Cybersecurity Is a Business Risk — Not an IT Problem
Ask most business owners what cybersecurity means, and they’ll point to their IT team. It’s a server thing, a password thing, a “someone else is handling it” thing. But that mindset is exactly what leaves companies exposed.
According to Merlin Halteman, Managed Services Director at Kirbtech, cybersecurity isn’t a line item IT quietly manages in the background. It’s a business risk, right alongside cash flow, staffing, and reputation, and it belongs on the same table as every other decision ownership makes.
We sat down with Merlin to talk about how the threat landscape has changed, why the old rules of thumb no longer hold, and what business owners should actually be asking their IT provider.
Security Is Abstract… Until It Isn’t
Physical security is intuitive. Locks on the doors, gates on the property, cameras in the parking lot — everyone understands what they’re protecting and how. Cybersecurity is a different animal. There’s no fence to point to, no lock to check. The threats are remote, invisible, and often triggered by something as ordinary as a click.
At its core, Merlin explains, cybersecurity comes down to protecting your assets and your intellectual property, and that protection is built in layers: strong email filtering, endpoint detection, removing unnecessary administrative privileges, and scoping every account to only what that person actually needs to do their job.
That last point matters more than it sounds. Giving every employee broad access because “we trust them” isn’t a policy — it’s a liability. If one account is compromised, tightly scoped privileges are what keep that breach from becoming a company-wide event.
Most Breaches Start With Good Intentions

That’s exactly why scoped access, unique credentials for every user, and a strong security awareness culture matter. When something does go wrong, the damage stays contained, and IT can trace exactly what happened and coach the employee involved. No finger-pointing required.
Two-Factor Authentication Isn’t the Silver Bullet It Used to Be
For years, two-factor authentication was treated as the finish line of good security. Merlin still recommends it, but he’s candid that it’s no longer enough on its own.
Attackers have gotten sophisticated enough to harvest login credentials and authentication tokens directly, bypassing the extra step altogether. That’s why more businesses are layering on breach detection systems and geo-based login restrictions. These are rules that only allow certain accounts, like banking logins, to authenticate from known locations or approved IP addresses.
Not every account needs that level of lockdown. But for the systems that would do the most damage if compromised, it’s a layer worth having.
AI Has Changed the Threat Landscape
Phishing used to be easy to spot, but AI has erased most of the bright, neon signs signaling an attack. Attackers can now generate thousands of highly convincing, personalized emails and texts, mimicking tone, language patterns, and even the writing style of a specific region or industry.

The Safety Net: Backups and Process
Even the best defenses can be breached, which is why backups and internal process are just as much a part of cybersecurity as firewalls and filtering. Immutable backups give a business somewhere to land if ransomware or a system crash takes data offline. Unfortunately, a surprising number of businesses that lack this simply don’t survive the event.
Process matters just as much as technology. A documented two-person approval step for any significant financial transfer closes one of the most common — and most costly — gaps. Scammers count on urgency, especially around holidays and weekends, to push people into hasty decisions. A simple second set of eyes is often all it takes to stop that.
This Is a Leadership Decision, Not Just an IT Task
IT is the hands and feet that implement security, but the decisions about how much protection a business needs, and what it’s willing to risk, belong at the ownership level. That’s the real intersection between cybersecurity and IT.
It’s also where friction often shows up. Additional layers of protection come with additional cost, and it can be tempting to view them as unnecessary, especially if nothing bad has happened yet. But that’s the wrong way to measure it. When cybersecurity is working, nothing happens. No breach in the news, no lost intellectual property, no damaged reputation. The absence of a crisis is the return on investment.
How to Know If Your IT Team Has You Covered
Merlin’s advice for business owners who want a clearer picture of where they stand:
- Schedule an annual risk-planning session. Talk through continuity like what happens if the internet goes down, or a key system fails, and identify what the business genuinely cannot afford to lose: reputation, revenue, data, intellectual property.
- Start from what you don’t want to happen, then work backwards to the systems and processes that prevent it. It’s often easier to name the outcomes you’re trying to avoid than to guess at every possible solution.
- Test your provider. Ask them to restore a few deleted files from backup. Unplug a network switch and see how quickly they notice and respond. It’s a simple way to verify that promises in a contract match what’s actually happening.
Merlin compares it to taking a car to the mechanic. Most owners don’t have the technical background to evaluate the work firsthand, so trust plays a real role. But a few simple checks go a long way toward confirming that trust is well placed.
He’s also quick to push back on a common misconception: that smaller businesses or newer employees aren’t attractive targets. Hackers don’t discriminate. One compromised entry point, at any level of an organization, can ladder up to more sensitive access or spread to a connected business. Every person in the company is part of the chain, and a company email address carries built-in trust that makes it a valuable target no matter whose name is on it.
The Bottom Line
Cybersecurity isn’t a cost center or a box to check, but rather risk management, and it deserves the same attention business owners give to any other threat to the company’s future. The businesses that treat it that way are the ones that stay out of the headlines.
Ready to find out where your business stands? Kirbtech offers cybersecurity assessments to help you identify gaps before they become incidents.