Skip to main content
Dig IT Solutions logo

Cyber Security

IT support vs cyber security: what is the difference and do you need both?

How IT support and cyber security differ, what a managed IT contract usually includes versus a security contract, and how to check your provider covers both.

By Dig IT SolutionsUpdated 8 September 20266 min read

Short answer

IT support keeps your systems working: helpdesk, devices, software, networks, backups and updates. Cyber security keeps them from being misused: access control, threat detection, incident response, policy and compliance. They overlap in patching and backups, but a standard IT support contract does not automatically include monitoring, incident response or certification work. Most businesses need both, ideally from one accountable provider.

Many businesses assume that because a company looks after their computers, that company is also keeping them secure. Sometimes it is. Often the contract says nothing of the kind, and the gap only appears when something goes wrong and each party assumed the other was watching. This article sets out what IT support and cyber security each cover, where they overlap, and how to read your own contract.

The short version

IT support is about function: making sure people can log in, print, email, share files and get help when something breaks. Cyber security is about protection: making sure nobody who should not be in your systems gets in, spotting them quickly if they do, and recovering if the worst happens.

Both are technical, both touch the same systems, and both are often delivered by the same people. But the objectives differ, the tools differ, and crucially the scope of a contract differs. "We look after your IT" does not by itself mean "we monitor for intrusions and will respond at 2am".

What each discipline does day to day

IT support sets up new starters and their devices, resolves helpdesk tickets, installs and maintains software, keeps the network running, manages printers and phones, applies updates, and looks after backups. It is measured by uptime, response time and whether staff can do their jobs. Our managed IT support page describes the typical scope.

Cyber security controls who can access what and with what proof, watches for signs of compromise across devices, identities and email, responds when something is detected, sets and enforces policy, trains staff, prepares for certification and supports compliance obligations such as UK GDPR breach reporting to the ICO. It is measured by risk reduced, incidents caught early and audits passed. Our cyber security services page lists what that looks like in practice.

The overlap is real and important: patching is both a support task and the second Cyber Essentials control, backups are both a support task and the last line of defence against ransomware, account creation and removal is both an onboarding task and an access-control requirement. That overlap is why splitting the two between different providers creates gaps.

What is in a managed IT contract versus a security contract

The table below is a fair reflection of what UK SMEs typically get. Individual providers vary, which is exactly why you should check yours.

AreaTypical managed IT support contractTypical cyber security contract or add-on
Helpdesk and on-site supportIncludedNot included
Device setup, joiners and leaversIncludedAccess reviews, least privilege, leaver audits
Windows and application patchingIncluded, via RMMPatch compliance reporting against the 14-day Cyber Essentials requirement, firmware included
AntivirusOften basic antivirus includedManaged EDR with alert handling and device isolation
BackupsBackup jobs configured and checkedImmutable or offline copies, ransomware-resilient design, documented restore testing, Microsoft 365 backup
FirewallInstalled and maintainedRule reviews, exposure scanning, secure remote access with MFA
Microsoft 365Licensing, mailboxes, SharePointMFA enforcement, conditional access, app consent restrictions, tenant hardening, sign-in monitoring
Email securityBasic spam filteringAdvanced filtering, link protection, SPF/DKIM/DMARC, impersonation protection
MonitoringDevice health and uptimeSecurity event monitoring, alert triage, response
Incident responseRestore from backupContainment, investigation, evidence preservation, ICO reporting support
Staff trainingNot usuallyAwareness training and simulated phishing
Policy and complianceNot usuallySecurity policy, incident plan, Cyber Essentials preparation, insurer questionnaires

If your current agreement covers only the left-hand column, you have IT support without security, however good the support is.

The tools tell you which is which

IT support runs on remote monitoring and management (RMM) platforms, helpdesk ticketing, Microsoft 365 administration, remote access tools such as Splashtop and backup software. Cyber security adds endpoint detection and response, identity protection and conditional access, email security gateways, vulnerability scanning, log collection and, in larger environments, security information and event management (SIEM). Ask a provider which of the second group they operate for you and who looks at the output. If the answer is "the alerts go to a mailbox", that is not monitoring. For a fuller explanation of the difference between antivirus and EDR see EDR vs antivirus.

The incidents tell you too

IT support handles: a laptop that will not boot, a slow network, an application crash, a forgotten password, a new starter's setup, a deleted file that needs restoring.

