Editorial

Business Took the Risk, Security Got the Blame

Business moves fast; Security still owns the consequences.

Monday, June 01, 2026 | 5 MINS

Ransomware is responsible for 88% of data breaches at small and medium-sized businesses, according to research by SQ Magazine. 

By its very nature, ransomware attacks can only be successful when cybercriminals are able to gain unauthorised access to systems and data, and encrypt that data before IT and security teams are able to mount any defence.

That ransomware is so dominant among security threats to SMBs sums up the fact that many security operations are reactive rather than proactive. And while this isn’t necessarily the security team’s fault, they still get the blame regardless.

Why isn’t it their fault? Because the growth of shadow IT means that they don’t always even know that departments and employees have unilaterally installed their own applications or bought their own SaaS services.

Why are they still to blame? Because the rest of the business still sees security as responsible for keeping all data, systems and applications safe — whether they knew about them or not, and whether they approved the procurement and installation or not.

All this means that many modern security teams in SMB operations are now simply cleaners, there to tidy up mess caused entirely by other people, and taking all the flak for not addressing it sooner.

This isn’t especially fair on security teams, nor will it help maintain good security at a time when just one successful breach can cause an existential crisis for an SMB. The solution is to reframe security accountability and review security and governance processes in the context of changing IT usage habits.

This topic is sponsored by Palo Alto Networks, whose commitment to making enterprise-grade security accessible to mid-market organisations helped bring this discussion to the community.


Charting the Course to AI-Driven Sec Ops

We hope you find this complimentary guide useful.

Download

Topic sponsored by Palo Alto Networks, whose commitment to making enterprise-grade security accessible to mid-market organisations helped bring this discussion to the community.

Also in this section

}());