Running IT security without a security team

You will not have your own security team any time soon. With 50 to 500 employees, the budget rarely stretches beyond an IT department that already has too much on its plate, and the labour market for security people does not improve the maths either. We write this without regret: running IT security without your own security team is the normal case for most Swiss SMEs, and it can be run properly. The gap we find in our engagements is almost always the same one, and it does not appear in any staffing plan: tasks that exist but belong to no one.

The reflex of "we should hire someone for this"

The sentence usually follows a concrete trigger. A customer questionnaire lands on the table, the cyber insurer wants answers, or a company nearby was down for two weeks. Then someone in management says: "We should hire someone for this."

Behind the sentence sits a picture from the corporate world: a security operations center, shift work, big screens. Vendors nurture this picture because it sells products and billable days. And anyone who tries to hire internally soon notices that the market plays the same picture: the profiles you find want corporate environments, corporate salaries or both, and a lone specialist in an SME has no one to exchange ideas with anyway.

The picture does not describe your problem, though. The security tasks in an SME exist, but they do not fill a full-time position. Part of them takes a few hours per week, another part one meeting per quarter. We have seen more than once what happens when a 100-person company creates a full-time security position anyway: the person has too little to do and starts building work for themselves. New policies and new tools that nobody asked for. The security level barely rises, the costs do. You recognise the pattern when the security work mostly produces documents and rarely anything an attacker would notice.

Without assigned responsibilities, however, the opposite happens. Security then runs as a side effect of IT operations: IT installs patches when there happens to be time. Alerts from the systems land in a mailbox nobody reads. And risk decisions are made implicitly, by nobody deciding anything. That goes well for a long time, until the day someone asks who was responsible.

The four jobs that need an owner

When we set up security operations in an engagement, we sort all tasks into four jobs. The sorting is unspectacular, but it makes visible what is missing.

Deciding. Someone determines which risks the company consciously accepts, what money is spent on and what takes priority. That is the core of what a CISO does, and the only task on this list that has to sit close to management. Whether you need a dedicated person for it is something we took apart in Do you need a CISO?

Operating. Someone keeps the foundation in order: permissions, patches, backups, the configuration of the tools you already own. No glamour, but the part with the greatest protective effect per franc spent.

Watching. Someone looks at the alerts your systems generate, tracks known vulnerabilities and spots the unusual login on a Sunday evening. Watching is the job that is most often unassigned in SMEs, because it is the easiest to push aside in daily business.

Evidencing. Someone can demonstrate how you run security: to customers, the insurer, the board of directors. This job gets underestimated until the first enterprise customer sends a questionnaire and the answer costs three weeks of research.

Four jobs emphatically does not mean four people. One person can wear several hats, and for individual hats you can bring in external help. But every job needs a name behind it. "IT handles that" does not fill a job, it only shifts it, and usually it shifts it into a void.

It also helps to size the jobs realistically before you think about models. Operating is everyday work and already runs somewhere in most companies, just without the security lens. Watching is an on-call job: minutes on quiet days, everything at once in an emergency, and that is exactly why it does not work as a side task. Deciding and evidencing are cadence work; a fixed appointment per quarter is often enough, but it has to take place and leave minutes behind. When you lay the four jobs side by side like this, you usually see for yourself which one is in good hands internally and which one is not.

Three models for IT security without your own team

In practice we see three operating models that work. All three have limits, and we describe those as well.

Model 1: IT wears the hat, with guardrails. The most common variant. The head of IT takes on operating and watching, management decides. That holds as long as two conditions are met: decisions are documented instead of nodded through verbally, and there is a fixed rhythm in which security is on the management agenda. One hour per quarter with three agenda items is enough: what happened, what is open, what do we consciously accept as risk. The limit of the model is structural. IT reviews itself, and in daily business availability beats security almost every time; the migration with a deadline beats the patch window. An external review at sensible intervals balances that out.

Model 2: buying operations and monitoring. A service provider takes over parts of operating and watching, for example as managed detection or as a managed security service. You are buying eyes and hands, and that can make a lot of sense, especially for watching around the clock. What you are not buying: decisions and responsibility. When the provider reports something, someone at your company still decides what it means and what happens. The most useful question to ask such a provider is therefore: what do you do when you find something, and what do you expect from us in that moment? If the answer boils down to "we send you a ticket", you know that the watching job is only half bought and the other half sits with you, with a name attached. A second hint from experience: a provider who also sells tools has a built-in conflict of interest with every gap they find. Before you buy on a recommendation, the three questions before every tool renewal are worth asking for new purchases too.

Model 3: buying leadership, keeping operations. An external practitioner takes over decision preparation, prioritisation and the evidence, on a few days per month. Operating and watching stay with your IT or your existing provider. The model fits when the operational side works and the gap sits at the top: nobody prioritises and nobody reports. That is how our security management is built, and to be honest: this is our business, so expect us to like this model. The yardstick stays the same as with any purchase: it has to close a named gap, otherwise it is decoration.

What stays the same in all three models: the risk decisions belong to management. You can outsource every hands-on task, but no provider ships responsibility with the service.

The test for one afternoon

You can find out whether your operation holds up without a security team, and you do not need an audit for it. Four questions, one per job, and the answers have to contain names.

  1. Who last decided to consciously accept a security risk, and where is that recorded?
  2. Who installs patches, in what rhythm, and who notices when it does not happen for two months?
  3. If an alert comes in tonight: who sees it first, and does that person know they are responsible?
  4. Could you show a large customer within one week how you run security?

Four names with clear answers: you are in better shape than many companies with a much bigger budget. A "well, IT, somehow" in between: that is where the gap sits, and it costs nothing until it gets expensive.

If several answers are shaky, a simple order helps. The third question first, because an unwatched system devalues every other effort; then the first, because undecided risks otherwise decide themselves; the fourth can wait until a customer asks it, and then suddenly it cannot. What matters is that you choose the order consciously, instead of starting wherever an offer happens to be on the table.

Start with the responsibilities before you buy anything. In our experience, clarifying these four jobs is the cheapest security gain there is. It costs one meeting and a sheet of paper, and its effect beats many a tool subscription, because it makes the tools you already have effective.

If you have run through the four questions and want a sparring partner for the result, an initial conversation is the easiest way. We look at the gaps with you, without a mandate having to come out of it.

And because we are interested in the answer: which of the four jobs would be unassigned at your company today, if you look honestly?