Endpoint security, backed by SentinelOne and managed by TPx. Explore Managed Endpoint Security →

Cybersecurity Is a Team Sport

Key Takeaways:

  • Security tools still need the right people and expertise behind them.
  • Detection, investigation, and response each play a distinct role in cybersecurity.
  • Regular assessments, proactive security, and a practiced response plan can help organizations stay prepared

A Conversation with TPx’s Jeff Hunter

Businesses have no shortage of cybersecurity technology to choose from. The harder questions usually come after the purchase: Who will manage it? Who is watching what it finds? And when something happens, who knows what to do next? 

Those questions can be especially difficult for lean IT teams with limited cybersecurity resources.  

For Cybersecurity Awareness Month, we spoke with Jeff Hunter, VP of Product Management, Cybersecurity & Infrastructure at TPx, about what he’s seeing in the market, the challenges IT teams are facing, and why people and expertise remain such an important part of cybersecurity. Jeff has more than 25 years of product management experience, including the last 10 in cybersecurity, and leads the TPx product management team focused on cybersecurity solutions and the managed services behind them. 

What makes cybersecurity challenging for IT teams today?

Jeff: There are thousands of cybersecurity companies out there and a huge number of solutions to choose from. Just figuring out what you need can be challenging.  

Then you have the resource side of it. Budgets are limited. Cybersecurity expertise can be difficult to find. And even if you have the technology, somebody still has to implement it, manage it, and pay attention to what it’s telling you.  

For a lean IT team, that adds up quickly. You’re trying to determine what you need, how you’re going to manage it, and whether you have the people and resources to stay on top of it.   

So having more security technology doesn’t necessarily mean you’re better prepared?

Jeff: You can have all the tools in the world, but if nobody is continually managing them and watching for suspicious activity, all you have is a bunch of tools. 

They’re generating alerts and detections. Somebody has to understand what those mean and determine what needs attention. 

That’s where I think organizations sometimes underestimate the work involved. Deploying the technology is one step. Managing it and being prepared to act on what it finds is another.  

Where do people fit into that equation?

Jeff: People are incredibly important because they’re often the target.  

Think about phishing and social engineering. Attackers are trying to get someone to click on a link or provide information they shouldn’t. You also have employees adopting applications or tools because they’re trying to do their jobs more efficiently, without necessarily thinking about the security implications.  

That’s why security awareness can’t be something you do once a year and forget about. With ongoing education, employees can go from being a potential source of risk to an important part of your defense.  

There’s another side to the people question, too: the expertise behind your security technology. Cybersecurity covers a lot of different disciplines. Someone who’s an expert in network security isn’t automatically an expert in endpoint security. You need the right expertise for the different areas you’re trying to protect. 

What does that mean for a lean IT team?

Jeff: IT and cybersecurity require different skill sets.  

Your IT team may be responsible for everything from the network to laptops to day-to-day technology support. Now you’re asking that same team to understand the cybersecurity landscape, assess where the gaps are, determine which technologies make sense, and then manage those technologies once they’re deployed.  

That’s a lot to put on one team.  

This is where teams need to look at what they can realistically support internally and where they may need additional expertise. That doesn’t mean giving up control. It means understanding where your team is strongest and where additional support can help.  

Cybersecurity covers a lot of ground. How should IT leaders think about the different areas they need to protect?

Jeff: One solution isn’t going to protect everything.  

You have technologies focused on endpoints. You have network security. You have identity and access. They all have different jobs to do. 

The important part is understanding how those different areas fit together. An endpoint solution may see one piece of activity while a network security solution sees another. The more visibility you have across the environment, the better context you have when you’re trying to understand what’s happening.  

That’s becoming even more important as environments become more distributed. Users aren’t necessarily sitting in an office, on a corporate network, accessing applications from one place anymore.  

When an endpoint security solution detects suspicious activity, what happens next?

Jeff: Detection is the first part.  

The technology identifies something that looks suspicious, but a detection doesn’t automatically tell you the whole story. Somebody has to investigate it and determine whether it’s a real threat or legitimate activity that happened to trigger the detection.  

That’s where a trained security analyst comes in. They’re looking at what happened, what else was occurring around it, and whether action needs to be taken.  

Then you get into response. Once you’ve determined that something is a real threat, what are you going to do about it? 

Those are different functions. Detection gives you the signal. Investigation gives you context. Response is what you do with that information.  

Where can a managed services provider fit into a cybersecurity strategy?

Jeff: Think about what it would take to do it in-house. You have to select the technology, deploy it, configure it, monitor it, and know how to respond when something is identified.  

For a lean IT team, having the people and expertise to cover all of that can be difficult. That’s where bringing outside expertise can help. You may have cybersecurity expertise on staff, but that doesn’t mean your internal team has to handle every part of the process.  

If an IT leader wants to strengthen their cybersecurity program, where should they start?

Jeff: I’d focus on three things.  

First, assess your environment regularly. Your technology and business are always changing, and so are the threats you’re dealing with. An assessment shouldn’t be something you do once and put on a shelf.  

Second, be proactive. Don’t wait for a security tool to tell you something bad has already happened before you start looking for risk.  

Third, have a response plan and practice it. If something happens, who needs to be involved? What does IT do? What do employees do? Which partners need to be contacted? Those aren’t questions you want to answer for the first time during an incident.  

Tabletop exercises are a good way to walk through those scenarios and see where the gaps are before you’re dealing with the real thing.  

Cybersecurity takes a team

Jeff’s advice comes back to a common thread: preparation takes more than technology. It takes people who know what to look for, expertise to act on what they find, and a plan for what comes next.  

How prepared is your IT environment? 

The IT Checkup can help you uncover potential risks and identify opportunities to improve your IT environment. It only takes a few minutes, and you’ll receive a personalized IT readiness score with actionable recommendations.  

Take the IT Checkup

Table of Contents

Related Posts

Share this Post

Print Button

Need more help:

We’re ready to answer any of your questions. Visit our Technical Support page for phone numbers and web portal links.

Request a Consultation

"*" indicates required fields

* By submitting this form, you are accepting TPx’s privacy policy .