ITML IT Leadership Q&A Resource Center:
IT Security and Risk
Return to the main IT Leadership Knowledge Base page
Table of Contents
- What does an IT manager need to know about cybersecurity?
- How do I respond to a security incident as an IT leader?
- How do I build a culture of security awareness?
- How much cybersecurity should a non-security IT manager understand?
- How do I talk to the board about cyber risk?
What does an IT manager need to know about cybersecurity?
IT managers, even those not specifically focused on security roles, need sufficient cybersecurity understanding to make informed decisions, communicate effectively with security specialists and executive leadership, and ensure appropriate security considerations are integrated into their team’s work, even without needing deep technical security expertise themselves.
Understanding fundamental risk concepts is essential, including how to think about likelihood and impact when evaluating security risks, and genuine appreciation that perfect security is neither achievable nor typically the appropriate goal, since security investment should be calibrated to genuine risk levels and business context rather than pursuing maximum possible security regardless of cost or operational impact.
Familiarity with common threat categories helps inform reasonable judgment about security priorities, including understanding basics of phishing and social engineering attacks, ransomware and malware risks, and the significance of both external attacker threats and insider risk, whether malicious or accidental, from within the organization.
Basic understanding of foundational security controls provides useful context for informed decision-making, including concepts like multi-factor authentication, appropriate access control and least-privilege principles, patch management importance, and basic encryption concepts, even without needing deep technical implementation knowledge of these specific controls.
Awareness of relevant regulatory and compliance requirements applicable to your industry and organization helps ensure appropriate attention to compliance-driven security requirements, even if detailed compliance management falls to specialized compliance or legal functions rather than IT management directly.
Understanding incident response fundamentals, including your role and responsibilities if a security incident occurs within your area of responsibility, ensures appropriate preparedness rather than confusion or delayed response if an actual incident occurs. This includes understanding appropriate escalation procedures and your specific responsibilities during incident response.
Recognizing the importance of security culture and awareness within your own team, including modeling appropriate security behaviors yourself and supporting security awareness training and practices, helps ensure security isn’t treated as solely the responsibility of dedicated security specialists but rather a shared responsibility across the organization.
Ability to communicate effectively with dedicated security specialists, translating between technical security concepts and business-relevant framing for your own stakeholders, requires sufficient security literacy to engage meaningfully in these conversations rather than either dismissing security considerations due to limited understanding or deferring entirely without genuine engagement in security-related decisions affecting your area.
Finally, staying reasonably current with evolving security threat landscape and best practices, even without deep technical specialization, helps ensure your security understanding doesn’t become significantly outdated given how rapidly both threats and defensive best practices continue evolving. Many IT managers benefit from periodic security awareness training specifically designed for leadership audiences, providing appropriate depth of understanding without requiring the specialized technical expertise expected of dedicated security professionals.
How do I respond to a security incident as an IT leader?
Responding effectively to a security incident as an IT leader requires calm, decisive action following established procedures, while providing clear leadership and communication throughout what is often a high-stress, high-visibility situation.
Immediately activate your organization’s established incident response plan if one exists, ensuring appropriate technical and leadership personnel are engaged according to predetermined roles and escalation procedures, rather than improvising response coordination during the high-pressure moment of an actual incident. If no formal plan exists, this experience often highlights the critical importance of developing one for future preparedness, even as you must manage the current situation without this benefit.
Prioritize containment and damage limitation as an immediate technical priority, working closely with your security team or specialists to stop the incident from causing further damage, even before fully understanding the complete scope and cause of the incident. Early containment actions, even if imperfect, often prove more valuable than delayed action while seeking complete understanding of the situation.
Establish clear incident command and communication structure, designating a specific incident commander responsible for coordinating response efforts and ensuring clear, consistent internal communication throughout the incident, avoiding the confusion and duplicated effort that can result from unclear leadership during crisis situations.
Communicate proactively and honestly with relevant stakeholders, including senior leadership, potentially affected customers or partners, and regulatory bodies if required, based on the nature and severity of the incident. Transparent, timely communication, even when the news isn’t positive, generally serves the organization’s interests better than delayed or overly minimized communication that later proves inaccurate as more information emerges.
Document the incident and response actions thoroughly as they occur, rather than relying on memory to reconstruct events afterward, since detailed contemporaneous documentation supports both effective response coordination and later post-incident analysis, along with potential legal or regulatory requirements for incident documentation.
