Ask a typical contractor who is responsible for cybersecurity, and you will often hear a pause. The owner assumes IT handles it. IT assumes the owner has accepted the risk. Accounting assumes the bank is on guard. Project managers assume the software vendor takes care of it. Meanwhile, attackers see a company with no clear owner for the problem.
Cyber risk is a business risk, and business risks need named owners. That does not require a large security team. It requires clear roles.
Why unclear ownership hurts
- Policies are written but never enforced
- Vendor and software access is granted without review
- Incidents are noticed late because nobody is looking
- Insurance applications are completed without anyone verifying the answers
- Compliance requirements, such as CMMC flow-downs, land on someone with no authority to act
Roles that work in a small or mid-size company
The owner or executive sponsor
The executive sponsor sets the tone and accepts business risk. Responsibilities include approving the security budget, backing difficult decisions such as enforcing MFA, and signing off on risk acceptance. When something goes wrong, this person is accountable to customers, insurers and, in some contracts, the government.
The security lead
This person coordinates the program day to day. At a small company it may be the IT manager, the controller or an operations leader supported by an outside provider. The role includes maintaining policies, tracking risk, overseeing vendors and reporting to the sponsor. It does not require them to do everything technical. It requires that they keep the program moving.
The finance owner
Payment fraud targets finance directly. The controller or CFO should own payment verification procedures, banking security settings and vendor master file controls. Work with the security lead on training and tools.
Project and operations leaders
Project managers and superintendents control who gets access to project platforms, how field devices are used and how subcontractors connect. They should own access reviews for their projects and follow closeout steps.
HR or people operations
Onboarding and offboarding are security processes. HR triggers account creation, device assignment and access removal. Without HR involvement, former employees keep access.
IT or your managed provider
The technical team implements controls, monitors systems, applies updates and responds to incidents. Their authority and responsibilities should be written in a service agreement, including response times and escalation.
Every employee
Everyone is responsible for following basic practices and reporting suspicious activity quickly. Make that expectation explicit and easy to meet.
Write it down
A one-page responsibility chart can settle most confusion. For each key area, list who is accountable, who does the work and who is consulted. Useful areas include:
- Access approvals and removals
- Vendor and software approvals
- Payment verification
- Backup and recovery testing
- Incident response and communication
- Insurance and compliance questionnaires
- Training and awareness
- Mobile devices and field equipment
Build routines around the roles
- Monthly: the security lead reviews open issues, patch status and alerts with IT.
- Quarterly: project and finance owners review user access and vendor changes.
- Annually: the sponsor reviews risks, budget, insurance and compliance status, and the team runs a tabletop exercise.
A hypothetical example
Consider a hypothetical 70-person contractor where a former project engineer keeps access to the document platform for months after leaving. IT never learned of the departure, HR assumed IT was told and the project manager assumed it had been handled. A clear offboarding trigger owned by HR, with a named IT contact, closes the gap.
When you use an outside provider
Outsourcing technical work does not outsource accountability. Keep an internal owner who understands the program, asks hard questions, and holds the provider to the agreed scope. Ask for regular reporting in plain English.
Setting it up
Ironfield Cyber helps contractors define security roles, write simple responsibility charts and put routines in place. If you are not sure who owns what today, a short workshop can give your leadership team clarity and a plan.