Why Isn’t Cybersecurity Solely the IT Team’s Responsibility?

26 Aug 2026 Updated 18 Sep 2026 14 views
Cyber ​​Security for Business

Cybersecurity for business is not solely the IT team’s responsibility because cyber risks can:

  1. Disrupt system-dependent operational processes.
  2. Delay transactions, revenue, and customer service.
  3. Create legal, contractual, and compliance obligations.
  4. Damage the company’s reputation and clients’ trust.
  5. Require risk, budget, communication, and recovery decisions beyond the IT team’s technical authority.

The IT team manages technical controls, while management determines priorities, risk tolerance, and incident preparedness. This division of responsibility is essential because system disruptions can directly affect operations, transactions, and customer service.

Under Article 57 of Law Number 27 of 2022 concerning Personal Data Protection, violations of certain obligations may result in administrative sanctions, ranging from written warnings to fines of up to 2% of annual revenue or annual income, depending on the relevant violation variables.

Note: This provision does not mean that every cyberattack automatically results in sanctions. Data protection, reporting, and communication obligations should be assessed with legal or compliance functions based on the type of data, business sector, contracts, and applicable regulations.

Digital Systems Have Become Part of Business Operations

Digital systems no longer support administrative work alone. They can drive production, transactions, communication, service delivery, and decision-making.

1. Critical Processes Depend on System Availability

Ordering, production, warehousing, shipping, payments, HR, and customer service may be disrupted when applications or networks become unavailable. The level of risk should be assessed according to the processes that depend on each system.

2. Disruption to One System Can Affect Multiple Processes

System integration means that disruption to user identities, databases, APIs, cloud services, or core applications may affect several departments simultaneously. Dependency mapping helps companies identify these potential cascading effects.

3. Manual Procedures May Not Be Able to Replace Digital Systems

Manual processes may be unable to handle transaction volumes, data requirements, authorizations, and synchronization across platforms. Companies should test alternative procedures instead of assuming that all work can simply be transferred to spreadsheets or physical documents.

Security Disruptions Can Delay Transactions and Services

The impact of a cyberattack should be measured by the transactions and services that cannot be completed, not only by the number of affected devices.

1. Transactions May Be Delayed or Unable to Be Processed

Disruptions to applications, databases, payment systems, accounts, or networks may interfere with sales, payments, and billing.

2. Teams May Be Unable to Serve Clients as Usual

Employees may lose access to order statuses, communication histories, or customer information, preventing them from providing clear service updates.

3. Service and Revenue Targets May Be Affected

The duration of a disruption should be translated into delayed transactions, backlogs, lost working hours, and unmet service targets.

The following table can help connect system disruptions with their business impact and tolerable downtime.

Affected SystemBusiness ProcessInterrupted Transaction or ServiceAffected PartiesTolerance Limit
Sales applicationOrderingOrders cannot be processedCustomers and sales teamDetermined by the process owner
Payment systemPayment processingTransactions are delayed or failCustomers and finance teamBased on transaction requirements
Customer databaseCustomer serviceCustomer information cannot be accessedCustomer service team and customersBased on service targets
Warehouse systemOrder fulfilmentInventory and shipments are difficult to verifyWarehouse, sales team, and customersBased on the operational schedule

Cyber Risks Can Create Corporate Obligations

An incident may involve personal data, customer contracts, vendor requirements, service standards, and sector-specific regulations.

1. Incidents May Involve Customer and Employee Data

Management should understand the types of data being processed, where the data is stored, who has access, and the potential impact if the data is exposed, lost, or altered.

2. Companies May Have Contractual Obligations

System disruptions or data loss may affect compliance with service-level agreements, confidentiality provisions, support commitments, and other terms agreed upon with clients or vendors.

3. Reporting Decisions Cannot Be Made by the IT Team Alone

The technical team provides verified facts about an incident. However, legal, compliance, and management functions must assess reporting and communication obligations based on the data involved, contractual terms, business sector, and applicable regulations.

Client Trust Is Part of Cyber Risk

Customers and partners assess not only service quality but also the company’s ability to protect data and maintain operations.

1. Clients May Question the Company’s Ability to Protect Data

Concerns may increase when an incident involves confidential information, accounts, transactions, or personal data.

2. Partners May Reassess the Business Relationship

An incident may lead to additional audits, revised security requirements, requests for evidence of remediation, or a reassessment of the company as a vendor.

