IT and information security professionals collaborate at computer workstations to strengthen cyber resilience and risk management.

Aligning IT and IS Security Functions for Cyber Resilience

7/28/2026
STRATEGIC

Clear delineation of security functions strengthens cyber resilience, response coordination, and risk management.


IT and IS share a similar mission, but their security functions differ. Aligning them helps improve cyber resilience.

Information technology (IT) plays a central role in nearly every organization, and most people understand the services an IT team provides even if they do not know what IT stands for. The same is not always true for information security (IS). Organizations might have IT leaders, directors, or teams but still lack explicit, dedicated roles and teams for IS, including a chief information security officer.

While IT teams historically carried the responsibility for security operations, IS has evolved, and organizations now must dedicate resources and personnel commensurate with security risks, including substantial AI-driven threats. Additionally, even organizations with established IS functions can experience friction between IT and IS teams, especially when a lack of clarity regarding responsibilities hinders both groups, and, in some cases, IT and IS teams have competing objectives, particularly regarding operational performance and budget priorities.

Untangling the distinct and complementary roles of IT and IS is critical for organizational success, cyber resilience, and risk management. Organizations can achieve stronger outcomes when they treat IT and IS objectives as a coordinated risk management exercise. While IT investments support operational performance and recovery, IS investments reduce cyber risk and strengthen resilience. Both functions require funding decisions grounded in business impact, criticality, and long-term organizational objectives rather than short-term cost considerations.

Sign up to receive the latest insights on identifying threats, managing risk, and strengthening your organization’s security posture.

Delineating roles

IT encompasses the processes, systems, and infrastructure that support an organization's technology environment. It focuses on how computer systems, networks, and applications enable business operations. Because IT covers a broad range of functions, its responsibilities span everything from infrastructure management to user support.

Organizations often measure IT performance through availability, performance, and efficiency. Availability reflects the ability of systems and services to operate when needed. Many organizations support availability through routine maintenance, failover capabilities, and established processes for responding to disruptions. However, strong IT performance requires more than uptime. Systems must operate reliably, support business needs, and minimize friction for users. Maintaining current software, enabling connectivity across applications, and aligning technology investments with business objectives can improve performance, increase efficiency, and support growth.

While IT focuses on system availability, performance, and operational efficiency, IS focuses on protecting the confidentiality, integrity, and availability of organizational data and systems. IS teams manage cyber risk, develop security policies, monitor threats, and help organizations operate securely amid an evolving threat landscape.

Organizations commonly measure IS performance through metrics such as incident detection, response times, vulnerability remediation, and the reduction of security gaps. Broader indicators include the maturity of security controls, the effectiveness of monitoring capabilities, and resilience during operational disruptions or cyber incidents. Unlike IT, where success often appears through system uptime and performance, success in IS can be less visible because effective security controls prevent disruptions before they occur. A strong IS program allows the organization to maintain stable operations while reducing financial, operational, and regulatory risk.

Budgeting: Cost center versus risk investment

Organizations should approach IT and IS budgeting based on business risk tolerance and operational efficiency rather than short-term cost reduction. While the two functions have different objectives, effective budgeting requires close coordination and a shared understanding of organizational priorities.

IT budgeting should focus on maintaining system availability, performance, and operational resilience. Organizations can conduct business impact analyses (BIAs) to identify critical systems, dependencies, recovery requirements, and acceptable downtime thresholds. Those findings help IT leaders prioritize investments in infrastructure, modernization, business continuity, and disaster recovery based on the potential operational consequences of system failures.

IS budgeting should focus on reducing cybersecurity risk and strengthening the organization’s ability to detect, respond to, and recover from security incidents. Security investments often prove difficult to justify through traditional return-on-investment models because their primary value lies in preventing disruptions and minimizing future losses. As a result, organizations should evaluate security spending based on risk reduction, control maturity, alignment with regulatory requirements, and resilience rather than direct financial returns.

Despite their different priorities, IT and IS share several budgeting needs. Both functions benefit from risk assessments, BIAs, and alignment with broader business objectives. Both require investments that support continuity, recovery, and resilience. The outputs of BIAs also create a common framework for decision-making by helping IT and IS identify critical assets, establish recovery priorities, and define response expectations during operational or cybersecurity events.

Organizations should avoid treating IT and IS budgets as competing priorities or relying solely on cost-based decision-making. Delaying infrastructure upgrades, underfunding security controls, or selecting solutions based primarily on price can reduce short-term spending but increase long-term operational and cybersecurity risk. A strategic budgeting approach directs resources toward the areas of greatest business impact and risk exposure and can help organizations maintain stability, support compliance requirements, and reduce the financial and operational consequences of disruptions.

Incident response: Who owns what?

