All resources
Cybersecurity

Managed cybersecurity: who is responsible for what?

Clarify responsibilities with your cybersecurity provider: service scope, business decisions, escalation and evidence that work is complete.

Monitoring digital activities and risks

Introduction

Managed cybersecurity assigns agreed security tasks to an external provider. To understand who does what, identify who performs each task, who authorizes changes and who checks the outcome. The word “managed” alone does not define service coverage. A useful agreement connects technical work to the people who can make decisions about its business impact.

Start with the systems actually covered

Your organization may use an IT provider, several cloud applications and devices managed in different ways. Before dividing responsibilities, put these elements on one list. Identify the accounts, devices and applications included in the proposed service, as well as any environments excluded from it. A list of purchased products does not establish who follows up on them.

The Canadian Centre for Cyber Security recommends identifying the systems within scope and documenting incident response responsibilities. These principles help frame the conversation with your providers. The worksheet below is an original planning tool to adapt to your agreement, rather than a service certification or a statement that your organization meets a standard.

Baseline cyber security controls for small and medium organizations

Separate technical work from business decisions

For planning purposes, we suggest three distinct questions: who performs the task, who can authorize its effect on operations, and who confirms completion? One person may hold several roles, but the allocation should remain explicit. A provider might recommend blocking an account; your organization needs agreed conditions under which that provider can act directly.

Include the owner of the affected application or business activity. A technically available change may interrupt essential work. That owner contributes the operational context needed to decide. Avoid phrases such as “coordinate with IT” without identifying a contact, a communication channel and an alternate when the usual contact is unavailable.

Cybersecurity operations centre illustrating shared responsibilities between an organization and its managed provider
Managed cybersecurity requires clear ownership, escalation thresholds and evidence of closure.

Complete a responsibility worksheet together

Select a recurring task and fill in the following fields with your team and the provider. Start with one concrete activity instead of attempting a comprehensive risk catalogue. Where answers conflict, keep the issue open until someone makes and records a clear decision.

  • Task and scope: what action applies to which accounts or devices?
  • Execution: who receives the request and performs the work?
  • Authority: who decides, and which actions are already permitted?
  • Coverage: what hours, channels and conditions have been agreed?
  • Escalation: who handles a blocked task or an out-of-scope situation, and who is their alternate?
  • Completion: what evidence establishes the outcome, and who reviews it?

Fictional example: an account flagged on a Friday

A fictional small business receives a report about its sales manager’s account. The security provider can examine the information covered by its agreement. The IT provider administers the account, while the sales director understands the operations that depend on access. Without a prior allocation of responsibility, each participant could wait for another to make a decision.

In this planning example, the three parties complete a worksheet naming who examines the report, who may suspend access under agreed conditions and who informs the affected person. They also record the procedure when a responsible contact is absent. The scenario represents no actual response time or customer result. Its purpose is to expose missing questions before a real situation occurs.

Check that follow-up leads to completion

During a service review, select one completed action and one pending action. Ask what was observed, what was decided, who decided and what remains outstanding. A count of received notifications does not answer those questions. A short list of open decisions can be more useful than a lengthy report with no clear recipient or next step.

Repeat this exercise when a new application enters service or a provider changes. The initial worksheet is a starting point that should evolve with your organization. If you want to prepare this allocation with Loupe Technologies, managed cybersecurity scoping can help examine the systems involved and the operating arrangements that need to be agreed.

Frequently asked questions

Does managed cybersecurity replace our IT team?

Not necessarily. It can complement work performed by your team or an existing IT provider. Discuss system administration, protection follow-up, change authorization and business oversight separately. The agreement should make the selected allocation explicit.

Does “managed” mean continuous monitoring?

Check the agreement. Ask about coverage hours, reporting channels, escalation conditions and the interventions actually included. Do not infer continuous service or a response-time commitment from the service name alone.

What should we request in a service report?

Ask for the items examined, work completed, decisions still required and the person responsible for each. Include the agreed evidence of completion for finished tasks. The format should help your team decide what happens next.

Explore support for your needs

Sources and references

  1. Baseline cyber security controls for small and medium organizations — Canadian Centre for Cyber Security

Continue reading

View all resources