The Technology Translator

Why IT Support Doesn't Automatically Mean Security

Vic Episode 7

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 23:21

Most businesses think cybersecurity is simply part of IT.

But is it?

In this episode of The Technology Translator, Vic explains why keeping technology running and protecting a business from cyber threats are two very different challenges.

Starting with a simple poster she saw early in her career comparing cybersecurity to personal hygiene, Vic explores how cyber risk has evolved from an IT issue into a business responsibility.

You'll learn:

  •  Why cybersecurity became its own profession 
  •  The difference between an MSP and an MSSP 
  •  What firewalls, antivirus, endpoint protection, EDR, MFA and Security Operations Centres actually do 
  •  Why moving to the cloud doesn't automatically make your business secure 
  •  When growing businesses need more than basic IT support 
  •  Why organisations now employ Chief Information Security Officers (CISOs) 
  •  Why boards, insurers and regulators are paying closer attention to cyber risk than ever before 

Whether you have an internal IT team or outsource your technology, this episode will help you ask one simple but incredibly important question:

Who is actually responsible for protecting our business?

Because understanding where IT support ends and cybersecurity begins could be one of the most important technology decisions your organisation ever makes.

Support the show

Thanks for listening to The Technology Translator.

If you found this episode useful, please follow the podcast and share it with someone who has ever been responsible for making a technology decision.

You can connect with me on LinkedIn - https://www.linkedin.com/in/victoriaccole/

Instagram - @thetechnologytranslator

Email - vic@thetechnologytranslator.au

Remember:

You don't need to become technical.

You do need to become informed.

SPEAKER_00

Welcome to the Technology Translator. I'm Vic. Every episode we break down technology, cybersecurity, and AI into plain English for Australian business leaders. Welcome to the podcast.

