From Infrastructure to Cyber Security: Why IT Teams Are Taking on More Responsibility
From Infrastructure to Cyber Security: Why IT Teams Are Taking on More Responsibility
There was a time when running IT infrastructure felt relatively straightforward.
I don’t mean to suggest it was easy. Keeping systems available, managing storage growth, planning upgrades, maintaining backups and troubleshooting complex outages was challenging enough. But the boundaries of the role were generally understood.
If the business wanted reliable technology, the infrastructure team built it, operated it and kept it running. Most technology professionals who have been around for more than a decade will recognise that world.
Over the last few years, however, those boundaries have changed considerably.
Infrastructure teams are no longer responsible only for servers, networks, storage and cloud platforms. They are increasingly expected to play a central role in cyber security, technology risk, compliance, resilience and, more recently, AI governance.
The IT manager who once spent most of their time thinking about server capacity and network performance is now expected to have an opinion on ransomware. Boards want reassurance that cyber risks are being managed. Auditors want evidence. Cyber insurers have increasingly detailed questionnaires. Regulators are asking tougher questions about how organisations protect their systems and data.
And now AI has introduced another layer of complexity.
What information can employees safely share with AI tools? How do we prevent sensitive data from ending up somewhere it shouldn’t? Which AI services are being used across the organisation? Who is responsible for overseeing their use?
For many organisations, the answer to that last question is the same person who was managing the infrastructure yesterday.
Somewhere along the way, security landed on their desk.
Why Cyber Security Can Feel Like a Different Discipline
Most infrastructure professionals never expected to find themselves in this position.
They built careers around servers, storage, networking, cloud platforms and operational support. They understand technology deeply, but cyber security can appear to be a completely different discipline with its own terminology, frameworks, regulations and specialists.
That can create an uncomfortable feeling.
Over the space of a few years, responsibilities have expanded well beyond the traditional boundaries of infrastructure management. Questions that once sat elsewhere in the organisation are increasingly landing with technology teams.
The result is that experienced IT professionals can suddenly find themselves trying to determine which of the hundreds of cyber security risks being discussed actually deserve their attention first.
I’ve had versions of this conversation countless times.
The person sitting opposite me is usually highly experienced. They’ve led infrastructure teams, managed major outages and delivered complex transformation programmes. They’re trusted by their organisation because they consistently solve difficult technology problems.
Yet when the conversation turns to cyber security, they often describe feeling as though they’re starting again from scratch.
In reality, they usually aren’t.
Infrastructure and Cyber Security Have More in Common Than You Think
The longer I’ve worked in cyber security, the less convinced I’ve become that infrastructure and security are completely separate disciplines.
Some of the best security outcomes I’ve seen have come from people who didn’t start their careers in cyber security at all.
They came from infrastructure backgrounds where understanding dependencies, controlling change, monitoring critical systems, maintaining availability and planning for failure were already fundamental parts of the job.
Those skills translate remarkably well.
Infrastructure professionals often undersell themselves when cyber security becomes part of their responsibility. They focus on the terminology, frameworks or technologies they haven’t encountered before and overlook the experience they already have.
But many of the principles behind effective cyber security are familiar:
You need visibility of your environment.
You need to understand what is important.
You need appropriate controls around critical systems and data.
You need monitoring that tells you when something is wrong.
You need a plan for responding when incidents occur.
And you need confidence that the organisation can continue operating when things go wrong.
None of those ideas should feel particularly unfamiliar to someone who has spent years running critical IT infrastructure.
Technology Risk Is Now Business Risk
What has changed most dramatically is the context in which these decisions are being made.
Technology risk is no longer viewed purely as an IT issue.
A ransomware attack can stop business operations entirely. A data breach can lead to regulatory scrutiny, financial loss and reputational damage. Poorly governed AI tools can expose confidential information or create new risks that organisations have never previously had to manage.
Technology has become inseparable from day-to-day business operations.
That means cyber risk has become business risk.
It also explains why infrastructure teams are increasingly being drawn into conversations about cyber security, operational resilience, compliance, governance and AI.
The technical decisions they make can now have security, regulatory and commercial implications attached to them.
The Real Challenge Is Prioritisation
Most of the people I speak to already have much of the technical capability required to deal with these challenges.
What they often lack is a simple way to organise and prioritise everything that is suddenly competing for their attention.
When people first encounter cyber security, it can look like dozens of separate disciplines:
Asset management, vulnerability management, identity and privileged access, phishing, endpoint security, logging, incident response, disaster recovery, third-party risk, compliance and AI governance can all appear disconnected.
Each one seems important.
Each one appears urgent.
And each one comes with its own technologies, vendors, frameworks and terminology.
Trying to tackle them independently quickly becomes overwhelming.
This is where cyber security frameworks become useful.
Why the NIST Cybersecurity Framework Helps
Frameworks rarely generate much excitement.
Most people don’t get out of bed in the morning wanting to learn another one.
Their value comes from helping organisations turn complexity into something manageable.
One framework that has stood the test of time is the NIST Cybersecurity Framework (NIST CSF).
What I like about NIST is that it doesn’t begin with products or individual security technologies. It starts by creating structure.
The framework gives organisations a way to think about cyber security as a collection of connected activities rather than an endless list of unrelated problems.
At a high level, the NIST Cybersecurity Framework encourages organisations to think about security across six areas: Govern, Identify, Protect, Detect, Respond and Recover.
That structure immediately makes prioritisation easier.
You need governance around technology risk.
You need to understand what exists in your environment and what matters most.
You need controls that protect critical systems, users and data.
You need visibility when something unusual or malicious happens.
You need the ability to respond effectively.
And ultimately, you need confidence that the organisation can recover and continue operating.
For infrastructure teams, much of this thinking will already feel familiar.
Bringing Security, Resilience and AI Governance Together
One of the challenges organisations face is that these responsibilities no longer exist in isolation.
Cyber security, operational resilience, compliance, technology risk and increasingly AI governance are becoming part of the same conversation.
That is one of the reasons frameworks such as NIST are so valuable.
They give technology teams a common structure for organising what can otherwise feel like an overwhelming collection of competing priorities.
Over time, that structure allows organisations to move away from reacting to individual security problems and towards managing technology risk more deliberately.
Instead of treating security, resilience, governance and operational risk as entirely separate activities, organisations can begin to see them as connected parts of the same technology strategy.
You Probably Have More Security Experience Than You Think
Perhaps that is the most important point.
For many infrastructure professionals, the skills required to manage cyber security risk are not completely new.
What has changed is the environment in which those skills are being applied.
The technology landscape has changed.
The threats have changed.
Regulatory expectations have changed.
AI has introduced another layer of complexity that many organisations are only beginning to understand.
But the fundamental disciplines remain surprisingly familiar.
Visibility. Control. Monitoring. Response. Recovery. Resilience.
If you have spent much of your career running IT infrastructure, you have probably already spent years developing many of those capabilities, even if you never described them in cyber security terms.
The challenge now is bringing those skills together into a coherent cyber security strategy.
That is where frameworks such as the NIST Cybersecurity Framework can help.
And it is where we’ll start in the next article.
Next in the series: You Can’t Protect What You Can’t Find: Why Asset Discovery Is the Real Starting Point for Security