3. Reputational Damage Does Not End When Systems Are Restored

Systems may be restored faster than trust. Delayed or inconsistent communication can also prolong reputational damage.

4. Restoring Trust Requires Evidence

Companies should demonstrate improvements in controls, monitoring, governance, and response preparedness. Simply stating that the system is secure may not be enough to address clients’ concerns.

Critical Incident Decisions Are Beyond the IT Team’s Authority

Technical teams can provide analysis and recommendations. However, decisions with operational, legal, financial, and reputational consequences require cross-functional approval.

1. Deciding Whether a System Should Be Shut Down

Isolation can contain an attack, but it may also stop critical processes. The decision should consider both the risk of further spread and the impact of service interruption.

2. Deciding Which Services Should Be Restored First

Recovery priorities should reflect process criticality, system dependencies, customer needs, and downtime tolerance.

3. Approving Communications to Relevant Parties

Information shared with employees, customers, partners, regulators, or the public should be based on verified facts and approved by the relevant functions.

4. Accepting the Risk of Reactivating a System

Reactivation should consider investigation findings, the risk of repeat attacks, operational requirements, and the temporary controls available.

Management Must Establish Risk Tolerance and Protection Priorities

Management should determine business requirements and acceptable risk limits before the IT team selects the technologies and security controls to implement.

1. Identify the Most Critical Business Services

Determine which processes cannot remain unavailable for long, as well as the customers and obligations that depend on those processes.

2. Define Unacceptable Impacts

These may include the loss of certain data, transaction stoppages, unauthorized data changes, or service disruptions that exceed the company’s tolerance limits.

3. Prioritize Budgets Based on Business Impact

Systems with the most serious consequences should receive stronger protection, monitoring, backup, and recovery capabilities.

4. Determine Which Risks Can Be Accepted or Must Be Reduced

Not every risk can be eliminated. Management must decide whether each risk should be avoided, reduced, transferred, or accepted for documented reasons.

The following matrix helps management connect cyber risks with their potential impact and appropriate treatment decisions.

Cyber RiskRelated SystemOperational ImpactImpact on CustomersLikelihoodDecision
RansomwareApplications and databasesOperations stopServices become unavailableAssessed according to system conditionsReduce
Data breachCustomer databaseInvestigation and access restrictionsData may be exposedAssessed according to existing controlsReduce or transfer
Cloud vendor disruptionCloud-based servicesApplications cannot be usedServices are delayedAssessed using service history and SLAReduce or accept
Administrator account takeoverCore systemsUnauthorized changesServices and data are at riskAssessed according to access controlsAvoid or reduce

Cybersecurity Requires Cross-Functional Responsibility

Cross-functional involvement does not mean that every employee must handle technical work. Each party should fulfil responsibilities that match its authority and expertise.

FunctionPrimary ResponsibilityDecision or Contribution
Board of directorsEstablish direction and oversightPriorities, risk tolerance, and resources
Process ownersIdentify critical systems and dataBusiness impact and disruption tolerance
IT or securityOperate technical controlsAccess, patching, monitoring, detection, response, and recovery
Legal and complianceReview obligationsRegulations, contracts, documentation, reporting, and communication
HR and employeesMaintain security in daily activitiesTraining, access management, procedural compliance, and reporting
ProcurementManage vendor riskAccess requirements, security, incident notification, and service termination

1. The Board Establishes Direction and Oversight

The board ensures that cyber risk is monitored as part of enterprise risk and that resources are allocated according to business priorities.

2. Process Owners Identify Critical Systems and Data

Business departments explain the impact if a process, application, or dataset becomes unavailable, exposed, or altered.

3. The IT or Security Team Operates Technical Controls

The IT team implements protection, access controls, patching, monitoring, detection, response, and technical recovery. These measures should be supported by fundamental corporate cybersecurity practices that also involve users.

4. Legal and Compliance Review Corporate Obligations

These functions assess regulations, contracts, documentation, reporting obligations, and incident communications.

5. HR and All Employees Maintain Security in Daily Activities

HR supports security training and access management throughout the employee lifecycle. Every user should also follow established procedures and report suspicious activities.

6. Procurement Manages Vendor Risk

Procurement should ensure that access requirements, data security, incident notifications, support arrangements, and service termination are addressed in vendor agreements.

