Search for content, post, videos

Three Disciplines, One Mission: Understanding the Roles of IT, Security, and Privacy

Twenty years ago, if you asked someone in an office what “IT” meant, they would say it was the person you called when the printer jammed or your email stopped working.

Fast forward to today, and IT, security, and privacy have quietly become three of the most consequential functions inside any organization, right up there with finance and legal. And yet, a surprising number of executives still treat them as a single blob called “the tech stuff.”

That confusion is not just a semantic annoyance. It costs money, it costs trust, and in 2025 it cost the average breached organization in the United States a record 10.22 million dollars, according to IBM’s Cost of a Data Breach Report. Globally, the average dropped slightly to 4.44 million dollars, the first decline in five years, largely thanks to AI-assisted detection cutting the time to identify and contain a breach down to 241 days. Progress, sure. But 241 days is still eight months of an intruder having the run of the house before anyone notices.

So let’s clear something up, once and for all: IT, security, and privacy are related, but they are not the same job, they do not have the same goals, and treating them interchangeably is exactly how organizations end up on the front page for the wrong reasons.

Three Disciplines, One Boardroom Headache 

Here is the plain language version, the one I wish someone had handed me two decades ago.

  • Information Technology is about making things work. Servers run, applications load, employees can log in and get their jobs done. IT’s mission is uptime, efficiency, and enabling the business. If IT does its job well, nobody notices it exists.
  • Security is about keeping the bad guys out, and just as importantly, knowing what to do when they get in anyway (because they will, eventually, no matter how good your defenses are). Security asks: who can access what, how do we detect something unusual, and how fast can we respond before “unusual” becomes “catastrophic.”
  • Privacy is about respecting the data itself, not just protecting it from theft, but making sure it is collected, used, and shared the way the person it belongs to actually agreed to. Privacy asks a very different question than security does: even if nobody stole this data, are we using it in a way our customers, regulators, and our own conscience would be comfortable with?

Here’s the part that trips people up: you can have excellent IT and lousy security. You can have airtight security and still violate privacy laws left and right, because a perfectly secured database of data you had no right to collect is still a legal landmine. These three disciplines overlap, argue, and depend on each other constantly. Treating them as one function is like asking your accountant to also be your lawyer and your therapist. They might be capable people, but that is three very different skill sets wearing one exhausted hat.

Why This Distinction Is Suddenly Urgent 

For most of my career, this was an academic argument, mostly confined to conference panels and mildly heated LinkedIn threads. Not anymore. Two forces have collided to make the distinction unavoidable for anyone in a leadership seat.

The first is regulation, and it is arriving fast. As of early 2026, twenty US states now have comprehensive privacy laws on the books, with Indiana, Kentucky, and Rhode Island joining the list this year alone. States are not just passing these laws either, they are enforcing them, with an estimated 3.425 billion dollars in privacy-related fines issued across US states in 2025, according to Gartner. Meanwhile, the EU AI Act reaches full enforcement on August 2, 2026, requiring organizations to maintain a documented inventory of their AI systems, a risk classification for each one, and clear disclosures about how those systems are used. If your organization cannot answer “what AI is running on our data, and why” with a straight face, you have some homework to do before that deadline lands.

The second force is AI itself, which has become both the shiny new productivity tool and a fresh attack surface, sometimes in the same product. IBM’s research found that 97% of organizations that suffered an AI-related security incident had no proper access controls on their AI systems, and 63% had no AI governance policy at all. Read that again. It is not that the controls failed. In most cases, they simply were never built. That is not a security problem or a privacy problem in isolation. It is both, tangled together, and it needs both disciplines pulling in the same direction to fix.

The Practical Part; Because Nobody Wants Another Lecture

If you are a CISO, a privacy officer, or anyone with “information” somewhere in your job title, here is what this actually means for your Monday morning:

Stop letting “we are secure” and “we are compliant” be treated as synonyms in board meetings. They answer different questions, and a board that only hears one of them is flying half blind.

Build your AI governance program before regulators or auditors force you to. An inventory of every AI tool touching customer or employee data, who approved it, what data it touches, and what happens if it is wrong, is no longer optional homework. It is table stakes, and August 2026 is closer than it looks on a calendar.

Get your privacy and security teams talking to each other on a regular cadence, not just during incident response. Security tends to think in terms of confidentiality, integrity, and availability. Privacy thinks in terms of consent, purpose limitation, and individual rights. Both are right. Both are needed. Neither one alone tells the whole story of whether your organization is actually trustworthy with the data it holds.

And translate all of this into business language for your executives. Nobody in the C-suite needs to understand the difference between symmetric and asymmetric encryption. They do need to understand that a privacy misstep and a security breach are two different fires, they spread differently, and they need two different fire departments, working from the same playbook, ready before the smoke starts.

A Final Reflection

I have spent twenty years watching this field mature from “the people who fix the printer” into a set of disciplines that quite literally determine whether an organization survives a bad year. What strikes me most, looking back, is not how much the technology has changed (though it has, dramatically), but how slowly our language and our org charts have caught up to that change.

Information technology, security, and privacy are not competing priorities fighting for the same budget line. They are three different lenses on the same responsibility: earning and keeping the trust of the people whose data you hold. Get the technology right and things run. Get the security right and things stay standing when someone tries to knock them down. Get the privacy right and people actually want to keep giving you their data in the first place.

Miss any one of the three, and the other two will not save you. So the next time someone in a meeting says “let’s just get IT to handle the privacy stuff,” do the field a favor: gently correct them. Twenty years from now, I would like the next generation of practitioners to inherit a boardroom that already understands the difference, so they can spend their careers solving new problems instead of still explaining the old ones.

Leave a Reply

Your email address will not be published. Required fields are marked *