Engage appropriate external resources as needed, including legal counsel, regulatory notification requirements, cyber insurance providers, and potentially external incident response specialists if the incident exceeds your internal team’s capacity or expertise, recognizing that attempting to handle a significant incident entirely with internal resources when external expertise would genuinely help can sometimes worsen outcomes.
Maintain composure and provide steady leadership throughout the incident, recognizing that team members and stakeholders will take significant cues from your demeanor and communication style during a high-stress situation. Visible panic or disorganized leadership can significantly worsen team performance and stakeholder confidence during an already challenging situation.
Finally, conduct a thorough post-incident review after the immediate crisis has been resolved, focusing on genuine learning and systemic improvement rather than blame assignment, ensuring lessons learned translate into concrete improvements to your security posture, incident response procedures, and organizational preparedness for future incidents, since incidents that don’t produce meaningful organizational learning represent a missed opportunity for genuine improvement despite the real cost and disruption they’ve already caused.
How do I build a culture of security awareness?
Building genuine security awareness culture requires moving beyond compliance-focused, checkbox-style annual training toward sustained, engaging efforts that help employees genuinely understand and internalize security-conscious behavior as a natural part of their daily work rather than a separate, occasionally addressed obligation.
Begin with leadership modeling, ensuring senior leaders, including yourself, visibly demonstrate security-conscious behavior in their own daily practices, since employees often take stronger cues from observed leadership behavior than from formal policy statements or training content alone. Leaders who visibly bypass security practices for convenience send a powerful, damaging message that undermines broader security culture efforts regardless of how well-designed formal training programs might be.
Make security training genuinely engaging and relevant, moving beyond generic, one-size-fits-all content toward training that connects to employees’ actual daily work and provides genuinely useful, actionable guidance rather than abstract security concepts disconnected from practical application. Using real, relevant examples and scenarios specific to your organization tends to produce significantly better engagement and retention than generic, purchased training content that doesn’t feel specifically relevant to employees’ actual context.
Implement regular, varied reinforcement rather than relying solely on annual training events, since security awareness naturally fades over time without ongoing reinforcement. This might include periodic phishing simulation exercises with constructive, educational follow-up rather than purely punitive responses to failures, brief regular security tips or reminders, and incorporating security considerations into broader organizational communications rather than treating security as an entirely separate communication stream.
Create psychological safety around reporting security concerns or mistakes, ensuring employees feel comfortable reporting suspicious activity, potential phishing attempts, or even their own security mistakes without excessive fear of punishment or embarrassment. Organizations where employees fear negative consequences for reporting security concerns often experience delayed incident detection and response, since employees may hesitate to report genuine concerns or mistakes due to this fear.
Recognize and celebrate positive security behavior, publicly acknowledging employees who demonstrate strong security awareness, such as correctly identifying and reporting phishing attempts, which reinforces desired behavior more effectively than purely focusing on negative consequences for security failures.
Involve employees in security awareness efforts beyond purely passive training consumption, such as security champion programs that identify enthusiastic employees within various departments who can help reinforce security awareness messaging and serve as accessible points of contact for security-related questions within their specific teams.
Measure and track security awareness culture indicators over time, such as phishing simulation performance trends, security incident reporting rates, and periodic culture surveys, using this data to continuously refine your security awareness approach rather than assuming initial program design remains optimal indefinitely without ongoing adjustment based on actual effectiveness data.
Finally, recognize that building genuine security culture takes sustained, long-term effort rather than being achievable through any single initiative or training program, requiring patient, consistent investment over an extended period to genuinely shift organizational behavior and mindset regarding security-conscious practices as a natural, integrated part of daily work rather than a separate, occasionally addressed compliance obligation.
How much cybersecurity should a non-security IT manager understand?
Non-security IT managers need sufficient cybersecurity literacy to make informed decisions, communicate effectively with security specialists and business stakeholders, and ensure appropriate security considerations are integrated into their team’s work, without requiring the deep technical specialization expected of dedicated security professionals.
At minimum, non-security IT managers should understand fundamental risk concepts well enough to engage meaningfully in risk-based discussions, including basic understanding of how likelihood and impact factor into security risk assessment, and genuine appreciation that security decisions inherently involve trade-offs between security, cost, and operational convenience rather than pursuing maximum security regardless of these other considerations.