SPEAKER_01

I am actually really excited to be recording this one because today's topic is something that is incredibly close to my heart, and that's cybersecurity. Hello and welcome back to the Technology Translator. Thank you so much for joining me for another episode. Now, what's interesting is that my passion for cybersecurity didn't actually begin when I started working in cybersecurity. It actually started much earlier. I remember it was right at the beginning of my career, around 2015. I wasn't working in a cybersecurity role at the time. I was simply working in management consulting in the technology space, learning the industry, and trying to understand where I actually wanted my career to go. And one day I saw a poster in the office that simply said something along the lines of, good cybersecurity hygiene is as simple as washing your hands. And I remember walking back to my desk, sitting there for a few minutes, and just thinking about it. Because the more I thought about it, the more I realized just how true it was. Think about washing your hands. Today is just something we do. We really don't question it. We understand that good hygiene helps stop the spread of germs and keeps ourselves and the people around us healthy. But there was a time when people didn't understand germs. People didn't understand how disease spread. Once that knowledge becomes common, washing your hands stopped being something special and it simply became a habit. And I think cybersecurity is going through the exact same transition. Technology has become so deeply embedded into our lives that cybersecurity is no longer something that's only relevant to IT departments or large multinational organizations. It's become a part of everyday life. It's become part of running a business. It's become part of being an employee. And it's starting to become part of being a consumer as well. Good cybersecurity often comes down to simple habits. Locking your computer when you leave your desk, using a password manager, turning on multi-factor authentication, double checking the websites you're logging into or that you're processing a payment on. Thinking about what you're actually doing before you click an email. None of those things are difficult and none of them require you to be an IT professional. But together, they create good cybersecurity hygiene. And I think that's one of the biggest shifts we're seeing in technology today. Cybersecurity is no longer about buying software, it's about changing behavior. And that's actually a really nice way into today's episode. Because I've lost count to the number of times I've spoken to someone about cybersecurity and they've said something along the lines of, ah, we've got an IT department, they'll take care of that. Or ah, we've got an IT provider. That's covered. And look, maybe it is. Maybe they've got an outstanding internal IT team. Maybe they've partnered with a fantastic provider. But I've learned many things over the years, and one of the biggest ones is that organizations have never actually stopped to ask what that actually means. So who's responsible? Who's monitoring threats? Who's responding if something goes wrong? Who's reviewing alerts? Who's making sure security controls are actually working? Who's actually ensuring that all the security controls are turned on in the first place? Because tech keeping technology running and protecting a business from cyber threats are definitely related, but they're not always the same thing. And that's what we're going to unpack exactly why today. We're going to talk about why cybersecurity became its own profession. We'll simplify some of the buzzwords that get thrown around all the time, and I'll talk about the difference between IT support and cybersecurity. We'll explore why cloud doesn't automatically mean that it is secured. And hopefully, by the end of today's episode, you'll have a much clearer understanding of where IT ends and where cybersecurity begins, and why that distinction has become so important. So let's jump in. Alright, so to understand where we are today, we need to also understand where we've come from. If we go back 20 years, technology was actually pretty straightforward. Most businesses had a few desktop computers, maybe a server sitting in a cupboard somewhere. There was email, a little bit of internet, a printer that of course never seemed to work properly, and one IT person whose job was basically to keep everything running. If your password stopped working, they fixed it. If your printer didn't print, they fixed it. If the server crashed, they fixed it. Technology was largely operational. Their job was to keep the lights on. Cybersecurity certainly existed, but compared to today it was relatively simple. If you had a firewall protecting your internet connection, an antivirus installed on your computers, you're generally considered to be doing a pretty reasonable job. And then technology changed and evolved. Cloud computing arrived. People started working from home. Smartphones became business devices. Businesses stopped storing files on one server and started storing them across dozens of cloud applications. We started collaborating with suppliers electronically. We gave staff access from airports, hotels, and coffee shops. And without really noticing, the entire security perimeter disappeared. The office stopped being the thing we're protecting. Now we're protecting people, their identities, their devices, and their data, and that's a much harder problem to solve. At exactly the same time, cyber criminals became significantly more sophisticated. Technology wasn't just becoming more advanced, the attackers were too. Ransomware became a business model. Identity theft became really big business. Organized crime realized something incredibly important. It was often easier to steal money digitally than physically. Suddenly, cybersecurity wasn't just about stopping the odd computer virus, it became about protecting businesses from organized crime enterprises. And that's a very, very different challenge. So remember the story I told you at the beginning about cybersecurity hygiene? That's exactly why that idea stuck with me. As our understanding of germs evolved, personal hygiene became part of everyday life. As our understanding of cyber risk has evolved, cybersecurity has become part of everyday business. And that's why cybersecurity became its own profession. And one of the best ways I found to explain this is through healthcare. Think about your local GP. A GP knows a little bit about a lot of things. They're fantastic. But if you develop a serious heart condition, you're probably going to be referred to a cardiologist. Not because your GP isn't capable, but because cardiologists spend every day