Use Business Language in Cyber Risk Reports

Cyber risk reports should translate technical findings into information that helps management establish priorities and make decisions.

1. Do Not Stop at the Number of Alerts and Attacks

The number of blocked threats does not explain which services, transactions, or customers are at risk.

2. Connect Vulnerabilities with Assets and Business Processes

Identify the affected system, the business functions that depend on it, and the consequences if the vulnerability is exploited.

3. Show Remediation Progress and Residual Risk

Explain the actions already completed, existing obstacles, completion targets, risk owners, and outstanding decisions.

4. Report Response and Recovery Readiness

Include the results of backup tests, incident simulations, recovery times, and any coordination gaps identified.

Test Preparedness Through Cross-Functional Incident Simulations

Simulations help companies test roles and decision-making authority before a real incident occurs.

1. Use Scenarios That Disrupt Critical Processes

Select scenarios such as ransomware, a data breach, an administrator account takeover, or an unavailable cloud service.

2. Test Escalation Paths and Decision-Making Authority

Confirm who receives the initial report, declares an incident, approves a system shutdown, and establishes recovery priorities.

3. Test Communications with Employees and Clients

Ensure that messages use verified information, have an authorized approver, and can be delivered through alternative channels if the primary system is unavailable.

4. Document Gaps That Must Be Addressed

The simulation should result in improvements to procedures, contact lists, controls, backups, documentation, and assigned responsibilities.

The NIST Cybersecurity Framework 2.0 places Govern alongside Identify, Protect, Detect, Respond, and Recover. This structure demonstrates that cyber risk management covers strategy, policies, roles, oversight, protection, response, and recovery, all of which should be managed in a coordinated manner.

FAQ

The following answers explain how cybersecurity responsibilities and governance should be distributed across a company.

1. Does Responsibility for Cybersecurity Still Rest with the IT Team?

The IT team is responsible for many technical controls. However, decisions involving risk and business impact require the participation of management and the relevant process owners.

2. Does the Board Need to Understand the Technical Details of Cybersecurity?

Not at an operational level. The board needs to understand risks, potential impacts, priorities, and the decisions that require its approval.

3. Who Owns Cyber Risk Within a Company?

Cyber risk ownership depends on the company’s structure and the affected processes. Responsibilities should be explicitly assigned to prevent unclear or conflicting accountability.

4. Is Purchasing Security Tools Enough?

No. Security tools must be supported by governance, processes, expertise, monitoring, response procedures, and recovery capabilities.

5. Why Should Business Process Owners Be Involved?

Process owners understand operational impacts, critical data, disruption tolerances, and the services that should be prioritized.

6. How Should Cyber Risk Be Reported to Management?

Connect technical risks with assets, business processes, customers, potential losses, existing controls, residual risks, and the decisions required.

Conclusion

If a system disruption can stop transactions, expose critical data, or affect customer service, cybersecurity should be managed as a business risk. Management must establish critical processes, disruption tolerances, budget priorities, and incident decision-making authority, while the IT team implements and tests the appropriate technical controls.

The next step is to map systems to business processes, assign clear responsibilities, and test the company’s preparedness through cross-functional incident simulations.

Manage Cyber Risks Before They Disrupt Your Business

If system security has become a concern for management, operational continuity, or client trust, SMART IT can help your company evaluate its cyber risks and protection requirements. Discuss your systems, critical processes, and priority risks to ensure that your company’s cybersecurity strategy aligns with its business needs.

PT SMARTIT MANTAP DIGITAL INDONESIA

Vieloft Ciputra World, Suite 10-01

Ciputra World Superblock Complex

Jl. Mayjen Sungkono No. 89, Surabaya, East Java, Indonesia 60224

Phone: +6281130576888 / +628113426391

Email: hello@smart-it.co.id

Facebook: Smart IT Indonesia

LinkedIn: Smart IT Indonesia

Instagram: smartitcoid

References

1. National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29). U.S. Department of Commerce.

https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf

2. Republic of Indonesia. (2022). Law of the Republic of Indonesia Number 27 of 2022 concerning Personal Data Protection. Legal Documentation and Information Network of the Ministry of Communication and Digital Affairs.

https://jdih.komdigi.go.id/produk_hukum/view/id/832/t/undangundang%2Bnomor%2B27%2Btahun%2B2022

Share this article