100% Veteran-Owned · SDVOSB & WOSB Certified · CAGE 13HY7

Article

Your IT Department Says It Includes Cybersecurity. But Does It?

IT Security

For many organizations, cybersecurity is assumed to be part of IT. The firewall is configured, employees have passwords, multi-factor authentication may be enabled, computers have antivirus or endpoint protection, software gets updated, and someone manages the network and fixes problems when something stops working. So when leadership asks who handles cybersecurity, the answer often comes quickly: our IT department does.

We have encountered this assumption repeatedly when working with organizations, and it can lead to a difficult realization. Their IT provider may be doing a perfectly good job of configuring and maintaining technology securely, but that does not necessarily mean someone is actively managing the cybersecurity of the organization. Those responsibilities overlap, but they are not the same.

Secure IT Is Part of Cybersecurity — Not the Whole of It

A competent IT professional should configure technology securely. Administrative accounts should be protected, firewalls should be properly configured, permissions should be managed, systems should be patched, endpoint protection should be deployed, wireless networks should be secured, and appropriate authentication and encryption should be implemented. All of these activities contribute to cybersecurity, and they are important.
Cybersecurity, however, goes beyond configuring individual technologies. It asks whether the organization understands its environment well enough to identify where it is vulnerable and whether the safeguards in place are actually protecting it.

That requires understanding what systems and devices the organization owns, where sensitive information resides, how that information moves through the organization, who has access to it, and whether those individuals still need that access. It means understanding which vendors can access systems or data, whether security activity is being monitored, whether vulnerabilities are being identified and corrected, whether backups can actually be restored, and whether the organization is prepared to respond when something goes wrong.
A firewall can be configured correctly and the organization can still be vulnerable. Multi-factor authentication can be enabled while former employees retain access they no longer need. Endpoint protection can be installed while critical vulnerabilities remain unresolved elsewhere in the environment. Backups can run every night without anyone discovering that they cannot actually be restored until a disaster occurs.

The individual safeguards matter, but cybersecurity is about understanding how those safeguards work together to protect the entire environment.

Security Is Not a One-Time Configuration

One of the biggest problems with equating secure configuration with cybersecurity is that an organization's technology environment never stays still.

Employees join and leave. Responsibilities change. New applications are introduced. Vendors are added. Devices are replaced. Software becomes outdated. Permissions accumulate. Cloud services are adopted. A firewall rule may be temporarily changed to solve an operational problem and never changed back. Someone may begin using an application to store information without realizing where that information is actually going.

A system that was securely configured six months ago is not automatically secure today.
This is why cybersecurity has to be an ongoing process. Organizations need to periodically evaluate risk, review access, monitor activity, identify vulnerabilities, assess changes, test safeguards, document deficiencies, and make sure identified problems are actually corrected. Security is not simply the condition in which technology was originally installed. It is the continuing process of understanding and managing risk as the environment changes.

The Difference Matters Even More in Regulated Environments

The distinction between IT and cybersecurity becomes particularly important for organizations subject to HIPAA, CMMC, NIST-based contractual requirements, PCI DSS, or other security and privacy obligations.

Compliance requirements generally extend well beyond whether an organization has a firewall, antivirus software, or strong passwords. Depending on the applicable requirements, an organization may need to demonstrate that risks have been assessed, access is appropriately controlled, security activity is reviewed, incidents are handled according to established procedures, personnel receive appropriate training, third parties are managed, recovery capabilities exist, and security policies and procedures are maintained.

The key word is demonstrate.

It is not enough to assume that a safeguard exists or that someone is taking care of it. Organizations increasingly need to understand what protections are in place, who is responsible for them, whether they are operating effectively, what evidence supports that conclusion, and what happens when a deficiency is discovered.
An organization can therefore have an excellent IT provider and still have substantial cybersecurity gaps. That does not necessarily mean the IT provider has failed. In many cases, the organization simply believed it was receiving a service that was never actually within the scope of traditional IT support.

The Awareness Gap May Be the Bigger Problem

What continues to surprise us in conversations with organizations is how often leadership genuinely believes cybersecurity is already being handled. They are not deliberately ignoring security. They believe they purchased it.

That misunderstanding is concerning because an organization cannot address a cybersecurity gap it does not know exists.

If an IT provider says that cybersecurity is included, a business owner may reasonably assume that someone is evaluating the security of the organization as a whole. In reality, the provider may mean that systems are configured according to good security practices. Both are valuable services, but they are not interchangeable.

Cybersecurity professionals have an important awareness gap to bridge here. We need to help organizations understand what cybersecurity actually means without turning every conversation into a fear-based sales pitch or suggesting that every small business needs an enterprise-sized security program.

A small healthcare practice does not need the same cybersecurity infrastructure as a multinational corporation. A ten-person business should not be buried under unnecessary enterprise controls simply for the sake of having more controls. Security should be proportionate to the organization's size, systems, information, regulatory obligations, and actual risks.

But appropriate cybersecurity begins with knowing what those risks are.

A Better Question to Ask Your IT Provider

Rather than simply asking, “Do you handle our cybersecurity?”, organizations may want to ask a more specific question:

“What are we doing to continuously determine whether our environment is secure?”

The answer should provide considerably more insight.

Who evaluates the organization's cybersecurity risks? Who reviews user access and determines whether it remains appropriate? Who monitors security activity? Who identifies vulnerabilities and tracks their remediation? Who maintains an accurate inventory of systems and devices? Who evaluates third-party access and risk? Who verifies that recovery capabilities work? Who reviews the environment when technology or business operations change? And who documents all of this so the organization can demonstrate what it is doing to protect itself?

There may be several people responsible for those activities. Some may belong to IT, some to cybersecurity, and some to management or compliance. That is perfectly reasonable. What matters is that the organization knows the responsibilities exist and knows who is performing them.

If the answer to those questions repeatedly comes back to “we have antivirus, MFA, backups, and a firewall,” then an important part of the security picture may be missing.

Technology should absolutely be configured securely. Good IT is an essential part of protecting an organization, and IT and cybersecurity should work closely together.
But securely configured IT is not, by itself, a cybersecurity program.

Understanding that distinction—and helping organizations understand it before an incident, breach, or audit forces the conversation—is an awareness gap the cybersecurity industry needs to continue working to close.

← Back to News & Articles