https://www.miningweekly.com
DigitalShield|Microsoft|The Cloud Crew|Backup And Recovery|Cloud Security|Cybersecurity|Identity And Access Management|Incident Response|Managed IT|Patch Management|Ransomware|Threat Detection|OneDrive|SharePoint|Azure – Technology|Microsoft 365
|||
digitalshield|microsoft|the-cloud-crew|backup-and-recovery|cloud-security|cybersecurity|identity-and-access-management|incident-response|managed-it|patch-management|ransomware|threat-detection|onedrive|sharepoint|azure-technology|microsoft-365

Cybersecurity is now part of managed IT, not a separate conversation

21st September 2026

     

Font size: - +

This article has been supplied and will be available for a limited time only on this website.

I still see businesses drawing a neat line between IT operations and cybersecurity. One team looks after Microsoft 365, user access, endpoints, backups, patches and support, while security is handled through separate tools, policies or specialist providers.

That separation starts to look less convincing in the course of an ordinary support day. A user reports a suspicious sign-in after asking for help with their account. A new laptop needs to be configured for someone working remotely. A supplier needs access to a system to resolve a fault. These are everyday IT requests, but each one can quickly raise questions about identity, access, device security, or the need for further investigation.

Just look at Microsoft’s May 2026 investigation of Storm-2949. The attacker began with compromised cloud identities and went on to access Microsoft 365 data, including files in OneDrive and SharePoint, before moving into Azure resources. Microsoft found that the actor relied heavily on legitimate cloud and administrative features rather than traditional malware.

The incident shows how closely operational administration and security now overlap. Identity, permissions, remote access, cloud configuration, and the way users interact with systems can all become part of an attack path.

Security debt accumulates quietly

Most organisations do not wake up one morning to find themselves in a completely insecure environment. Instead, exposure tends to build in much less dramatic ways. For example, access granted for a short-term project is never removed, or a business-critical system stays unpatched because taking it offline would disrupt operations. Around those decisions, smaller configuration changes and workarounds accumulate until the environment no longer resembles the one the original controls were designed for.

Microsoft’s July 2026 Secure Future Initiative update reinforces this point. Its work includes secure-by-default configuration, identity controls, policy enforcement, monitoring, and configuration-drift detection across cloud environments. Security is treated as something that has to persist as the environment changes, rather than as a control applied once and left alone.

Managed IT therefore needs to account for security during routine administration. Nobody expects every support engineer to become a threat analyst, but teams do need to recognise when an ordinary support or configuration issue changes risk and requires specialist attention.

Backup and patching sit inside the security picture

Backup is another good example. It is often discussed as an availability function, but recovery becomes a security issue when ransomware, malicious deletion, account compromise, or accidental data loss enters the picture. Microsoft 365 Backup guidance includes ransomware and accidental or malicious deletion as scenarios that recovery planning needs to address.

Patching is another aspect that cannot be ignored. Microsoft reported this year that the ransomware actor Storm-1175 had weaponised some disclosed vulnerabilities in as little as one day. A deferred update can therefore create a much shorter window of exposure than an IT team expected.

Managed IT and cybersecurity cannot deal with these and other priorities in different ways. The team responsible for keeping systems available needs to understand the security consequences of postponing a change, while security specialists need enough operational context to know what can realistically be changed and when.

Managed IT needs a security escalation path

Managed IT and specialist cybersecurity remain different disciplines. Treating them as interchangeable would create its own problems.

At The Cloud Crew, our managed IT role keeps us close to the environment itself, including users, cloud services, configuration, backups, licensing, support, and infrastructure. DigitalShield provides the specialist depth needed for continuous monitoring, threat detection, investigation, vulnerability management, and incident response.

The value comes from connecting those capabilities properly. A suspicious login noticed during support, an unexpected configuration change, a failed recovery test, or an overdue patch should have a clear route into security investigation when required. Security findings should also feed back into how the environment is configured, supported, and maintained.

Cybersecurity has become part of managed IT because the attack surface is shaped daily by how technology is operated. Keeping the disciplines distinct is sensible. Keeping the conversations separate is increasingly difficult to justify.

Edited by Creamer Media Reporter

Article Enquiry

Email Article

Save Article

Feedback

To advertise email advertising@creamermedia.co.za or click here

Showroom

Rentech
Rentech

Rentech provides renewable energy products and services to the local and selected African markets. Supplying inverters, lithium and lead-acid...

VISIT SHOWROOM 
Multotec
Multotec

Multotec, recognised industry leaders in metallurgy and process engineering help mining houses across the world process minerals more efficiently,...

VISIT SHOWROOM 

Latest Multimedia

sponsored by

Photo of Martin Creamer
On-The-Air (18/09/2026)
18th September 2026 By: Martin Creamer

Option 1 (equivalent of R125 a month):

Receive a weekly copy of Creamer Media's Engineering News & Mining Weekly magazine
(print copy for those in South Africa and e-magazine for those outside of South Africa)
Receive daily email newsletters
Access to full search results
Access archive of magazine back copies
Access to Projects in Progress
Access to ONE Research Report of your choice in PDF format

Option 2 (equivalent of R375 a month):

All benefits from Option 1
PLUS
Access to Creamer Media's Research Channel Africa for ALL Research Reports, in PDF format, on various industrial and mining sectors including Electricity; Water; Energy Transition; Hydrogen; Roads, Rail and Ports; Coal; Gold; Platinum; Battery Metals; etc.

Already a subscriber?

Forgotten your password?

MAGAZINE & ONLINE

SUBSCRIBE

RESEARCH CHANNEL AFRICA

SUBSCRIBE

CORPORATE PACKAGES

CLICK FOR A QUOTATION







sq:0.051 0.078s - 141pq - 2rq
Subscribe Now