Vulnerability exploitation overtook stolen credentials for the first time in the DBIR's 19-year history, now the entry point in 31% of breaches, while organizations fully remediated only 26% of critical known flaws last year.1 Ask a department head who owns the security of the SaaS tool their team signed up for last quarter, and you'll get the same answer nine times out of ten: “IT handles that.” IT usually has no idea the tool exists.
This is the most common and most dangerous ownership gap in cybersecurity, and it has nothing to do with firewalls. It's a language problem. “IT” and “security” get used interchangeably by everyone except the people doing the actual work, and that confusion is exactly where breaches live.
IT keeps the lights on. Security decides what's an acceptable risk. Those are different jobs requiring different judgment, and collapsing them into one department means nobody is actually asking the second question. Patch management is an IT function. Deciding whether an unpatched legacy system is an acceptable risk for another quarter is a security decision, and it needs an owner who isn't the same person who'd have to do the work of fixing it.
The shared responsibility model that cloud providers popularized made this worse in a way people don't talk about enough. AWS or Microsoft secures the infrastructure. You secure what you put on it: configurations, access controls, data classification. Plenty of companies read “shared” and heard “someone else's.” A misconfigured S3 bucket is not Amazon's fault, and pretending otherwise is how customer data ends up indexed by Google.
The NIST Cybersecurity Framework's five functions, identify, protect, detect, respond, recover, don't have a “delegate” step. Every function needs a named owner, and in most companies the honest org chart shows “detect” and “respond” owned by whoever's on call that week.
Here's my actual opinion, since balanced-on-all-sides isn't useful to anyone: most companies don't have a security ownership gap because they can't afford a security team. They have one because they've never made anyone accountable for saying no to the business. A CISO who reports through IT and needs IT's budget approval to fund a control isn't really independent. They're a security-flavored IT manager, and the org chart shows it the moment there's an incident and everyone starts pointing.
It can, but the moment it does, someone above both functions needs to own the tie-breaking vote on risk decisions IT would rather not fund.
Pull the last three security findings your team closed late, and ask who actually had the authority to prioritize the fix. The answer usually isn't the person who got blamed.
The split of duties differs by service model, IaaS, PaaS, SaaS, but the principle holds everywhere: the provider secures the platform, you secure what you configure on it.
Devensa AI's vCISO vOfficer draws the line between IT operations and security ownership explicitly, with named accountability for each control instead of a shared assumption that someone else has it covered.
If an auditor asked who owns the risk decision on your oldest unpatched system, would the answer be a name or a shrug?
Schedule a demo with our team at info@devensa.ai, or request early access to the Governance Readiness Assessment, coming to devensa.ai.