The meeting usually starts with a question that sounds almost too simple.
“Who manages cybersecurity for the business?”
There is normally a quick answer: “Our IT provider.”
Fair enough. So I ask another question.
Who decides what level of cyber risk the business is willing to accept? Who reviews those risks with management? Who knows which systems would hurt the business most if they disappeared tomorrow? Who determines whether the security controls currently protecting the organisation are appropriate for the threats it faces?
The room usually gets a little quieter.
It is not necessarily because the IT provider is doing a bad job. Quite often, they are doing exactly what they were hired to do.
The problem is that somewhere between keeping the technology running and protecting the organisation, nobody established who is responsible for seeing the whole picture.
When Everything Is Working, Security Can Look Fine
Imagine a 40-person professional services firm. We’ll call it Harbour & Co.
They have a managed IT provider. Microsoft 365 works. Their laptops are supported. The network is maintained. New starters receive accounts and devices, backups are running, endpoint detection and response protects their computers, email security filters malicious messages, and multi-factor authentication protects user accounts.
From the outside, Harbour & Co. looks reasonably well protected.
Then a major customer sends them a supplier security questionnaire.
When was your last cyber risk assessment?
Nobody is quite sure.
What is your target Essential Eight maturity level?
There isn’t one.
When was your incident response plan last tested?
Another uncomfortable silence.
How quickly could critical systems be restored following ransomware?
The backups are working, but nobody can confidently explain whether the recovery time actually meets the needs of the business.
Suddenly, the question is no longer whether Harbour & Co. has security.
Clearly, it does.
The question is whether all those controls are part of a deliberate cybersecurity strategy built around the risks of the business.
That distinction matters.
IT Operations, Security Operations and Cyber Risk
A good MSP is one of the most important partners a small or medium business can have. IT operations keep the organisation functioning. Networks need to remain available, Microsoft 365 needs to work, devices need to be maintained, users need support and business applications need to remain operational.
Cybersecurity builds on that foundation.
Controls such as EDR, MDR, email security, Microsoft 365 security, vulnerability management, MFA, Conditional Access, backups and security monitoring exist for good reasons. Each addresses particular risks, and when they are properly designed and implemented, they can dramatically improve an organisation’s resilience.
EDR helps prevent and detect malicious activity on endpoints. Email security reduces exposure to phishing and malicious content. MFA and Conditional Access make stolen credentials harder to exploit. MDR provides continuous monitoring and specialist response capability. Vulnerability management helps identify weaknesses before attackers can exploit them.
These aren’t boxes to tick. They are layers of defence.
But someone still needs to determine which layers the organisation requires, where the gaps are, what should be prioritised and whether those controls continue to address the risks the business actually faces.
That is where cyber risk management and governance enter the picture.
Start With the Risk, Then Build the Defence
Take MDR as an example.
The conversation should not simply be, “Should we buy MDR?”
A risk-based conversation begins differently.
What would happen if an attacker compromised an employee account at midnight? Would anyone notice? What if ransomware began spreading across endpoints? Who would investigate the alert? Who has authority to isolate affected systems? How quickly could the business respond?
If the answers expose a serious detection and response gap, then MDR may be exactly the right control.
The same thinking applies to email security. If phishing, credential theft, business email compromise and malicious attachments represent significant threats to the organisation, strengthening the email security layer makes strategic sense.
This is the important distinction.
The security product is not separate from the strategy. It is an implementation of the strategy.
Good cybersecurity connects the two.
You identify the business assets that matter, understand the threats against them, assess the likelihood and potential impact, determine what level of risk is acceptable, and then implement controls to reduce that exposure.
Risk informs the control. The control reduces the risk. Monitoring tells us whether it is working.
This Is Where Cybersecurity Governance Matters
For Australian businesses, this conversation is becoming increasingly important.
ASD’s Australian Cyber Security Centre received more than 84,700 cybercrime reports during the 2024-25 financial year, approximately one every six minutes. The average self-reported cost of cybercrime for small businesses increased to around $56,600, while medium businesses reported an average cost of approximately $97,200.
The lesson isn’t that every SMB suddenly needs an enterprise security department.
It is that cybersecurity now deserves business-level oversight.
Management doesn’t need to understand every EDR detection or Conditional Access configuration. It does need to understand whether the organisation could detect an attacker, whether critical data can be recovered, whether privileged access is adequately protected and which cyber risks currently present the greatest potential impact to the business.
Someone needs to translate between those two worlds.

So, Who Sees the Whole Picture?
This is where the CISO function becomes important.
A CISO is not there to replace the IT provider or security operations team. The role sits across the environment and connects business objectives, technology, security and risk.
For a large enterprise, that might mean an internal security executive and an entire governance team.
For a 30, 50 or 150-person organisation, employing a full-time CISO may make little commercial sense. The responsibilities, however, still exist.
That is where a virtual CISO, or vCISO, can provide value.
A vCISO can help establish the organisation’s cyber risk profile, assess security maturity, define an achievable roadmap, align controls with frameworks such as the ASD Essential Eight, review policies and incident response capability, measure progress and provide management with visibility over where risk remains.
Just as importantly, the role can help prioritise investment.
Sometimes the recommendation might be to introduce MDR because detection capability is inadequate. Another organisation may need stronger Microsoft 365 security and identity controls. Another might already have excellent technology but desperately need to improve backup recovery, privileged access or incident response.
The answer should depend on the risk, not on whichever product happens to be fashionable that month.
The Question to Ask at Your Next IT Review
At your next technology or security review, there is one question worth asking:
“What are the five biggest cyber risks facing our business right now?”
That question changes the conversation.
It moves beyond whether antivirus is installed or backups are green on a dashboard. It asks what could materially disrupt the organisation, what information would be most damaging to lose, where the organisation is most exposed and what should be prioritised next.
Then ask the follow-up:
“What are we doing about each of them?”
Now your security controls have context.
Perhaps EDR addresses endpoint compromise and ransomware. MDR addresses the risk that malicious activity goes undetected. Email security reduces phishing exposure. Conditional Access reduces identity compromise. Backups address resilience and recovery.
Suddenly, you are not looking at a collection of products.
You are looking at a cybersecurity strategy.
Someone Still Has to Own the Risk
Harbour & Co. eventually completed that security questionnaire, but something more valuable happened in the process.
Management stopped asking, “What security products do we have?”
They started asking, “What cyber risks do we have, and are we managing them appropriately?”
Their IT provider still kept the technology running. Their EDR still protected endpoints. Their email security still filtered threats. Their MDR service still watched for suspicious activity.
None of those things became less important.
They became more valuable because they were now connected to a wider strategy.
That is ultimately the difference between having cybersecurity and managing cyber risk.
Your IT provider can keep the lights on. Your security controls can protect the environment. Your security operations can detect and respond to threats.
But someone still needs to connect those capabilities to the objectives, priorities and risk appetite of the business.
So perhaps the question is not simply:
“Do we have an IT provider?”
The better question is:
“Who is managing our cyber risk?”
Because good cybersecurity is not governance or technology.
It is knowing your risks, choosing the right defences, and making sure they work together.
🌐 Explore our services at Managed Services Australia.
📧 Dial 1300 024 748, shoot us an email at [email protected], or schedule a session with one of our IT specialists.







