Now offering personalized training and coaching sessions – limited availability Apply Now>>

What to Do When IT and Security Teams Report to Different Bosses

It’s a Monday morning standup, and the tension in the room is thick enough to cut with a knife. The IT operations manager is frustrated because a critical patch wasn’t applied over the weekend, leaving a server vulnerable. The security lead is furious because the IT team pushed a configuration change that locked down a port they needed for a forensic investigation. Both are right. Both are trying to do their jobs. And both report to different bosses.

If this scenario feels familiar, you’re not alone. In many organizations, the IT operations team sits under the CIO or CTO, while the security team reports to a Chief Information Security Officer (CISO), the COO, or sometimes even directly to the CEO or the board. On paper, this separation is meant to provide independence and oversight. In practice, it often creates a structural conflict that leads to finger-pointing, duplicated work, and—worst of all—security gaps that attackers love to exploit.

So, what do you do when your IT and security teams are siloed under different leadership? How do you bridge the gap without waiting for a massive corporate reorganization that might never happen? Let’s walk through the practical, sometimes messy, reality of fixing this disconnect.

Why the Split Happens (And Why It’s So Damaging)

To fix the problem, you first have to understand why it exists. The separation of IT and security reporting lines isn’t usually a random accident. It usually happens for one of three reasons:

  • The “Check and Balance” Theory: The idea is that if security reports to the same person running IT operations, security will be pressured to cut corners to hit uptime goals. By separating them, you ensure the security team can say “no” without fear of retribution from the operations boss.
  • The Compliance Requirement: Regulations like Sarbanes-Oxley (SARBOX) or PCI DSS often require a separation of duties. Auditors want to see that the people who build the system aren’t the same people who approve its security controls.
  • The “Digital Transformation” Hangover: As companies modernize, they often hire a CISO first to “clean up security,” but leave the existing IT Director in charge of the infrastructure. Two leaders, two teams, two sets of priorities.

The intention behind the split is usually good. The execution, however, is often terrible. When IT and security report to different bosses, you inevitably get misaligned metrics. The IT team is measured on uptime and ticket resolution speed. The security team is measured on the number of vulnerabilities patched and compliance audit results.

Consequently, IT sees security as the “Department of No” that slows down deployments and creates bureaucratic hurdles. Security sees IT as a bunch of cowboys who prioritize speed over safety and leave the back door open.

This friction isn’t just annoying; it’s expensive. According to various industry studies, organizations with high friction between security and operations take significantly longer to patch critical vulnerabilities. And every day a critical vulnerability sits unpatched is a day an attacker has a shot at your data. Additionally, the “human cost” is real: burnout spikes when teams feel they are fighting their own colleagues rather than external threats.

The VisibleOps Framework: A Blueprint for Convergence

This is exactly the problem that frameworks like VisibleOps Cybersecurity were designed to solve. Created by Scott Alldridge and the IT Process Institute (ITPI), VisibleOps isn’t just a theoretical model; it’s a methodology for integrating operational excellence with security practices. With over 400,000 copies of the handbook sold globally, it has become a standard for organizations trying to stop the internal bleeding.

The core premise of VisibleOps is that you cannot secure what you cannot see, and you cannot operate what you don’t understand. When IT and security report to different bosses, they often have different “views” of the infrastructure. Scott Alldridge’s work emphasizes creating a single pane of glass—a unified view of operations and security.

But how do you implement that when the org chart is standing in your way? You can’t always change who reports to whom, but you can change the processes and the culture. Here’s a step-by-step guide to bridging the divide.

Step 1: Conduct a “Friction Audit” to Identify the Real Conflicts

Before you can fix the relationship, you need to diagnose the pain points. Don’t just assume the teams hate each other; find out exactly where the processes are breaking down.