Cyber security handles: a sign-in from a country you do not operate in, an EDR alert on a file server, a staff member who entered their password on a fake Microsoft page, a supplier reporting that "you" emailed them new bank details, a ransomware note, and the question of whether personal data was exposed and must be reported within 72 hours.

The support desk is usually the first to hear about a security incident, because the user calls to say something looks odd. What matters is whether anyone behind the desk is equipped to investigate, contain and report rather than reboot and close the ticket.

Why the commercial roles differ

From a director's point of view, IT support is an operating cost that keeps staff productive, downtime is expensive and visible, so response and uptime are the measures. Cyber security is a risk control: its value is the incident that did not happen, the insurance claim that was paid because the questionnaire was answered honestly, the public-sector tender you could bid for because you hold Cyber Essentials. It is easier to skimp on because its absence is invisible until it is not.

The Cyber Security Breaches Survey has found for years that a large share of UK businesses experience a breach or attack annually and that phishing dominates. Very few of those incidents are addressed by a faster helpdesk.

Should they be separate suppliers?

For large organisations, yes: dedicated security teams and separate assurance. For a business of up to 250 people, splitting support and security between two suppliers usually costs more and works worse, because the two overlap so heavily. The patching provider blames the security provider for the alert, the security provider blames the patching provider for the missed update, and the business sits in the middle.

What works is a single accountable partner whose contract explicitly lists both, with the security services named and priced rather than assumed. If you have internal IT, the same logic applies in a co-managed arrangement: your team keeps the desk, the partner supplies the tooling and the 2am response.

Questions to ask your current provider

  1. Which security services are listed in our contract, and which are extras?
  2. Do we have EDR on every device, and who acts on its alerts?
  3. Is MFA enforced for every user, with conditional access, or just "available"?
  4. Can you show me a patch compliance report for last month, including the firewall firmware?
  5. Is there a backup copy that a compromised administrator account could not delete, and when was a full restore last tested?
  6. What happens, step by step, if ransomware is detected on a Friday night?
  7. Would you support us through Cyber Essentials and an ICO breach report?

If the answers are vague, our guide to switching IT provider explains how to move without disruption.

What to do next

If you are not sure which column your current contract sits in, send it to us. An IT health check reviews what is actually in place against the table above and tells you, in plain terms, what is covered, what is not, and what it would take to close the gap.

Frequently asked questions

Can one provider handle both IT support and cyber security?
Yes, and for a business of up to 250 people it is usually the better arrangement, because patching, account management and backups sit in both disciplines and finger-pointing between two suppliers is a real risk. The test is whether the security services are explicitly listed and priced in the contract rather than assumed to be included.
How do I know if my IT support contract covers cyber security?
Read the service schedule. If it lists helpdesk, updates and backups but says nothing about endpoint detection and response, monitoring of security alerts, MFA enforcement, incident response or Cyber Essentials, then security is not in scope. Ask the provider directly what happens at 2am when EDR flags ransomware on a server, and who is responsible for the response.
Are antivirus and a firewall enough?
No. Both are necessary, but modern attacks mostly come through stolen credentials and phishing, which neither addresses. A baseline for a UK SME today is MFA and conditional access, EDR rather than plain antivirus, managed patching, email filtering, tested backups that an attacker cannot reach, and someone watching the alerts.
Is cyber security only needed after an attack?
The opposite. After an attack the costs are recovery, downtime, possible ICO reporting and customer conversations, all of which cost more than the controls that would have prevented it. Cyber security is preventive by design. The businesses that recover well from incidents are the ones that had detection and tested backups in place beforehand.
Which industries need to prioritise cyber security alongside IT support?
Any business holding client money, personal data or confidential information: law firms, accountants, healthcare practices, estate agents, recruiters and anyone bidding for public-sector work where Cyber Essentials is required. In practice every business with email and online banking is exposed, the sectors above simply have more to lose and more regulators watching.
What should a co-managed arrangement look like for a business with internal IT?
The internal team keeps day-to-day support and local knowledge, the external partner supplies the security tooling, monitoring, alert handling and specialist response that a one- or two-person team cannot sustain around their other work. Responsibilities are written down so that both sides know who owns patching, who owns alerts and who leads an incident.

Next step

Not sure how exposed you are?

An IT health check reviews your security, backups, Microsoft 365 and network and gives you a prioritised list, whether or not you work with us afterwards.

WhatsApp us