Most SMEs can name the person or company that helps with IT. Far fewer can explain who is responsible for cybersecurity as an ongoing operation.
“Our CTO handles cybersecurity” or “our external IT company takes care of it” may sound reassuring. But both the scope and the work matter. A CTO often focuses on the company’s own application, while an IT company may mainly manage workplaces, accounts, Microsoft 365 or Google Workspace and support. Cybersecurity is only fully managed when the complete environment is covered and someone actively finds and fixes security gaps, monitors suspicious activity and responds to attacks.
These five setups reflect what we repeatedly find when assessing and onboarding SMEs. Management often believes cybersecurity is covered, but discovers that nobody owns the full environment, tools are not actively managed or alerts are not investigated 24/7.
The five setups in practice
Find the statement that sounds most like your company. Each setup explains what is likely covered, where the main risks are and what to improve next.
“We haven’t really arranged cybersecurity”
Known vulnerabilities remain open, controls such as MFA may be missing and suspicious activity goes unnoticed.
Fraud, data loss, downtime or a warning from a third party may be the first sign of an attack.
Logical next step: appoint an owner and perform a baseline review of the full environment.
“Our CTO or IT manager handles cybersecurity”
Limited time and specialist expertise leave vulnerabilities, misconfigurations and alerts unresolved.
The company depends on one person and may spend more internal time and money than specialist outsourcing would cost.
Logical next step: keep internal ownership, but add specialist capacity for continuous security work and 24/7 response.
“Our external IT company handles cybersecurity”
A few disconnected tools may run in the background, while their coverage, policies and alerts are not actively managed.
Management assumes the company is protected, but nobody is continuously detecting, investigating or responding to attacks.
Logical next step: check the proposal, contract and invoices for the exact security scope, monitoring hours, response commitments and reporting.
“We use different specialists for different parts”
Gaps remain between devices, identities, e-mail, networks and cloud or SaaS systems managed by different parties.
You pay multiple specialists but still have to manage the incident yourself. While providers determine who is responsible, the attack continues, increasing downtime, data loss and recovery costs.
Logical next step: appoint one Managed Security firm to oversee the complete environment, coordinate the existing providers and lead the response when an attack affects multiple systems.
“A Managed Security firm protects us 24/7”
Blind spots remain if the provider cannot see and manage every relevant part of the company’s environment.
An enterprise-focused provider may add expensive tools, processes and complexity that an SME does not need.
Logical next step: confirm that the provider covers the full environment, performs the agreed security work, responds 24/7 and reports the results. Then check that the service and price are designed for an SME rather than a large enterprise.
The real risk is assuming someone has it covered
Most SMEs already have an IT manager or external IT company and several security tools. The problem is that each person, provider or product usually covers only part of the company. Management may assume the gaps are covered when nobody is actually responsible for them.
A CTO may secure the company’s own application but not employee accounts and devices. An IT company may manage workplaces and licences but not investigate security alerts. An endpoint specialist may protect laptops but not e-mail, identities or SaaS applications. Each provider may deliver exactly what its contract requires while important systems and data remain exposed.
To find out whether your cybersecurity is fully managed, ask for clear evidence. Which systems are protected? Which vulnerabilities and misconfigurations have been found and fixed? Who investigates alerts and responds to threats 24/7? If nobody can provide the complete answer, your cybersecurity is fragmented rather than fully managed.
For most SMEs, the solution is not to replace their CTO, IT manager or IT company. They should continue to manage the product and everyday IT. A specialist Managed Security firm should take responsibility for security across the wider environment. It should select and combine the most suitable security technologies, keep them configured and up to date, monitor threats 24/7 and respond when an attack is detected.
Technology alone is not enough. Effective protection requires complete coverage, active management and rapid response.
Want to know which setup matches your company?
Tell us how your cybersecurity is currently organised. We can help you identify what is covered, what may be missing and whether the current approach fits your company.
%20-%20no%20white%20space%20-%20resized-1.png?width=4164&height=948&name=logo%201%20(bold)%20-%20no%20white%20space%20-%20resized-1.png)