How to do it:

  • Map the Workflow: Trace a single change request from start to finish. Who initiates it? Who approves it? Who implements it? Who verifies it? If the approval sits with the security boss but the implementation sits with the IT boss, you’ve found a delay point.
  • Review the Incident History: Look at the last five “critical” incidents. Did the mean-time-to-resolution (MTTR) suffer because one team had to wait for permission from the other’s leadership?
  • Ask the Front Lines: Don’t just talk to the managers. Talk to the sysadmins and the security analysts. They are the ones feeling the friction. Ask them: “What is the most frustrating part of dealing with the other team?”

Once you have this data, present it not as a blame game, but as a business case. For example: “We lost 40 hours of productivity last month because of approval delays between IT and Security. That’s X dollars in wasted labor.”

Step 2: Create a Unified Governance Body (The “Bridge”)

You can’t wait for a reorg, but you can create a temporary structure that forces collaboration. Scott Alldridge’s framework emphasizes the need for disciplined change management. When teams report to different bosses, change management often becomes a battleground.

The Solution: Establish a joint Change Advisory Board (CAB) or a Security Operations Council.

  • The Membership: It must include the IT Operations Manager, the Security Manager, the lead architect, and a business representative.
  • The Rule: No major infrastructure change happens without a sign-off from both sides. But—and this is crucial—the sign-off has a deadline. You can’t just ignore a request until it goes away.
  • The Goal: The council’s job is not to say “yes” or “no,” but to say “how.” How can we deploy this feature securely? How can we secure this system without breaking uptime?

If the bosses are fighting, the council provides a neutral ground. It also serves as a place where the two leaders can align their goals.

Step 3: Align Metrics (Stop Paying Them to Fight)

This is the hardest part. If the IT manager gets a bonus for 100% uptime and the Security manager gets a bonus for zero open vulnerabilities, they are incentivized to sabotage each other. The IT manager might delay patching to keep uptime high; the Security manager might shut down a service to patch a hole.

Actionable Steps:

  • Shared KPIs: Introduce a “Time to Remediate” metric that is shared by both teams. If the metric is missed, both leaders feel the heat.
  • The “Secure Velocity” Metric: Instead of just measuring uptime, measure “Secure Deployments.” How many features did we ship securely? This encourages IT to bring security in early, rather than treating them as a final gatekeeper.
  • Compliance as a Service (CaaS): Use this to automate the evidence collection for audits. If IT and Security are fighting over who collects logs for PCI or HIPAA compliance, automate it. VisibleOps emphasizes compliance automation to reduce the manual burden on both teams.

When both teams are measured on the same outcomes, the “us vs. them” dynamic starts to fade. They stop trying to win arguments and start trying to solve problems.

Step 4: Implement “Integrated” Change Management

In a traditional siloed environment, IT builds a server, then throws it over the wall to Security to “harden” it. Security sends it back with a list of 50 things to fix. IT gets annoyed and fixes 40 of them. Security gets annoyed and signs off anyway.

VisibleOps recommends a different approach: Integrated Change Management.

  • Security as Code: Security requirements should be baked into the build process, not added at the end. The security team should provide “gold images” or automated scripts that the IT team can use.
  • Pre-Approved Changes: Not every change needs a meeting. If a change follows a predefined, secure pattern (e.g., a standard patch), it should be auto-approved. This eliminates the bottleneck where IT waits for Security approval for routine tasks.
  • The “Break Glass” Protocol: What happens when the IT team needs to make an emergency change at 2 AM and the Security boss is asleep? You need a documented, pre-agreed protocol. Perhaps the IT lead can make the change but must document it and notify security immediately. This trust is built on the framework, not on personalities.

Step 5: Adopt Zero Trust Principles to Reduce the Blame Game

When a breach happens, the first question is usually “Whose fault is this?” The IT team blames Security for missing the vulnerability. Security blames IT for misconfiguring the firewall.

Zero Trust, a key component of the VisibleOps Cybersecurity framework, helps eliminate this blame game by assuming nothing is safe.

