
Is my IT company responsible for cyber security?
Quick Answer
Usually not. Most IT support companies are responsible for keeping systems running, fixing problems, and supporting users. Cyber security is a separate responsibility unless it's clearly included in your contract.
The gap matters because most business owners assume cyber security is covered. It often isn't, and many only find out when something goes wrong.
What does an IT Support normally cover?
Most IT support agreements usually cover things like
Fixing things when they break — the helpdesk
Keeping software and Windows updated
Setting up new starters and removing leavers
Managing your email and file storage
Sorting out printers, phones and Wi-Fi
Usually some antivirus, and usually a backup
That is a valuable job, and good IT support is important. Most of it, though, is focused on keeping the business running, fixing problems, keeping systems available, and getting people working again when something stops.
Most of those tasks are routine or reactive. They help keep the business working, but they do not usually include actively looking for ways an attacker could get in.
What's missing, and why does it matter?
Security is the opposite discipline. It is about assuming someone is trying to get in and making sure they can't — which is a different mindset, a different skill set and, usually, a different person.
Here is what typically isn't in an IT support contract:
Nobody is watching out of hours. Most attacks happen at 2am on a Sunday, precisely because nobody is looking. A helpdesk that opens at 8am is not monitoring.
Antivirus isn't detection. Standard antivirus catches known threats. It does not spot an attacker who has logged in with a stolen password and is quietly looking around — because to the computer, that just looks like a member of staff working late.
Nobody has tested your defences. There is a difference between "we've set it up correctly" and "we've checked whether it can be broken into". Most IT contracts include the first and none of the second.
Your staff haven't been trained. The overwhelming majority of successful attacks on small businesses start with a person clicking something, not with clever hacking. That is a training problem, and training is rarely in an IT contract.
Certification isn't included. Cyber Essentials, GDPR evidence, the security questionnaire your biggest client just sent you — these usually sit with nobody.
A backup is not a recovery plan. Plenty of businesses have backups. Far fewer have ever tested restoring from one under pressure, and modern ransomware specifically goes after backups first.
The honest summary: your IT company keeps the lights on. That is what you hired them for and most of them do it well. But "the lights are on" and "we are secure" are two different statements, and only one of them is in your contract.
Doesn't my insurance cover it?
It might help, but only if you've done what your policy requires.
Cyber insurance often depends on things like multi-factor authentication, tested backups, staff training, and regular patching. If those controls are not in place, an insurer may question, reduce, or refuse a claim. That's why insurance shouldn't be treated as a replacement for security.
It can help after an incident, but it doesn't prevent the attack, the downtime, or the loss of trust.
How do I check what I'm actually paying for?
Ask your IT provider these four questions in writing, and keep their response:
Are you monitoring our systems for attacks outside office hours?
If yes, ask what tool is being used, who checks the alerts, and what happens if something suspicious is detected.When were our systems last tested for security weaknesses?
Ask for the date, what was tested, and whether there is a report you can see.What does our contract say happens if we suffer a cyber attack?
Check the liability and responsibility sections in the agreement rather than relying only on a verbal answer.Do you have cyber security-specific qualifications or certifications?
General IT experience is valuable, but cyber security is a specialist area with its own qualifications and expertise.
A good IT provider should be able to answer these questions clearly. Some may simply say, “That isn't included in your current contract, but we can help you find the right support.”
That is not a bad answer. In many cases, it is a sign of an honest supplier who understands where their responsibility starts and ends..
Do I need to replace my IT company?
Usually, no — and that is one of the most important points to take away from this.
Your IT provider already knows your systems, your staff and how your business works. Replacing them can be expensive, disruptive and unnecessary if the real issue is simply that cyber security was never included in the contract.
The sensible approach is usually to keep the IT support you already have and add cyber security alongside it.
Two suppliers, two clear roles:
Your IT company keeps the business running.
Your cyber security provider focuses on reducing risk, monitoring for threats and helping protect the business from attack.
The two should work together.
In our experience, most IT providers are happy to do that because cyber security is often not what they were originally hired to be fully responsible for.
What does adding security actually cost?
It depends on the size of your business and the level of protection you need, but it may cost less than you expect.
Systems Secure publishes its prices openly:
Sole Trader: from £35 per computer, per month
1–9 people: from £204 per month
10+ people: from £710 per month
All prices exclude VAT. There are no setup fees, no minimum term, and the service runs monthly with 30 days' notice if you decide to leave.
Prices shown are correct at the time of writing and may change. For the latest pricing and package information, please check the Systems Secure website.
For context, the UK Government’s Cyber Security Breaches Survey found that a significant proportion of UK businesses experienced a cyber security breach or attack in the previous 12 months.
The important thing is to compare the cost of protection with the potential disruption of an incident — lost working time, recovery costs and the impact on customers — rather than looking at the monthly price in isolation.
What to do next
If you are not sure what your IT contract covers, send it over.
I will review it and explain in plain English what it includes, what it does not include, and where there may be gaps.
There is no charge and no sales pitch. If you are already well covered, I will tell you that too.
In short
Most IT support contracts focus on keeping systems running and fixing problems, rather than providing a full cyber security service.
IT support and cyber security are different roles and often require different skills and qualifications.
Common gaps can include out-of-hours monitoring, security testing, staff training, certification and tested recovery.
Cyber insurance can help after an incident, but cover may depend on you meeting the conditions in your policy.
You usually do not need to replace your IT provider — you can add specialist cyber security alongside them.
Systems Secure works with existing IT providers, with pricing starting from £35 per month. Check the Systems Secure website for the latest packages and pricing.





