Devensa Advisory
Get started

Security Ownership: Why “IT Handles That” Is Usually Wrong

IT and security get treated as one job. They aren't. See where that confusion actually breaks, and what the 2026 DBIR shows about the cost of unassigned risk decisions.

Devensa Advisory 3 min read
Two overlapping circles labelled IT and Security, with the overlap asking who decides. IT keeps the lights on. Security decides the risk.

Vulnerability exploitation overtook stolen credentials for the first time in the DBIR's 19-year history, now the entry point in 31% of breaches, while organizations fully remediated only 26% of critical known flaws last year.1 Ask a department head who owns the security of the SaaS tool their team signed up for last quarter, and you'll get the same answer nine times out of ten: “IT handles that.” IT usually has no idea the tool exists.

This is the most common and most dangerous ownership gap in cybersecurity, and it has nothing to do with firewalls. It's a language problem. “IT” and “security” get used interchangeably by everyone except the people doing the actual work, and that confusion is exactly where breaches live.

Two Jobs, One Org Chart

IT keeps the lights on. Security decides what's an acceptable risk. Those are different jobs requiring different judgment, and collapsing them into one department means nobody is actually asking the second question. Patch management is an IT function. Deciding whether an unpatched legacy system is an acceptable risk for another quarter is a security decision, and it needs an owner who isn't the same person who'd have to do the work of fixing it.

The Shared Responsibility Model, Misread

The shared responsibility model that cloud providers popularized made this worse in a way people don't talk about enough. AWS or Microsoft secures the infrastructure. You secure what you put on it: configurations, access controls, data classification. Plenty of companies read “shared” and heard “someone else's.” A misconfigured S3 bucket is not Amazon's fault, and pretending otherwise is how customer data ends up indexed by Google.

NIST CSF Has No Delegate Step

The NIST Cybersecurity Framework's five functions, identify, protect, detect, respond, recover, don't have a “delegate” step. Every function needs a named owner, and in most companies the honest org chart shows “detect” and “respond” owned by whoever's on call that week.

The Real Problem Is the Reporting Line

Here's my actual opinion, since balanced-on-all-sides isn't useful to anyone: most companies don't have a security ownership gap because they can't afford a security team. They have one because they've never made anyone accountable for saying no to the business. A CISO who reports through IT and needs IT's budget approval to fund a control isn't really independent. They're a security-flavored IT manager, and the org chart shows it the moment there's an incident and everyone starts pointing.

Frequently asked questions

Should security ever report into IT?

It can, but the moment it does, someone above both functions needs to own the tie-breaking vote on risk decisions IT would rather not fund.

What's the fastest way to find our ownership gaps?

Pull the last three security findings your team closed late, and ask who actually had the authority to prioritize the fix. The answer usually isn't the person who got blamed.

Does the shared responsibility model apply the same way to every cloud vendor?

The split of duties differs by service model, IaaS, PaaS, SaaS, but the principle holds everywhere: the provider secures the platform, you secure what you configure on it.

If an auditor asked who owns the risk decision on your oldest unpatched system, would the answer be a name or a shrug?

Sources

  1. Verizon, 2026 Data Breach Investigations Report, cited via SecurityWeek. https://www.securityweek.com/verizon-dbir-2026-vulnerability-exploitation-overtakes-credential-theft-as-top-breach-vector/

Originally published on the Devensa blog.

Keep reading

All insights →
Cybersecurity

Five Security Findings That Show Up in Every Audit

The same five cybersecurity gaps show up in audit after audit. See why they keep recurring and how continuous governance closes them.

AI Governance

Is Your AI Governance Tool Actually Governance?

Many AI governance tools are controls tools. Learn how governance and controls differ, why it matters, and what to ask before you buy.

Privacy

Who Owns Privacy? Why a DPO Title Doesn't Guarantee Accountability

Twenty US states now have comprehensive privacy laws in effect. See why an independent DPO still isn't the same as owning privacy operationally.

Put a name next to every gap.

A Current State Assessment scores where you are across the six domains and sequences what comes next, with owners attached.

Get started Explore Cybersecurity