← All articles

Leadership and governance

Security is not an IT problem

Three decisions no technical team can make on leadership's behalf, and why company size was never a defense.

Published January 27, 2026 · Updated September 1, 2026

There's a division of labor almost everyone accepts: security is handled by "the IT person" while leadership gets on with selling, producing and growing. It sounds tidy and it's false — not because the technical part is unnecessary, but because some decisions can't be made by a technical team without inventing an answer.

Three decisions that don't get delegated

None of these is a technical question. All three block the technical work until someone on the business side answers them:

  1. 1

    What information cannot disappear

    Your client list, your designs, your quotes, your books. Not everything is worth the same, and protecting everything equally is the most expensive way to protect badly. Someone has to say what comes first, and that ranking is a business call.

  2. 2

    Who should be able to see what

    Not who can today — that's a fact, and it's usually broader than anyone remembers authorizing. Who *should*. The gap between those two lists is, almost always, the work that's pending.

  3. 3

    How long the operation can be down

    An hour, a day, a week. The answer sets how much it's worth investing in being able to come back, and it's the only one of the three that converts directly into a budget.

Size was never a defense

"Who would bother with us?" is a reasonable question if you picture someone choosing targets. That isn't how most of what happens works: programs sweep internet addresses continuously, probing whatever is exposed. They don't ask who owns a server before touching it — they find what answers.

That changes the question. It isn't "are we interesting?", it's "what of ours is reachable from outside, and since when?" The second one has an answer, and it can be checked.

What actually moves the needle

The measures that change the outcome most aren't the expensive ones. They're the ones that hold up:

  • Two-step authentication, starting with email, banking and admin access. It's what turns a leaked password into a scare instead of an incident.
  • Backups someone has actually restored. A backup that was never restored is a hypothesis. The useful question isn't whether there's a backup, it's when a file was last recovered from it.
  • Access cleanup. Every person who leaves, every vendor you switch and every system you stop using leaves a door behind. Reviewing that list twice a year costs an afternoon.

The cost that never shows up in the books

When people think about the cost of an incident they think about the ransom or the fine. The expensive ones are usually different: the time with the operation stopped, the trust of a client that took years to build, and the contract that didn't get signed because there was nothing to answer the last meeting's question with.

That last one is no longer hypothetical in most industries. We wrote it up separately, with what actually counts as an answer: how to prove you vetted your vendors.

Where we fit

If the problem is that nobody has the judgment or the time to make those three decisions, there's the fractional CTO or CISO: technical and risk leadership for a fraction of the time, without a full-time hire on payroll.

And if the problem is that there's no way to see the current state, Red Cricket Cloud brings eight modules into one subscription — among them Passwords & Backups, which is exactly the third list above. There is a 30-day trial, no credit card. And if you would rather make those three decisions with someone alongside you, let's talk.

Eight modules, one subscription

Vendor Risk, Attack Surface, Breach Exposure and five more modules under a single contract. Nothing to install.

Start a 30-day trial, no card