  • Continuous Verification: Don’t assume that because a user is inside the network, they are safe. Verify every request. This takes the pressure off the perimeter firewall (which IT manages) and puts it on identity management (which both teams can manage).
  • Micro-segmentation: If you segment your network, a breach in one area doesn’t compromise the whole system. This limits the blast radius. If a breach is contained, the “blame” is less catastrophic because the system was designed to handle it.
  • Shared Responsibility: Zero Trust makes security a shared responsibility. IT is responsible for the infrastructure that enables Zero Trust, and Security is responsible for the policies that define it. They have to work together to make it work.

Step 6: The Executive Companion Approach (Getting the Bosses on Board)

If you’re an executive (CEO, CFO, COO) reading this, you might be thinking, “I don’t care about the technical details; I just want them to stop fighting.” This is where the VisibleOps Cybersecurity: Executive Companion Handbook comes in.

Scott Alldridge designed this specifically for non-technical leaders who are tired of jargon. The Executive Companion strips away the acronyms and explains how to govern cybersecurity as a business risk, not an IT problem.

What Executives Need to Do:

  • Stop the “Blame Game” in Leadership Meetings: If the CISO and the CIO are fighting in front of you, you are the only one who can stop it. Set a rule: “We don’t discuss ‘who’ failed; we discuss ‘what’ failed and how we fix it together.”
  • Fund the “Bridge”: Invest in tools that foster visibility. If IT has a monitoring tool and Security has a separate monitoring tool, buy a solution that integrates both (or use the VisibleOps methodology to integrate them). You can’t manage what you can’t measure.
  • Hold Them Jointly Accountable: As mentioned in Step 3, their bonuses and performance reviews should reflect the other’s success.

Step 7: The Technical Fix – Visibility and Monitoring

You can’t fix a culture problem without fixing the technical visibility problem. When IT and Security report to different bosses, they often use different tools that don’t talk to each other.

  • The IT View: Focused on performance, CPU usage, disk space, and network latency.
  • The Security View: Focused on logs, intrusion attempts, and anomalies.

The Solution: A Single Source of Truth.

VisibleOps emphasizes Real-Time Monitoring and Continuous Visibility. You need a dashboard that both bosses can look at.

  • Integrated Dashboards: Show the health of the system and the security status. If the CPU is spiking because of a Denial of Service attack, both the IT manager and the Security manager should see the same alert simultaneously.
  • Audit Trails: Every change should be logged in a system that both teams can access. If the security team asks “Who changed this file?” the IT team shouldn’t have to dig through manual logs. It should be automated.
  • Penetration Testing: This is a great way to force collaboration. The security team (or an external vendor) attacks the system. The IT team defends it. Afterward, they do a “post-mortem” together. It’s a team-building exercise disguised as a security audit.

Case Study: How a Siloed Organization Fixed the Friction

Let’s look at a hypothetical but realistic example. Imagine a mid-sized healthcare company. They have an IT Director (reporting to the COO) and a Security Manager (reporting to the CFO).

The Problem: They were failing HIPAA audits. IT was deploying new patient portals without telling Security. Security was locking down servers, which broke the portals.

The Fix (Using VisibleOps principles):

  • The Joint Committee: They formed a “HIPAA Compliance Council” with the IT Director, Security Manager, and a Clinical representative.
  • Integrated Change Management: They implemented a rule: No new portal goes live without a Security review. But, Security promised to return the review within 48 hours. No more “black hole” delays.
  • Shared Metrics: They set a goal to reduce “Time to Remediate” critical vulnerabilities to < 7 days. Both leaders were measured on this.
  • Zero Trust Adoption: They implemented micro-segmentation so that if a database was breached, it didn’t affect the whole network.

The Result: Within six months, the friction dropped. They passed their audit. And, crucially, the IT and Security managers started having lunch together. The structure changed from “Adversaries” to “Allies.”

