IT Risk Radar: Cybersecurity – it’s a leadership responsibility
Cybersecurity – it’s a leadership responsibility
Join us for IT Risk Radar: Strategies that Work, host Dan Bourdeau is joined by Kip Boyle, Founder and CISO at Cyber Risk Opportunities and author of Fire Doesn’t Innovate and the forthcoming Gears Don’t Guess, and Jessica Dore, Principal at Rehmann Technology Services, for a practical conversation on cybersecurity governance for Michigan municipal and public sector agencies.
Ask yourself one question: if an exception request landed in your inbox right now—someone saying they can’t meet your cybersecurity requirements—who would respond to it within a week? If it takes you more than three seconds to name that person, you don’t have a cybersecurity program. You have an ownership vacuum.
This is the uncomfortable truth facing public sector leaders today. For years, we’ve treated cybersecurity as a technical specialty, something to delegate to the IT director and forget about until something breaks. That model is dead. The agencies that thrive in the years ahead will be the ones that recognize cybersecurity for what it actually is: a continuous act of governance that belongs squarely in the executive suite.
The Quiet Death of a “Program”
Here’s how strong cyber programs fall apart—and it’s rarely dramatic.
They don’t get canceled in a budget meeting. Nobody flips a switch to turn them off. Instead, they quietly stop. And the reason is almost always the same: you thought you had a program, but what you actually had was a person. Someone running things on personal authority and passion rather than occupying a defined, named role.
When that person retires, takes another job, or simply burns out, the program goes with them. This is especially common in smaller organizations, where everything tends to be personality-driven. It feels comforting—until it leaves.
This creates an apparent paradox that public leaders need to resolve:
- A program built on one person’s passion isn’t really a program. It’s too fragile to survive turnover.
- Yet every program needs a named, accountable owner. Diffuse responsibility is no responsibility at all.
Both statements are true at the same time. The resolution lies in professionalism and maturity—building durable roles that any qualified person can step into, rather than relying on irreplaceable individuals. The role outlasts the person.
Why This Can’t Be Delegated Down
Local government runs on visible investments. Fire trucks. Park equipment. Canine units. Voters can see these things, touch them, and understand them. A firewall? Not so much. It’s a harder story to tell.
This is why cybersecurity belongs to leadership, not just IT. The data backs it up: according to the World Economic Forum, 99% of highly resilient organizations have governing body involvement in their cybersecurity. That means mayors, city managers, township supervisors, councils, and boards must be actively engaged—not as figureheads, but as participants.
The hardest lift here is psychological. Leaders are accustomed to delegating down to technical staff. Effective governance requires delegating up—accepting that ultimate responsibility for cyber risk rests in the C-suite, where decisions about funding, risk acceptance, and organizational priorities are actually made.
But consider what that firewall actually protects. It keeps dispatch online to receive 911 calls. It keeps radio signals reaching first responders. It keeps the payroll system running so the people maintaining your parks get paid on time. The firewall isn’t competing with the fire truck for funding—the firewall is what makes the fire truck roll.
The Five Roles That Make a Program Durable
The good news is you don’t have to invent this from scratch. The NIST Cybersecurity Framework can feel daunting—it’s dense with acronyms and abstract language—but buried inside it is a practical model for distributing ownership across an organization. Here are the five roles every program needs:
- The Executive Sponsor. In a municipal context, this is your mayor, city manager, township supervisor, or county administrator. This role provides top-level authority and signals organizational commitment.
- The Program Owner. Critically, this should not be the IT director. Assigning it there reinforces the outdated notion that cybersecurity is an IT problem. Instead, place it with a deputy manager, finance director, or chief of staff—someone in the main line of management. They don’t need to be a technical expert. Their role sends a powerful signal to the entire organization that this is everyone’s concern.
- The Business Co-Owners. These are your functional leaders—the heads of police, fire, public works, the assessor, the clerk. Because they’ll be directly affected by cybersecurity decisions, they need a seat at the table to ensure no critical function gets overlooked.
- The Technology and Cyber Specialists. Your IT and security staff remain essential. Technology is still a big, important part of the picture—it’s just no longer the only part.
- The Legal and Risk Management Specialists. These voices must be active participants, not afterthoughts. They help you navigate compliance, liability, and the decisions about which risks to accept.
Notice that IT appears fourth on this list, not first. That’s not a demotion—it’s an accurate reflection of how the world has changed. Fifteen years ago, you could reasonably treat cyber as an IT issue. Today, a cyberattack on a local government is a public safety event, a financial event, a legal event, and a reputational event—all at once. No single department can own that alone.
The Exception Request Test—Revisited
Return to the question at the top of this article. Who handles the exception request?
If your answer is “the IT director handles it,” you have a clue that governance hasn’t fully taken hold. Exception requests are risk decisions. They require someone with the authority to say: “Yes, we accept this risk for these reasons,” or “No, we’re not prepared to accept it.” That is not a technical decision. That is a management decision.
A mature program has a documented exception process. It names the person responsible, defines the approval criteria, sets timelines, and records outcomes. When something later goes wrong—and at some point, something will—you want to be able to show that decisions were made deliberately, by the right people, with appropriate oversight.
This isn’t bureaucracy for its own sake. It’s how organizations demonstrate due diligence. It’s how leaders protect themselves, their staff, and the communities they serve.
Moving From Awareness to Action
Knowing that cybersecurity is a governance problem is one thing. Actually restructuring how your organization manages it is another. Here’s a practical starting point:
- Audit your current ownership structure. Who formally owns your cybersecurity program today? Is it documented? Is it a role or a person? What happens if that person leaves tomorrow?
- Map your five roles. Using the framework above, identify who currently fills each position—or acknowledge where the gaps are. An honest gap analysis is more useful than a comfortable fiction.
- Start the budget conversation differently. Instead of asking for money for cybersecurity tools, make the case in terms of service continuity. What happens to 911 response if dispatch goes down? What is the cost of payroll failure? Frame cyber investment as operational resilience, not IT spending.
- Establish a governance cadence. Executive sponsors and program owners should be reviewing cyber risk on a defined schedule—not just when something breaks. Quarterly briefings, at minimum, keep leadership connected to emerging threats and program health.
- Formalize your exception process. If you don’t have one, build it now. Define who approves exceptions, what justification is required, and how decisions are documented.
None of these steps require a large budget or a new hire. They require commitment and clarity—two things that cost nothing but leadership attention.
The Stakes Are Too High to Get This Wrong
Public sector organizations hold some of the most sensitive data in existence: health records, financial information, criminal histories, and the infrastructure that connects citizens to emergency services. A failure here isn’t just an embarrassment. It can be life-altering for the people your agency is meant to serve.
The agencies that get this right won’t necessarily be the ones with the largest IT budgets. They’ll be the ones where a mayor or city manager looked at this problem clearly, accepted that it belongs to them, and built the structures to manage it accordingly.
Cybersecurity is not a technology problem with a technology solution. It is a governance problem that requires governance solutions—clear ownership, accountable roles, active executive engagement, and the institutional maturity to make risk decisions deliberately rather than by default.
The question is no longer whether your organization will face a serious cyber threat. The question is whether your governance structure is ready to respond when it arrives.
Ready to build a cybersecurity governance framework that lasts? Connect with our team to learn how we help public sector organizations move from reactive to resilient—starting with the structures that matter most.
Ready to build a cybersecurity governance framework that lasts? Connect with our team to learn how we help public sector organizations move from reactive to resilient—starting with the structures that matter most.