Scott Alldridge from IP Services explains the cyber incident most executives get wrong
UBA MediaJuly 10, 2026, 7:00 a.m. ET
Whenever a prominent organization suffers a high-profile cyberattack, the narrative typically revolves around the technology: the malicious software, the paralyzed systems, the prolonged downtime. Scott Alldridge, a cybersecurity expert with three decades of experience and the CEO of IP Services, contends that technology is almost never the origin of the failure. Over and over, he maintains, the actual entry point is something far more routine. A call placed to a help desk. An employee who bypasses a verification step. A documented procedure that nobody actually adhered to. The technology was not the weak spot. The process was.
That differentiation forms the core of an argument Alldridge has been advancing for thirty years. He co-founded the IT Process Institute, authored the VisibleOps series, and holds an MBA in cybersecurity alongside CCISO, ITIL, and CISSP certifications. His premise is straightforward and, for most boards, unsettling: the incident that cripples a company is seldom technical. It is operational. And operations fall under governance, not IT maintenance.
The breach occurred not because the technology broke down
Cybersecurity governance refers to the organizational structure that determines who is accountable for security choices, how procedures are documented and enforced, and how risk is handled across a business’s people, process, and technology dimensions. It does not consist solely of the technology layer. When governance falters at the process layer, no amount of technology can make up for it.
The majority of breaches Alldridge encounters follow the same quiet blueprint. Someone reaches out to a help desk. An identity verification measure is omitted. Credentials are transferred, access is granted, and within hours an adversary obtains what it requires. None of this required breaking through a firewall. It required a person, under strain, to disregard a protocol. The question he poses to every executive he meets hits hard: how many individuals in your organization know precisely what they are supposed to do when someone phones claiming to be an employee who has misplaced a password?
Why cybersecurity governance belongs on the board’s agenda, not in the IT budget line item
The widely adopted framework for cybersecurity encompasses five functions: identify, protect, detect, respond, and recover. Alldridge’s perspective is that most companies have only the protect function partially implemented, via technological tools, while the process and people layers that genuine governance depends on remain without ownership. That is the opening attackers exploit.
The gap, in his assessment, stems from a single executive tendency: handing over cybersecurity entirely to the IT department, then treating that handoff as a strategy. The board bears responsibility for revenue continuity, and cybersecurity governance is the operational system that safeguards it. An IT director is often the most technically skilled individual on site, but seldom possesses the authority, budget, or mandate to govern the process layer, the incident response plan, and the help desk protocols where breaches actually begin. Alldridge presents this as a structural reality, not a critique. No single security leader can govern all three layers by themselves.
The three closed-loop processes that stop these breakdowns
Governance, risk, and compliance—frequently abbreviated as GRC—are the three pillars most boards recognize. Alldridge adds an operational level beneath them, drawn from the methodology he has benchmarked across hundreds of organizations. Its central finding: industry estimates attribute more than 70% of outages and IT disruption to unauthorized, unapproved, and untested changes. The cybersecurity parallel follows directly: no breach occurs without a change, or a requirement for one.
His methodology counters that with three closed-loop processes. Configuration management defines what exists in the environment. Change management defines what is being altered, by whom, and with what approval. Release management defines how modifications are tested before going live. An organization that governs all three cannot be breached without the breach leaving a traceable change event behind. The lesson from nearly every major attack, in his interpretation, is not that the victim lacked tools. It is that no one governed the process layer where the change took place.