Familiarity with your organization’s specific security policies and procedures relevant to your area of responsibility is essential, ensuring you can appropriately guide your team’s compliance with these requirements and recognize situations that require escalation to dedicated security specialists rather than attempting to handle security-significant situations without appropriate expertise.
Understanding basic security hygiene practices relevant to your specific technical domain provides practical value, such as patch management importance for infrastructure managers, secure coding basics for development managers, or access control principles for those managing systems with sensitive data access.
Awareness of your role and responsibilities during security incidents affecting your area is critical, ensuring you understand appropriate escalation procedures and your specific responsibilities if an incident occurs, even if detailed technical incident response falls primarily to dedicated security specialists.
Sufficient understanding to effectively communicate with dedicated security teams, translating between security-specific technical concepts and business-relevant framing for your own stakeholders and team members, requires enough security literacy to engage meaningfully in these conversations rather than either dismissing security input due to limited understanding or deferring entirely without genuine engagement.
That said, non-security IT managers generally don’t need deep technical expertise in specialized security domains like penetration testing methodologies, advanced threat hunting techniques, or detailed security architecture design, which appropriately remain the domain of dedicated security specialists with focused expertise in these areas.
The appropriate depth of security understanding may also vary based on your specific role and organizational context, with managers overseeing particularly sensitive systems or data, or operating in heavily regulated industries, likely benefiting from somewhat deeper security literacy than managers in less security-sensitive contexts.
Finally, recognizing the limits of your own security expertise and knowing when to engage dedicated security specialists is itself an important security competency, since attempting to handle security-significant decisions without appropriate expertise, due to either overconfidence or reluctance to involve additional stakeholders, can create meaningful organizational risk regardless of how much foundational security literacy you’ve developed.
How do I talk to the board about cyber risk?
Talking to the board about cyber risk requires translating technical security concepts into business-relevant risk framing that connects to the board’s fundamental governance and fiduciary responsibilities, while avoiding both excessive technical detail and oversimplified reassurance that doesn’t reflect genuine risk complexity.
Frame cyber risk explicitly in business impact terms, discussing potential financial cost, operational disruption, regulatory and legal exposure, and reputational damage that could result from various cyber risk scenarios, rather than presenting purely technical vulnerability or threat information without clear connection to these business-relevant consequences.
Provide appropriate context for evaluating your organization’s cyber risk posture, potentially including benchmarking against industry peers, results from independent security assessments or audits, and honest assessment of both genuine strengths and areas requiring continued investment or attention, avoiding either alarmist framing that doesn’t reflect genuine relative risk level or overly reassuring framing that understates real, ongoing risk exposure.
Present cyber risk using consistent, business-relevant risk categorization and prioritization, helping the board understand which risks represent your most significant current exposure requiring priority attention and investment, rather than presenting an undifferentiated list of numerous technical vulnerabilities without clear prioritization guidance.
Address specific board governance interests directly, including questions boards typically focus on such as how your cyber risk management compares to industry peers and regulatory expectations, what specific investments are being made to address identified risks, and what the organization’s incident response readiness looks like if a significant incident were to occur despite preventive efforts.
Use clear, non-technical language throughout, avoiding cybersecurity jargon and explaining any necessary technical concepts through business-relevant analogies or clear, accessible explanation rather than assuming board members share your technical vocabulary or deep technical understanding.
Provide balanced perspective that avoids both minimizing genuine risk, which could create false confidence and potentially expose the board to governance liability if risks aren’t appropriately communicated, and excessive alarmism that doesn’t provide constructive context for informed decision-making, instead aiming for honest, calibrated risk communication that supports genuinely informed board oversight.
Include clear information about current security investment and roadmap, helping the board understand not just current risk exposure but also planned mitigation efforts and associated resource requirements, connecting security investment requests explicitly to specific risk reduction rather than presenting security spending requests without clear risk-based justification.
Prepare for likely follow-up questions, anticipating what board members are likely to ask based on their governance and risk oversight responsibilities, and ensuring you or your team can provide credible, well-informed responses rather than being caught unprepared by predictable governance-focused questions.
Finally, establish regular, ongoing board communication regarding cyber risk, rather than treating board cyber risk communication as an occasional or crisis-driven activity, since consistent, regular reporting helps build board familiarity and confidence in your organization’s risk management approach over time, rather than relying purely on periodic, potentially anxiety-inducing updates that lack broader context from ongoing, regular communication.
Thinking of becoming an IT Managers? Click here to take our free IT Management Assessment!