software and applications, not just architecture. They also need to understand that there is a good possibility that they will be, or are, breached, and they need to better prepare to respond to that breach. In most cases, this is not the fault of IT management. Rather, an analysis of their system such as a vulnerability scan or a penetration test offers a chance for the IT director to open the discussion with the C-Suite on the appropriate measures, to include budget, technology, managed services, training etc, required to better prepare the company for a breach response. They should not “white wash” or minimize the results of a report or scan.

The solution: corporate C-Suites should become educated on cyber security threats and shift focus from defense to now identification and response in reaction to a breach. They should not have the unreasonable expectation that technology and training can protect themselves 100% — staff should be required to prepare both a disaster response and crisis response plan. Finally, separate cyber security and IT, placing cyber security either under another C-Suite position due to its criticality or have it report to security where the conflict between reporting cyber security issues and their impact on the IT department does not impede the flow of critical information. These steps will go far in ensuring that cyber security remains a priority and does its job in keeping the C-Suite informed.

Latest Posts

A transparent image used for creating empty spaces in columns
Most small business owners think about a data breach the same way they think about a house fire. They know it happens to people. They know it would be bad. They assume it probably won’t happen to them, and even if it did, their insurance…
A transparent image used for creating empty spaces in columns
When organizations invest in penetration testing, they’re often unsure what to expect from the process. A recent online discussion raised an important question: “Is our pen test provider’s approach normal, or are we getting shortchanged?” It’s a fair concern. Unlike compliance audits, penetration tests don’t…
A transparent image used for creating empty spaces in columns
If you work in healthcare or support organizations that handle patient data, you’ve probably heard that HIPAA is changing in 2026. The short version is that this is the most significant overhaul to the Security Rule since it was first introduced in 2003, and the…
A transparent image used for creating empty spaces in columns
There’s a post making rounds in the pen testing community that’s sparking strong reactions. Someone without an OSCP, in a country where it costs as much as a car, decided they weren’t going to wait for permission to start pen testing. They grabbed the certifications…
A transparent image used for creating empty spaces in columns
You’re planning next year’s security budget, and a question comes up: should we stick with the same penetration testing provider we’ve been using, or switch to a new one? Some organizations rotate testers annually. Others work with the same provider for years. Both approaches have…
A transparent image used for creating empty spaces in columns
AI is everywhere in cybersecurity right now. AI-powered threat detection, AI-driven security analytics, and AI-assisted vulnerability management. And increasingly, AI- or automated pen testing platforms are promising to replace human penetration testers. The pitch is compelling: continuous testing, faster results, lower costs, and no need…
contact

Our Team

This field is for validation purposes and should be left unchanged.
Name(Required)
On Load
Where? .serviceMM
What? Mega Menu: Services