We Have an IT Provider, So Are We Secure?

Understanding the difference between IT support and cybersecurity

One common misconception across all industries is that if a business has an IT provider, cybersecurity is already handled.

It is easy to understand why. IT providers are usually the ones setting up accounts, fixing email issues, managing devices, sorting out software problems, maintaining backups, and keeping everything running in the background. When something breaks, they are the first to receive the call. So it makes sense that many businesses assume that cybersecurity is also their responsibility.

Sometimes it is. Some parts of it are. The challenge is that IT support and cybersecurity overlap, but they are not the same thing.

This is not a criticism of IT providers. In fact, it is the complete opposite. Many Managed Service Providers, or MSPs, do an incredible job keeping organisations running. A lot of the time, they are already implementing systems and controls in the background to help protect their clients. The problem is that nobody has clearly mapped out where the responsibility for everything sits.

That is where things can get missed.

IT support and cybersecurity are connected, but they are not the same thing

Let’s break it down.

At a basic level, IT support is about keeping systems available and ensuring everything works the way it should. This could include setting up users, managing devices, troubleshooting basic issues, software maintenance, supporting cloud services, and helping staff when issues arise.

Cybersecurity is a little different. Yes, it is about keeping things working, but it is also about reducing the chance something goes wrong and making sure the business knows what to do if it does.

Naturally, there is overlap between the two. Keeping devices patched, managing user access, enabling multi-factor authentication (MFA), securing email systems, and maintaining backups all contribute to stronger security.

But there is much more to cybersecurity than technical maintenance. It also involves understanding business risks, preparing for incidents, reviewing access permissions, building a strong security culture, and deciding how much risk the organisation is willing to accept.

Technology matters, but it is only one part of the picture. If something involves staff behaviour, business processes, leadership decisions, supplier access, and incident planning, it cannot sit entirely in the “IT problem” basket.

Where assumptions create risk

Most organisations genuinely want to do the right thing. It is not a lack of concern. The issue is that cybersecurity responsibilities are often assumed rather than discussed.

Many assume the MSP is handling everything, or should be handling everything. But it is in these assumptions that risk begins.

A business may have reliable IT support but no documented incident response process. It might have backups, but no record of whether they have been tested or when that testing last happened. MFA might be turned on for email, but not for payroll, finance, or other key systems. There may be security tools in place, but no one knows who reviews the alerts or what happens when something suspicious is detected.

None of this means an organisation has failed or does not care. It simply means that there may be risks that have not yet been properly examined.

Cybersecurity is a shared responsibility

One of the most productive shifts an organisation can make is recognising that, at its core, cybersecurity is not solely an IT responsibility.

While your MSP may manage systems and technical controls, security decisions affect the entire organisation.

Everyone has a role to play. Leaders set the priorities and help build the security culture. Staff make decisions every day that can either reduce risk or increase it. Suppliers and third parties can also influence an organisation’s security posture.

When everyone understands their role, security becomes much more effective.

Now, let’s make something very clear. This does not mean that every employee needs to become a technical expert. Most staff have zero need to understand how security works behind the scenes. They just need to know what is expected of them and why it matters.

Take MFA for example. Staff do not need to understand the technology behind it. They do need to understand why approving an unexpected login request or sharing an authentication code creates risk.

Small actions matter, often far more than people realise.

Questions every business should be asking

If you do have an MSP, it is worth taking the time to understand exactly what is included in their services, and what responsibilities remain with the business.

Some useful questions to ask include:

  • Do we have multi-factor authentication enabled across all key systems?

  • Are our backups tested regularly, and do we know how long recovery would take?

  • Who monitors security alerts, and what happens when suspicious activity is detected?

  • Is our cybersecurity awareness training current, practical, and relevant to the risks our staff actually face?

  • Do we have an incident response plan, and when was it last reviewed?

  • How often are user accounts and access permissions reviewed?

  • Are devices consistently patched and updated?

  • Which security responsibilities sit with our MSP, and which remain with us as the business?

Most MSPs welcome these conversations because clear expectations usually lead to better outcomes for everyone involved.

Why this matters for small businesses and not-for-profits

For smaller organisations, cybersecurity is just one of many competing priorities.

When there are customers to support, projects to deliver, budgets to manage, staff to look after, and day-to-day operations to keep moving, security can easily slip into the “we’ll get to that later” category.

The reality is that many small businesses and not-for-profits rely heavily on digital systems that contain significant amounts of sensitive data. They may not have dedicated security teams, but they are still holding information that matters and they still depend on technology to operate.

The good news is that improving cybersecurity does not require solving everything at once.

Progress starts with understanding where you are today, identifying your biggest risks, and taking practical steps forward.

Sometimes the first step is as simple as asking the right questions.

At BrightPath Cyber Advisory, we help organisations ask those questions, understand where responsibility sits, and take practical steps to strengthen their security without making cybersecurity feel overwhelming.

Previous
Previous

Cybersecurity Training Should Not Be a Silent Exercise.

Next
Next

The Birth of BrightPath Cyber Advisory