Article

Security marketing sells sophisticated adversaries, because sophisticated adversaries justify sophisticated products. But look at how mid-sized companies actually get hurt, and the story is usually mundane: an account that should have been disabled months ago. MFA that was “rolled out” except for the exceptions. A firewall rule added for a vendor in 2022 that nobody remembers. Backups that ran nightly and were never once tested with a restore.

None of these are technology failures. Every one is an ownership failure—a task that lived in the gap between the MSP, the security vendor, the internal admin, and “whoever set that up.”

Why the gaps form

Tools create a comfortable illusion of coverage. Buying an email security product feels like handling email security. But every tool has edges, and the edges are exactly where responsibility is fuzziest. The vendor owns the product. Who owns the exceptions, the config drift, and the question “is this still right for how we work now?”

Five questions that surface unowned risk

Who reviewed active accounts and access in the last quarter? Who can name every device that touches company data? Who tested a backup restore this year—actually restored something? Who reads the alerts, and what happened to the last one? Who owns the gap between any two of your security tools?

Any answer that starts with “I think…” is the finding. You do not need a bigger security stack to fix it. You need every one of those questions to have a name attached—and a calendar.

— IAN BERKOWITZ, FOUNDER & CEO, IRONGUARD IT

← All insights