Skip to main content

Security Ownership: Why “IT Handles That” Is Usually Wrong

Alyssa O'Brien3 min read

Two overlapping circles labelled IT and Security, with the overlap asking who decides. IT keeps the lights on. Security decides the risk.

Vulnerability exploitation overtook stolen credentials for the first time in the DBIR's 19-year history, now the entry point in 31% of breaches, while organizations fully remediated only 26% of critical known flaws last year.1 Ask a department head who owns the security of the SaaS tool their team signed up for last quarter, and you'll get the same answer nine times out of ten: “IT handles that.” IT usually has no idea the tool exists.

This is the most common and most dangerous ownership gap in cybersecurity, and it has nothing to do with firewalls. It's a language problem. “IT” and “security” get used interchangeably by everyone except the people doing the actual work, and that confusion is exactly where breaches live.

Two Jobs, One Org Chart

IT keeps the lights on. Security decides what's an acceptable risk. Those are different jobs requiring different judgment, and collapsing them into one department means nobody is actually asking the second question. Patch management is an IT function. Deciding whether an unpatched legacy system is an acceptable risk for another quarter is a security decision, and it needs an owner who isn't the same person who'd have to do the work of fixing it.

The Shared Responsibility Model, Misread

The shared responsibility model that cloud providers popularized made this worse in a way people don't talk about enough. AWS or Microsoft secures the infrastructure. You secure what you put on it: configurations, access controls, data classification. Plenty of companies read “shared” and heard “someone else's.” A misconfigured S3 bucket is not Amazon's fault, and pretending otherwise is how customer data ends up indexed by Google.

NIST CSF Has No Delegate Step

The NIST Cybersecurity Framework's five functions, identify, protect, detect, respond, recover, don't have a “delegate” step. Every function needs a named owner, and in most companies the honest org chart shows “detect” and “respond” owned by whoever's on call that week.

The Real Problem Is the Reporting Line

Here's my actual opinion, since balanced-on-all-sides isn't useful to anyone: most companies don't have a security ownership gap because they can't afford a security team. They have one because they've never made anyone accountable for saying no to the business. A CISO who reports through IT and needs IT's budget approval to fund a control isn't really independent. They're a security-flavored IT manager, and the org chart shows it the moment there's an incident and everyone starts pointing.

Frequently asked questions

Should security ever report into IT?

It can, but the moment it does, someone above both functions needs to own the tie-breaking vote on risk decisions IT would rather not fund.

What's the fastest way to find our ownership gaps?

Pull the last three security findings your team closed late, and ask who actually had the authority to prioritize the fix. The answer usually isn't the person who got blamed.

Does the shared responsibility model apply the same way to every cloud vendor?

The split of duties differs by service model, IaaS, PaaS, SaaS, but the principle holds everywhere: the provider secures the platform, you secure what you configure on it.

Draw the Line Between IT and Security Explicitly

Devensa AI's vCISO vOfficer draws the line between IT operations and security ownership explicitly, with named accountability for each control instead of a shared assumption that someone else has it covered.

If an auditor asked who owns the risk decision on your oldest unpatched system, would the answer be a name or a shrug?

Schedule a demo with our team at info@devensa.ai, or request early access to the Governance Readiness Assessment, coming to devensa.ai.

Request a demo Join early access

Sources

  1. Verizon, 2026 Data Breach Investigations Report, cited via SecurityWeek. https://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/