Managed Security Cybersecurity for SMEs

Who protects your entire IT environment?

Compare five common SME cybersecurity setups, their key risks and what to improve.

28 August 2026 SpySecure SpySecure

Most SMEs can name the person or company that helps with IT. Far fewer can explain who is responsible for cybersecurity as an ongoing operation.

“Our CTO handles cybersecurity” or “our external IT company takes care of it” may sound reassuring. But both the scope and the work matter. A CTO often focuses on the company’s own application, while an IT company may mainly manage workplaces, accounts, Microsoft 365 or Google Workspace and support. Cybersecurity is only fully managed when the complete environment is covered and someone actively finds and fixes security gaps, monitors suspicious activity and responds to attacks.

These five setups reflect what we repeatedly find when assessing and onboarding SMEs. Management often believes cybersecurity is covered, but discovers that nobody owns the full environment, tools are not actively managed or alerts are not investigated 24/7.

The five setups in practice

Find the statement that sounds most like your company. Each setup explains what is likely covered, where the main risks are and what to improve next.

1
Nothing arranged

“We haven’t really arranged cybersecurity”

What this setup usually means: nobody has explicit responsibility for cybersecurity. The company may use the antivirus included with its laptops and some standard settings, but there is no structured process for finding and resolving security problems.
Technical risk

Known vulnerabilities remain open, controls such as MFA may be missing and suspicious activity goes unnoticed.

Business impact

Fraud, data loss, downtime or a warning from a third party may be the first sign of an attack.

Logical next step: appoint an owner and perform a baseline review of the full environment.

2
Managed internally

“Our CTO or IT manager handles cybersecurity”

What this setup usually means: a CTO typically prioritises the company’s own product or applications, while an IT manager focuses on keeping everyday IT running. In both cases, cybersecurity competes with their main responsibilities. Accounts, devices, e-mail, networks and SaaS connections may receive too little attention, leaving the wider IT environment easy to access and allowing sensitive data to leak.
Technical risk

Limited time and specialist expertise leave vulnerabilities, misconfigurations and alerts unresolved.

Business impact

The company depends on one person and may spend more internal time and money than specialist outsourcing would cost.

Logical next step: keep internal ownership, but add specialist capacity for continuous security work and 24/7 response.

3
External IT company

“Our external IT company handles cybersecurity”

What this setup usually means: the IT company manages accounts, laptops, Microsoft 365 or Google Workspace, licences and support. It may also install antivirus, backup software or another security product. Unless Managed Security is explicitly included and paid for, this usually remains IT management with some security tools.
If you do not explicitly pay for Managed Security, you do not have Managed Security.
Technical risk

A few disconnected tools may run in the background, while their coverage, policies and alerts are not actively managed.

Business impact

Management assumes the company is protected, but nobody is continuously detecting, investigating or responding to attacks.

Logical next step: check the proposal, contract and invoices for the exact security scope, monitoring hours, response commitments and reporting.

4
Several specialists

“We use different specialists for different parts”

What this setup usually means: separate providers cover devices, e-mail, cloud platforms, testing or compliance. Each may perform its own task well, but nobody is necessarily responsible for the complete environment.
Technical risk

Gaps remain between devices, identities, e-mail, networks and cloud or SaaS systems managed by different parties.

Business impact

You pay multiple specialists but still have to manage the incident yourself. While providers determine who is responsible, the attack continues, increasing downtime, data loss and recovery costs.

Logical next step: appoint one Managed Security firm to oversee the complete environment, coordinate the existing providers and lead the response when an attack affects multiple systems.

5
Managed Security

“A Managed Security firm protects us 24/7”

What this setup usually means: a specialist Managed Security firm takes responsibility for security across accounts, devices, e-mail, networks, cloud and SaaS applications. Your CTO, IT manager or IT provider continues to run everyday IT. The security team continuously finds and fixes vulnerabilities and misconfigurations, monitors activity 24/7, investigates alerts, responds to attacks and reports the results.
Technical risk

Blind spots remain if the provider cannot see and manage every relevant part of the company’s environment.

Business impact

An enterprise-focused provider may add expensive tools, processes and complexity that an SME does not need.

Logical next step: confirm that the provider covers the full environment, performs the agreed security work, responds 24/7 and reports the results. Then check that the service and price are designed for an SME rather than a large enterprise.

The real risk is assuming someone has it covered

Most SMEs already have an IT manager or external IT company and several security tools. The problem is that each person, provider or product usually covers only part of the company. Management may assume the gaps are covered when nobody is actually responsible for them.

A CTO may secure the company’s own application but not employee accounts and devices. An IT company may manage workplaces and licences but not investigate security alerts. An endpoint specialist may protect laptops but not e-mail, identities or SaaS applications. Each provider may deliver exactly what its contract requires while important systems and data remain exposed.

To find out whether your cybersecurity is fully managed, ask for clear evidence. Which systems are protected? Which vulnerabilities and misconfigurations have been found and fixed? Who investigates alerts and responds to threats 24/7? If nobody can provide the complete answer, your cybersecurity is fragmented rather than fully managed.

For most SMEs, the solution is not to replace their CTO, IT manager or IT company. They should continue to manage the product and everyday IT. A specialist Managed Security firm should take responsibility for security across the wider environment. It should select and combine the most suitable security technologies, keep them configured and up to date, monitor threats 24/7 and respond when an attack is detected.

Technology alone is not enough. Effective protection requires complete coverage, active management and rapid response.

Discuss your setup

Want to know which setup matches your company?

Tell us how your cybersecurity is currently organised. We can help you identify what is covered, what may be missing and whether the current approach fits your company.