focusing on one specific discipline. And cybersecurity has evolved in exactly the same way. Twenty years ago, your IT provider could reasonably understand almost every piece of technology inside a business. Today, think about everything a modern organization uses Microsoft 365, Cloud Storage, Azure, Amazon Web Services, Remote Wers, Mobile devices, identity platforms, business applications, security platforms, third-party suppliers, compliance requirements, artificial intelligence. And it's simply too much for one person to master. Technology itself has become specialized. And because technology became specialized, security became even more specialized. Which brings us to another question I hear all the time. What's actually the difference between an IT provider and a cybersecurity provider? Because a lot of businesses assume they're exactly the same thing, even within the managed service provider world. And I can tell you right now they're not. And that's what we'll unpack next. So, what is the difference? You'll often hear two acronyms. Number one being an MSP, a managed service provider. Second one, an MSSP. Just an extra S in there. A managed security services provider. Now, as soon as I say this, I want to be very careful because we're not saying one is better than the other. There are some outstanding MSPs that have built incredibly capable security teams. Likewise, there are organizations that specialize part purely in cybersecurity and also have very capable technology teams. And the question isn't are you an MSP or an MSSP? The better question is what capability do you actually have? Because saying we have a security person can really mean a hundred different things. It might mean there's one engineer who has an interest in cybersecurity. It might mean they've got someone with years of experience investigating cyber incidents. Or it might mean that they have an entire team of security analysts, engineers, architects, incident responders, and consultants working together. And those are very different levels of capability. Think about healthcare again. If you've broken your arm, your local GP can probably help. If you've had a heart attack, you probably want a cardiologist. And it's not because your GP isn't good at their job, it's because they're actually different jobs. Technology has evolved exactly the same way. IT support focuses on keeping your business running. Cybersecurity focuses on protecting your business. They're closely connected, but they're not identical. So whenever someone tells you they do security, don't stop there. Ask another question. What does that actually include? Do you monitor? Do you respond? Do you do testing? Do you do identity and permission reviews? Can you provide governance advice? Can you conduct vulnerability management? And can you also help customers prepare for audits? Those answers will tell you far more than whether someone calls themselves an MSP or an MSSP. So let's go through some of the buzzwords because there is a lot of terminology, and cybersecurity has a terrible habit of inventing acronyms for absolutely everything. So we'll start with firewalls that I mentioned before. Think of a firewall as a security guard standing at the front gate. Its job is to decide who gets in and who stays out, and what traffic is allowed to move through. It is your first line of defense. Multifactor authentication or MFA. And think of this one as adding a second lock to your front door. If someone steals your key, they still need another way to prove that they should be there. It is also one of the cheapest and easiest security improvements that you can do, and one of the most effective. Antivirus. And I think most people do know what antivirus systems are. They've been around for decades. But think of it like a security guard carrying a list of known criminals. If someone on that list turns up, they're stopped. The challenge is today that attackers are constantly changing their appearance and they're creating new techniques, which means that traditional antivirus alone isn't enough because we don't know who these people are and what tactics they're actually using. So modern endpoint protection is the evolution of antivirus. Instead of simply asking, have I seen this before? it asks, Does this behavior look suspicious? It's definitely smarter, it's definitely faster. It uses cloud intelligence and it's also much better equipped to deal with threats we've never seen before. EDR. EDR stands for endpoint detection and response. And this is where people often get confused. The simple explanation I found is this. Antivirus stops someone breaking into your house. EDR helps investigators understand what happened after they've already gotten inside. It records the activity, it builds timelines, it shows what files were accessed, what programs were run, which users logged in. It's less like a lock and more like a CCTV camera combined with forensic investigators. And here's something I learned during my years working in cyber. Technology is incredibly clever, but it doesn't always understand context. A security tool might see someone logging in, it might see files being copied, it might see someone opening a tool called PowerShell. Individually, those activities might be perfectly normal. Or it might be the beginning of a cyber attack. The technology doesn't always know, and the only way you can detect it with multiple levels of technology is something called defense in depth. And this is something that experienced security analysts will explain to you and where they become incredibly valuable. One of the biggest misconceptions is that security tools magically could stop every attack. They don't. Many of them are designed to detect, some are designed to alert, some are designed to investigate, and some designed to contain. Think about your smoke alarm. It doesn't stop your house catching fire, it tells you there's a fire. And someone still needs to decide what to do next. And there are some tools that include AI, which is becoming fantastic in this space because it's helping reduce alert fatigue. Rather than 10 different tools going, hey, we've noticed something unusual, can you go check it out? It's helping identify patterns that humans might actually miss. It's triaging thousands of alerts in seconds, but ultimately you still often need a human being to make a judgment call. You need someone to ask, is it genuine? Or is this just normal business activity? Have we actually got a contractor doing some testing in here at the moment? And that's why, despite all the advances in AI, human judgment is still one of the most valuable parts of cybersecurity. Our next concept, identity security. Years ago we protected officers. Today we're protecting people. Because if an