Cybersecurity, IT security and information security overlap so much that most people use them interchangeably, but they are not identical. CISA's explainer What is Cybersecurity? defines cybersecurity as "the art of protecting networks, devices, and data from unauthorized access or criminal use and the practice of ensuring confidentiality, integrity, and availability of information." Information security is broader in one direction, and IT security is often narrower in practice.
The labels matter less than what they hide. When a business owner in Canada or the US hears "IT handles security," it is worth knowing exactly which of these jobs is being done, and which is not. Here is how the main government sources define each term, and what that means for who owns what.
What is cybersecurity?
Cybersecurity is the protection of computers, networks and data from attack and unauthorized access. The Canadian Centre for Cyber Security's glossary defines cyber security as the "body of technologies, processes, practices and response and mitigation measures designed to protect networks, computers, programs and data from attack, damage or unauthorized access so as to ensure confidentiality, integrity and availability." That lines up closely with CISA's definition above.
Two things stand out in both definitions. First, cybersecurity is not only technology: it includes processes, practices and response. Second, both end with the same three goals, which are covered below.
How is information security different from cybersecurity?
Information security is defined around the information, not the technology that carries it. The NIST glossary defines information security as "the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability." Cybersecurity, by NIST's definition, centres on computers and electronic communications systems and the information they contain.
The two terms also have a shared history. NIST's glossary entry for cybersecurity notes that the term replaced "information assurance" in US Department of Defense and most US government policy documents in 2014, and that information assurance had earlier replaced "information security" and "computer security." It adds that the older terms "are still used in the USG and elsewhere depending on scope and intent." In other words, much of the difference is vocabulary, not substance.
What does IT security mean?
IT security usually means securing an organization's information technology: its computers, servers, networks, accounts and cloud services. In practice it is used as a synonym for cybersecurity. The Canadian Centre for Cyber Security uses both terms in the same guidance; its baseline cyber security controls for small and medium organizations say "organizations should identify someone in a leadership role who is specifically responsible for their IT security."
The more useful distinction is not IT security versus cybersecurity. It is IT administration versus security, which is where small businesses tend to get caught out.
Why does the difference between IT support and security matter?
Because keeping systems running and keeping attackers out are different jobs, and a contract can cover one without the other. The Cyber Centre's guide ITSM.10.023 says "an MSP offers information technology (IT) administration, whereas the MSSP takes care of cyber security," and that an MSP may run a network operations centre to keep IT running smoothly "but may not provide security related monitoring as part of that service."
ITSM.10.023 adds that some MSPs do offer endpoint, network and cloud security services, and advises businesses with an MSP contract to "check to see which security services they offer." Our guide to choosing a managed IT and cybersecurity provider makes the same point from the buyer's side: security gaps tend to live in the spaces between services, so ask whether security is part of the standard offering or a separate line item.
What goals do all three share?
Every definition above ends with the same three goals, often called the CIA triad: confidentiality, integrity and availability. The Cyber Centre's glossary defines them in plain terms:
- Confidentiality: "the ability to protect sensitive information from being accessed by unauthorized people."
- Integrity: "the ability to protect information from being modified or deleted unintentionally or when it's not supposed to be."
- Availability: "the ability for the right people to access the right information or systems when needed."
These goals are a practical test for any security spending. Ransomware attacks availability. A changed bank account number in an invoice attacks integrity. A leaked client file attacks confidentiality. If a proposed tool or service does not clearly protect at least one of the three, ask what it is for.
Who should own security in a small business?
A named person inside the business, even when an outside provider does the technical work. The Cyber Centre's baseline controls ask for someone in a leadership role who is specifically responsible for IT security, and ITSM.10.023 reminds businesses that outsource security that "you ultimately own the risk."
Many businesses already rely on outside help. In Statistics Canada's 2023 Canadian Survey of Cyber Security and Cybercrime, which covers businesses with 10 or more employees, half (50%) reported having cyber security employees, and the most reported reason for not having them was using consultants or contractors to monitor cyber security (47%). If that describes your business, our managed IT vs in-house cost comparison explains how the outsourced model shares a provider's expertise across many clients, and what you give up in control.
What should US and Canadian business owners ask next?
The vocabulary differs slightly between CISA, NIST and the Canadian Centre for Cyber Security, but the expectation is the same on both sides of the border: someone accountable, and protections that cover confidentiality, integrity and availability. Our small business cybersecurity checklist breaks that into areas like endpoint protection, email security and backups.
The question to put to your IT lead or provider is: "Which parts of our contract are IT administration, and which are security, and who watches for attacks?" To see where your own gaps are, take our free cybersecurity assessment. It covers 22 security areas in under five minutes.
This article is intended for general informational purposes only and does not constitute professional security, legal, or compliance advice. Definitions and statistics are based on public guidance from CISA, NIST, the Canadian Centre for Cyber Security and Statistics Canada available as of the date of publication. Organizations should consult qualified cybersecurity professionals before making decisions about security services or responsibilities based on this article.