Top Cybersecurity Myths: We Have a Great IT Department
- Contributor
- Allison D. Ward
Oct 2, 2026
Cybersecurity misconceptions are more than harmless misunderstandings. They can create gaps in your defenses and expose your organization to unnecessary risk. In our Top Cybersecurity Myths series, we examine common myths and explain the real-world security challenges they can create.
MYTH: We’ve never had a breach. Our IT department must be keeping us secure.
Have you heard this sentiment from the C-level of your organization? Do you find yourself saying this in management or budget meetings as a reason why additional IT or information security expenses are not justified? Have you heard this as a justification for why your organization doesn’t need to hire a separate information security officer?
You’re not alone. Many organizations view IT and information security as one and the same. They assume that because IT is doing a great job, the organization must be secure and have little risk of being affected by malware, hacking, phishing, breaches, or other incidents.
There are two primary reasons why this is a myth.
IT and information security are different.
IT and information security are two very different functions, and relying on the IT function alone to secure your organization would be a disservice to you, your clients and other constituents, and your mission. While IT and information security often work in conjunction with each other, they have different goals, priorities, and required skill sets.
IT is needs-focused and has the ultimate goal of helping the organization with ongoing maintenance and support of the technology, infrastructure, and systems. The IT department resolves end-user issues, recommends enhancements to infrastructure, and works to increase the effectiveness and efficiency of existing technology. IT staff must have very specific technical knowledge and competencies related to the hardware, software, and network components actually used within the organization.
The primary goal of the information security department staff is to assess risks, design controls to mitigate those risks, and establish monitoring procedures to identify deviations. Information security staff members must maintain competencies related to risk evaluation and mitigation. While information security staff must have a basic understanding of various forms of technology, the role typically does not require the same level of technical detail and hardware-specific knowledge that IT does.
Security often takes a back seat.
IT and information security are generally not income-producing departments, and these two functions often share budgets and resources. When budgets get tight, the needs of IT—supporting the infrastructure and ensuring technology runs as intended—often take precedence over the security-related needs, tools, and processes of the information security department.
It’s imperative for organizations to understand how IT and information security work together, the differences between them, and how to empower them to flourish in tandem. Efficiency and effectiveness do not automatically mean security. And while your IT department may perform at a high level and staff may experience ease and efficiency in their day-to-day work, the reality is that the solutions may not be secured adequately if staffing and budgets are not allocated sufficiently between
IT and information security.
Please contact us with any questions or to discuss how we can help your organization assess and reduce your cybersecurity risk.

















































































































































































































































































































































































































































































































































































































































































































