attacker steals someone's username and password, they often don't need to hack a firewall. They simply need to just log in. Identity has become a new security perimeter. A SOC. Security Operations Center. Imagine your office has alarms, motion sensors, security cameras. Who actually watches them? Because if no one's watching them, they're not actually providing much value. And that's what a security operations center does. It's the people behind the technology, the analysts reviewing alerts, investigating suspicious behavior, escalating genuine threats. Technology generates the information, but you've actually got people making the decisions. Now, there are some AI tools out there at the moment. Some of them are quite pricey to have 24-7 reviews, and at the end of the day, you still want to have an actual person reviewing any suspicious activity within your business. You want that human element. Now let's jump into why cloud doesn't automatically mean secure. One misconception I've heard way too many times over the years is we've moved everything into Microsoft 365 or we're in the cloud now. That's fantastic. Cloud technology is incredible. But moving into the cloud doesn't automatically make you secure. Think about renting an apartment. The apartment building has security, but you still lock your own front door. Microsoft secures Microsoft's environment. Amazon secures Amazon's environment. Google secures Google's environment. You still need to secure your users, your passwords, your devices, your permissions, your data, your backups, your business. The cloud changes where your technology lives. It does not remove your responsibility for protecting it. So when does a business need more security? And this is a question I get asked quite a bit. At what point do we actually need to do more in the cybersecurity space? Unfortunately, there's no magic employee number, but there are two major drivers: growth and regulation. So looking at growth, as businesses grow, they naturally become more complex. You have more employees, more devices, more systems, more suppliers, more customers, more data, which means more risk. For a smaller business, good cyber hygiene might just be enough. If you have strong passwords, multi-factor authentication, password manager backups, device management, those simple controls do go an incredibly long way. But as businesses grow, they usually need more. They need security awareness training, formal policies, incident response plans, vulnerability management, security monitoring, governance. I spoke about regulation, and unfortunately, some industries really don't get a choice. Accountants, financial services, healthcare, legal, government, critical infrastructure. The organizations supporting government, businesses inside large supply chains. Increasingly, customers, insurers, and regulators expect organizations to demonstrate that cybersecurity is being taken seriously. And that's why governance has become such an important part of security. Because good cybersecurity isn't just buying the software, it's understanding your risks, having policies, knowing who owns what, reviewing your controls, testing your processes, and planning for when something eventually goes wrong. So if we actually look at 20 years ago, many organizations had an IT manager. That was usually the most senior technology role. Today, many organizations have both a CIO, a chief information officer, and a CISO, a chief information security officer. Why? Because running technology and managing cyber risk have become two different executive responsibilities. The CIO enables a business through technology. The CISO protects the business from cyber risk. And that's a huge shift. And it shows just how important cybersecurity has become. And we also are seeing a shift. Boards are stunningly caring. And people have asked me why boards suddenly seem so interested in cybersecurity. And the answer is actually pretty simple. They don't care about fireballs and they don't care about antivirus. They don't care about acronyms. They care about risk, revenue, operations, customers, reputation, legal obligations, financial loss. And once something becomes a business problem, boards become interested. Executives become interested. Lawyers become interested. Insurers become interested. And regulators have become interested. Which is exactly why we're saying cybersecurity discussed in boardrooms today. So before we finish, I want to come back to where we started. That poster I spoke about, good cybersecurity hygiene should be as simple as washing your hands. More than 10 years later, I still think that's one of the best explanations I've ever heard. Because cybersecurity isn't just software, it isn't just expensive technology, and it just isn't something for the IT department themselves. It's a collection of small habits that together make an organization significantly safer. And if there's one thing I'd encourage you to do after listening to today's episode, it's one very small, simple question. Who is actually responsible for cybersecurity in our organization? Not IT generally, not technology broadly, cybersecurity specifically. Who's actually monitoring threats? Who's reviewing alerts? Who's responding if something goes wrong? Who's making sure our security controls are actually doing what they think they are? Because if the answer is I think that's covered, there's a good chance no one's actually had that conversation. And that's often where problems begin. Not every business needs a cybersecurity team. Not every organization needs a security operations center. What they do need to understand is where IT support ends and where cybersecurity begins. Because once you understand that difference, you'll start asking much better questions of your internal teams and your external technology providers. And ultimately, that's what this podcast is all about. Helping you ask better questions. In our next episode, we're going to build on today's discussion by looking at something that's changed dramatically over the last few years. What are the actual legal obligations of Australian businesses now when it comes to cybersecurity? What do the regulators expect? What do directors need to know? And why is cybersecurity no longer something businesses can simply choose to ignore? I'll see you in the next episode. I'm Vic, and until next time, keep learning.

SPEAKER_00

Thanks for joining the episode. If you do want to follow me on Instagram at all, you can find me under The Technology Translator. If you would like to email me, Vic at the Technology Translator.au.

SPEAKER_01

And I guess I wouldn't be doing this properly if I didn't say, if you like what you hear, hit the follow button. There will be more of these episodes coming up.