Common Mistakes to Avoid

If you are trying to fix the IT/Security divide, avoid these traps:

  • Ignoring the Culture: You can change the org chart, but if you don’t change the culture, the behavior remains the same. You must address the “us vs. them” mentality through team-building and shared goals.
  • Trying to “Win”: If you are the IT manager, don’t try to win against Security. If you “win,” the company loses. The goal is a secure system, not a political victory.
  • Over-Automation: Don’t automate a broken process. If your change management process is broken, automate it, and you’ll just have a faster broken process. Fix the process first, then automate it.
  • Ignoring the “Human Firewall”: The best security software can’t stop a user from clicking a phishing link. Ensure both IT and Security are involved in training the workforce. This is a shared responsibility.

The Role of Scott Alldridge and VisibleOps Cybersecurity

This is where Scott Alldridge’s experience becomes invaluable. He’s not a theorist; he’s a practitioner. With an MBA in Cybersecurity, CISSP, CCISO, and Harvard certification in Privacy and Technology, he has walked the walk.

The VisibleOps Cybersecurity framework provides the exact tools to bridge this gap. The handbooks offer:

  • Benchmarks and ROI Graphs: These show the financial value of integration. They help you prove to the executives that spending on security is not a cost, but an investment in efficiency.
  • Leadership Takeaways: Each section contains actionable advice for leaders.
  • Real-World Examples: The framework is based on decades of experience in IT management and cybersecurity.

If you are struggling with the “two bosses” problem, the VisibleOps Cybersecurity Handbook is essentially a manual for fixing it. It doesn’t just tell you to “get along”; it tells you how to align processes, metrics, and technologies to make the friction go away.

Additionally, for those looking at the future, VisibleOps AI: Governance, Risk, and Leadership in the Age of Intelligent Systems extends these principles to AI. As AI becomes more integrated into IT and Security, the governance of these systems will be the next big battleground. Getting the IT/Security relationship right now is the foundation for managing AI risks later.

Frequently Asked Questions (FAQ)

Q: Our CISO and CIO hate each other. What’s the first step?

A: Don’t try to fix the personalities. Fix the process. Create a joint project or a joint governance committee. Give them a business problem to solve together (like a compliance audit). The shared goal often softens the personal friction.

Q: How do we handle emergency patches if the security team reports to a different boss?

A: You need a “Break Glass” protocol. Pre-define what constitutes an emergency. If the criteria are met, the IT team can act immediately to patch the system, but must document the change and notify the Security boss within the hour. This builds trust.

Q: We can’t afford a big consulting project. Where do we start?

A: Start with visibility. Get a tool that both teams can see. Then, read the VisibleOps Cybersecurity Handbook. It is designed to be practical and cost-effective. Many of the solutions are process-oriented, not tool-oriented.

Q: Is it better to just put Security under IT to solve this?

A: Not necessarily. While this solves the reporting line issue, it can dilute security oversight. The goal is to keep the independence of security while integrating the operations. VisibleOps and Zero Trust can achieve this without a reorg.

Q: How do we know if it’s working?

A: Track your “Mean Time to Remediate” (MTTR) and your “Change Success Rate.” If MTTR goes down and Change Success goes up, the friction is decreasing.

Conclusion: Turning Friction into Function

Having IT and Security report to different bosses is a common reality. It’s often born from a desire for checks and balances, but it can easily devolve into a turf war that puts your data at risk.

However, you don’t need a sweeping reorganization to fix this. By adopting a framework like VisibleOps Cybersecurity, you can bridge the gap. You can align metrics, integrate change management, and implement Zero Trust principles. You can turn two separate teams into one cohesive unit.

The key is to stop focusing on who reports to whom and start focusing on what you are trying to achieve together. Whether you are an IT manager, a security professional, or an executive, the tools and methodologies developed by Scott Alldridge and the ITPI provide a roadmap.

Don’t let the org chart dictate your security posture. Take control of the narrative, build the bridge, and secure your future.

Ready to dive deeper? Explore the VisibleOps Cybersecurity handbook series to get the full blueprint for integrating your operations and security teams, or check out the Executive Companion Handbook to get your leadership on board.