By Aaron Fansler, CEO, FrontLine Cyber Solutions
This is probably going to be one of my more controversial articles. Not because I think IT professionals aren’t talented, they absolutely are. Not because I think IT isn’t critical to every organization, it absolutely is.
The controversy comes from a question I’ve asked for years:
“Why do we continue to expect IT professionals to be cybersecurity experts?”
They’re not the same profession. They never have been. Yet organizations continue to combine the two roles, assuming one naturally includes the other.
After nearly 25 years in cybersecurity, and after responding to countless security incidents, I can confidently say that assumption has cost organizations millions of dollars.
A Doctor Is Still a Doctor…
Let’s use a medical analogy since a very good friend of mine is a spine surgeon.
Suppose you’ve severely injured your spine. Multiple discs are damaged. You require complex spinal surgery. Would you go to your family physician?
Of course not, well most of you wouldn’t.
Your family doctor is an excellent physician. They diagnose illnesses, prescribe medications, and provide comprehensive medical care. But when it comes to replacing spinal discs, they would be the first person to tell you that you need a specialist.
I know some people reading this would probably still go to their family doctor. Why would they still do that?
Because in their mind, although they’re both doctors, one has spent years receiving additional education, specialized training, performing surgeries, and continually refining highly technical skills in a very specific discipline.
No one considers that insulting to family physicians. It’s simply recognizing that specialization matters.
IT and Cybersecurity Follow the Same Model
The technology industry is no different. A skilled IT professional understands:
- Servers
- Networks
- Microsoft 365
- Cloud infrastructure
- Active Directory
- Virtualization
- End-user support
- Storage
- Backups
- System administration
Those skills are incredibly valuable. Every successful organization depends on them. Cybersecurity professionals, however, start with many of those same foundational IT skills—and then build upon them with years of specialized education and experience. That additional specialization often includes:
- Threat hunting
- Malware analysis
- Digital forensics
- Incident response
- Detection engineering
- Adversary emulation
- Offensive security
- Security architecture
- Vulnerability research
- Exploit development
- Secure system design
- Threat intelligence
- Industrial Control System (ICS) security
- Compliance frameworks such as NIST, CMMC, IEC 62443, and NERC CIP
The difference isn’t that one profession is better than the other. The difference is that they’re solving different problems.
Reactive vs. Proactive Security
One of the biggest differences I see is how organizations approach security technology. Many IT departments rely almost entirely on signature-based security tools.
- Traditional endpoint protection.
- Known Indicators of Compromise.
- Known malware signatures.
- Known bad IP addresses.
- Known attack patterns.
Notice a trend? Everything I just listed depends on something already being known. That means the attack has already happened somewhere. Someone else became the first victim, someone else analyzed it, someone else developed a signature, and someone else distributed that update. Only then can your tools recognize it. That’s not proactive security, that’s 100% reactive security.
Signature-based detection remains an important layer of defense, but it should never be mistaken for a complete cybersecurity strategy. Modern attackers routinely modify malware, change infrastructure, use legitimate administrative tools, and exploit trusted software specifically to bypass signature-based detection. Waiting for yesterday’s indicators to identify today’s attack puts defenders at a constant disadvantage.
The Last Three Ransomware Cases
Unfortunately, this isn’t just theory. Our last three Incident Response (IR) engagements all shared a common theme. Each organization believed their cybersecurity was being adequately handled by internal IT personnel. Each organization believed they had the necessary protections in place. Each organization was ultimately compromised by ransomware. Let me be clear, this isn’t about assigning blame to the IT staff involved (well at least not all of the blame). In every case, they were doing the best they could with the knowledge, resources, and responsibilities they had. The issues are that they were expected to perform a role that requires specialized expertise and that expectation came from the C-level signing off on going with just and IT staff with zero cybersecurity experience just to save money.
The investigations identified gaps in security controls, monitoring, detection, and preparedness that attackers were able to exploit. Those shortcomings didn’t necessarily stem from a lack of effort, they reflected the reality that cybersecurity requires dedicated focus, continuous training, and specialized experience beyond traditional IT operations.
That’s an organizational decision, not an individual failure.
Cybersecurity Is Its Own Discipline
Years ago, IT and cybersecurity were often viewed as the same thing. That made sense. Networks were smaller, threats were less sophisticated, compliance requirements were minimal, nation-state attacks were rare allowing companies to get by with the old saying “security through obscurity”
Today? Not so much.
Cybersecurity has become its own engineering discipline.
We now have specialists dedicated to:
- Offensive security
- Defensive security
- Threat intelligence
- Detection engineering
- Security operations
- Cloud security
- OT security
- Identity security
- Application security
- Digital forensics
- Malware reverse engineering
- Incident response
No one person can master every one of those fields while simultaneously managing help desk tickets, replacing switches, deploying Microsoft 365, maintaining backups, and troubleshooting printers.
Yet that’s exactly what many organizations expect from their IT departments.
Why This Keeps Happening
The answer is usually simple. As I eluded to above, the C-level and the “budgets”. Hiring one IT person is less expensive than hiring an IT team and a cybersecurity team. On paper, combining the roles appears efficient and looks good to the board. However, in practice, it often creates gaps that aren’t discovered until after an incident. By then, the cost of recovering from ransomware, business interruption, legal expenses, regulatory reporting, and reputational damage can far exceed what proactive investment in cybersecurity would have required.
The Best Organizations Understand the Difference
Ironically, the strongest cybersecurity programs I’ve seen aren’t the ones where IT and cybersecurity compete. They’re the ones where they work together. IT builds and maintains reliable technology where as cybersecurity identifies and manages risk. IT keeps systems running so the company can make money, cybersecurity helps keep those systems resilient against evolving threats which allows IT to keep the systems running. They’re complementary disciplines, not interchangeable ones.
A Better Way Forward
Organizations shouldn’t stop investing in IT, modern businesses cannot function without skilled technology professionals, and AI will not replace that. But cybersecurity deserves the same respect we give every other specialized profession.
We don’t expect family physicians to perform spinal surgery, we don’t ask civil engineers to design jet engines, we don’t ask electricians to build bridges, therefore, we shouldn’t assume that because someone is excellent at Information Technology, they automatically possess the specialized knowledge required to defend against today’s cyber threats.
Cybersecurity has grown into its own profession for a reason. The threat landscape has evolved. The skills required have evolved. Our expectations must evolve as well.
When organizations recognize that distinction, IT and cybersecurity become partners instead of substitutes, and that partnership is often one of the strongest defenses an organization can build.