When an incident occurs, whether it involves a system outage, cyberattack, or data breach, organizations must clearly understand ownership and responsibilities. Incident response is not a one-size-fits-all process, and organizations that fail to define responsibilities often experience delays, confusion, and increased damage. According to the National Institute of Standards and Technology Incident Response Framework, effective incident response includes detection, analysis, containment, eradication, and recovery. Each stage requires coordination across multiple teams.

From an IT perspective, the primary responsibilities during an incident include restoring systems, maintaining availability, and recovering infrastructure. IT teams bring systems back online safely and efficiently, restore backups, rebuild servers, reestablish network connectivity, and help business operations resume with minimal disruption. IT success is measured by how quickly systems return to a stable operational state.

From an IS perspective, the primary responsibilities during and after an incident include threat detection, containment, forensic analysis, and communication. Security teams identify the root cause of the incident, determine how the attack occurred, and verify that threats are fully contained before systems are brought back online. Specific tasks include log analysis, investigation of compromised accounts, and coordination with leadership, internal stakeholders, and external regulators when necessary.

Friction can occur between IT and IS teams because they operate with different priorities. IT teams are incentivized to restore systems quickly to minimize downtime and operational disruption. IS teams, meanwhile, often require additional time to investigate and preserve evidence before restoration occurs. Restoring systems too quickly can lead to reinfection or the loss of forensic evidence, while delaying restoration can increase operational and financial impact. Without clearly defined responsibilities and communication protocols, these seemingly competing priorities can slow response efforts and increase organizational risk.

Clear separation of responsibilities significantly improves response outcomes. When IT and IS teams understand their respective roles, they can operate in parallel rather than in conflict. IS can focus on containment and analysis while IT teams prepare for recovery and restoration. A coordinated approach reduces response time, minimizes operational errors, and helps organizations address both operational continuity and risk mitigation effectively. Organizations with clearly defined incident response plans and ownership structures are better positioned to recover efficiently during disruptions.

Collaboration, not competition

While organizations should clearly delineate the responsibilities of IT and IS, they also must maintain strong alignment between both functions. IT and IS should not operate in silos, nor should they compete for resources or authority. Instead, they should function as complementary teams working toward shared organizational goals.

At their core, both IT and IS share the same objective: maintaining business continuity and organizational resilience. IT focuses on operational reliability and efficiency, and IS focuses on protecting systems and data from threats. When aligned effectively, these functions strengthen one another and create a more resilient technology environment.

One of the most effective ways to strengthen collaboration is through joint tabletop exercises. These exercises simulate real-world incidents and allow IT and security teams to practice their responsibilities within a controlled environment. By working through scenarios together, IT and IS teams can identify communication gaps, clarify responsibilities, and improve coordination before an actual incident occurs.

Organizations should also encourage cross-training opportunities and rotational experiences between IT and IS teams. Allowing personnel to better understand each other’s responsibilities, operational pressures, and decision-making processes through hands-on exercises helps build stronger collaboration and trust between the two functions.

These exercises also help foster empathy between teams, which strengthens communication, teamwork, and alignment during both normal operations and high-pressure incidents. Over time, increased communication creates a more unified technology culture in which IT and IS teams are better equipped to work toward shared objectives.

Another important approach involves establishing shared metrics where appropriate. While IT might focus on availability and performance, and security might focus on threat detection and response, they share overlapping priorities, such as incident response time and system recovery time. Shared metrics help both teams remain aligned and accountable to common organizational goals.

Clear escalation paths are equally important. During an incident, organizations should eliminate ambiguity regarding decision-making authority and escalation procedures. Defining these processes in advance helps organizations address issues quickly and efficiently while reducing delays, confusion, and future blame.

IT and IS: Strength through alignment and communication

For leadership teams, it is important to recognize that security is not solely a technical function. Security is also a business risk function. Decisions regarding security investments directly affect the organization’s ability to operate, compete, and maintain trust with customers and stakeholders.

IT and IS should remain aligned, but they should not be conflated. While both functions share common goals, they operate with different priorities, success metrics, and responsibilities. Treating them as a single function creates gaps in accountability, underinvestment in security capabilities, and slower response efforts during incidents.

Organizations that invest in clearly separating these functions while maintaining strong collaboration among them improve overall cyber resilience. Clearly defined responsibilities, aligned teams, and risk-based decision-making position organizations to manage disruptions more effectively, reduce long-term operational costs, and maintain operational stability in an increasingly complex threat environment.

Manage risks. Monitor threats. Enhance digital security. Build cyber resilience.

Discover how Crowe cybersecurity specialists help organizations like yours update, expand, and reinforce protection and recovery systems.

Contact us


Angie Hipsher - Large
Angie Hipsher-Williams
Managing Principal, Cyber Consulting
Josh Reid
Josh Reid
Principal, Cyber Consulting