You wouldn't let your accountant audit their own books. Why treat cyber security any differently?
- Iain Wadds

- Jun 15
- 2 min read
If there’s one thing I’ve had to repeat more than any other since founding this business, it is that Barefoot Cyber will not do our clients’ IT. We could have, many times. It is not because we lack the capability, but because doing so would compromise the integrity of our business.
The role of an IT team or service provider is to keep systems running, support users, and manage devices, networks, licences, backups, and uptime.
Cyber security makes sure the business operates safely, responsibly, and with risk in mind.
We are specifically concerned with security policy and control requirements, threat monitoring, governance and regulatory alignment, incident response, and third-party risk.
IT keeps the business operating. Cyber security makes sure it operates safely, responsibly, and with risk in mind.
Here is why that matters.
In what business would it be acceptable for your accountant to also audit your accounts? Corporate governance sets these principles out very clearly, and cyber risk should be treated in much the same way. IT implements and operates controls. Cyber security should challenge, verify, and govern those controls.
Barefoot Cyber needs to operate with enough independence to challenge IT decisions, test assumptions and hold control owners accountable. That is our business.
Any IT service provider can sign up as a Fortinet reseller and claim cyber security as part of its portfolio, but that reduces cyber to tools, licences, and vendor badges. Barefoot Cyber will always employ people with solid experience, strong independent certifications, and a genuine focus on client risk.
A business can have excellent IT and still be dangerously exposed. Systems can be patched and backed up, users trained and supported with perfect uptime, yet someone still needs to regularly check for weaknesses, prepare for and detect incidents, assess risk, enforce policy and align with regulation. Good IT is important. It is essential. But it is not, by itself, cyber security.
That is why even businesses with an internal IT team should see value in working with a specialist cyber security partner. The purpose is not to replace IT, undermine IT, or create friction. The purpose is to bring independence, specialist depth, and a risk-first perspective that most internal IT functions were never designed to provide. Internal IT quite rightly focuses on service delivery and operational continuity. Cyber security must focus on exposure, control effectiveness, resilience, and accountability.
That is where Barefoot Cyber sits. We are not here to sell the illusion of security through licences and vendor relationships. We are here to provide independent expertise, objective challenge and a service built around protecting the business as a whole. IT and cyber security should work closely together, but they should never be mistaken for the same thing. When they are, risk does not go down. It often becomes harder to see.



