
The 40-something IT-manager is not a security control!
When criminals stop attacking infrastructure and start applying pressure to the people who run it, cybersecurity becomes a question of leadership, duty of care and organisational design.
Editor’s note: This article was inspired by “Ransomware gangs skip the CEO, head straight for the 40-something IT manager”, published by The Register.
For years, the popular image of ransomware has been technical. Systems are encrypted, backups are tested and a demand appears on a screen. The organisation calls its security provider, insurer and lawyers. However disruptive the incident becomes, the crisis still fits inside a familiar frame: criminals attack the company’s technology, and the company responds with technology, money and governance.
That frame is becoming dangerously incomplete.
If ransomware gangs are beginning to focus their pressure on the ordinary, middle-aged IT manager rather than the chief executive, the important detail is not the target’s age or job title. It is the position that person occupies inside the organisation. They may know where the backups are, which accounts matter, which systems cannot be unavailable and which workarounds will keep the business alive. They are trusted enough to have access, responsible enough to feel the consequences and often insufficiently senior to command the resources or protection that a crisis demands.
That combination makes them valuable. It also makes them vulnerable.
Responsibility without authority
Many organisations have quietly built their operational resilience around a small number of people. These people are rarely described as critical infrastructure, but that is what they have become.
The IT manager who has been with the company for fifteen years may understand legacy systems that no diagram fully explains. During an incident, colleagues turn to them because they can translate technical failure into practical action.
Yet the same person may have little control over security budgets, staffing levels or risk acceptance. They may have spent years warning that a platform needed replacing or that one administrator should not hold so much institutional knowledge. Those proposals may have been delayed because the systems still worked.
Then the crisis arrives, and responsibility flows downhill.
This is the contradiction criminals can exploit. The organisation has placed enormous operational responsibility in one person without giving that person equivalent authority, redundancy or protection. A threat directed at them does not need to be technically sophisticated. It only needs to activate the fears already built into the role: fear of making the wrong decision, of letting colleagues down, of being blamed for the outage, of losing a career, or now, of bringing danger to a family.
The phrase “40-something IT manager” is powerful because it suggests a life beyond the office. A partner, children, ageing parents, a mortgage, a recognisable home address and perhaps decades of personal information scattered across public databases and social media. It should not be treated as a precise demographic profile. It is shorthand for accumulated responsibility and accumulated exposure.
The attack surface now includes a private life
Security programmes are comfortable discussing attack surfaces. They inventory servers, cloud services, identities, endpoints and suppliers. Far fewer organisations are prepared to accept that an employee’s private life may become part of the attack surface created by their work.
Once criminals use home addresses, family details or threats of physical harm, the incident no longer belongs solely to the security team. It crosses into physical security, human resources, legal responsibility, crisis communications and employee welfare. A well-configured endpoint cannot reassure someone whose child’s school has been named in a message. Multifactor authentication does not resolve the fear created by a photograph of a home.
This does not make technical controls less important. Strong identity management, resilient backups, network segmentation and tested recovery still reduce an attacker’s leverage. But they cannot be the whole answer when the pressure moves from a system to a person.
The deeper problem is isolation. Extortion works by making the target feel that they alone must act, decide or conceal. An IT manager may believe that reporting a threat will create panic or expose them to suspicion. If the organisation has never discussed this possibility, the victim is forced to invent a response while frightened and under time pressure.
That is not an individual failure. It is a missing organisational control.
The myth of the heroic administrator
Technology culture has long romanticised the indispensable administrator who answers the phone at 02:00, remembers every exception and can recover the business through experience and stubbornness. Their heroics are celebrated precisely because the organisation depends on them.
But indispensability is not resilience. It is concentrated risk with a human face.
When one employee can reach every critical system, possesses unique knowledge and is expected to remain available during any emergency, the business has created an obvious point of pressure. The same qualities that make the employee effective during an outage make them attractive during an extortion attempt.
Mature organisations should stop rewarding this design. Knowledge needs to be shared. Privileged actions should require more than one person where the consequences justify it. Recovery must work when a key employee is unavailable or considered potentially compromised. Crisis authority should be explicit before an incident.
This is often presented as succession planning or operational hygiene. It is now also personal protection. If no single employee can quietly satisfy an attacker’s demand, there is less value in isolating that employee in the first place.
Duty of care must follow the risk
Companies accept that some roles create additional physical risk and provide protective measures for executives, lone workers and staff travelling to unstable regions. Cybersecurity roles have not always been viewed through the same lens, even when employees hold access that criminals can monetise.
That needs to change.
An organisation that gives someone privileged access also gives them a form of occupational exposure. The business benefits from that access, so the business must take responsibility for the risk surrounding it. It cannot expect the employee to absorb threats against their household as an unfortunate extension of the job.
This duty of care should be practical. Employees in exposed roles need a confidential way to report coercion without being treated as suspects. They must know they are not expected to negotiate or protect the company alone. They need rapid access to senior decision-makers, specialist support and, where appropriate, law enforcement and physical protection. Support should extend to family members when a threat reaches them.
Privacy support also matters, but it must remain voluntary and respectful. Organisations can help exposed staff understand what personal information is publicly available, remove unnecessary biographical detail from corporate websites and offer reputable assistance with data-broker removal or account security. The answer is not intrusive monitoring of employees’ families. It is giving people the knowledge and resources to reduce exposure without demanding that they disappear from public life.
A board issue disguised as an IT problem
The move towards personal coercion should change the questions leaders ask about ransomware.
Boards often ask whether backups are isolated and how quickly critical services can be restored. They should also ask which individuals an attacker would identify as pressure points. Who has extensive access but limited support? Whose knowledge is difficult to replace? What happens if one of them receives a credible threat at home?
These are governance questions because the answers reflect how authority, accountability and risk have been distributed across the organisation.
A useful exercise is to remove the key IT manager from a ransomware scenario. Assume they cannot be contacted, or that their requests must be independently verified because they may be under coercion. Can the organisation still recover? Are emergency credentials accessible through a controlled process? Can leaders decide without turning technical staff into de facto negotiators?
If the response plan collapses without one named person, the company does not have a response plan. It has a dependency.
The same principle applies after an incident. Leaders should resist the instinct to search immediately for the person who clicked, failed to patch or did not escalate quickly enough. Accountability matters, but blame applied before understanding creates exactly the silence attackers need. People report coercion early only when they believe the organisation will protect them first and investigate fairly.
Resilience is a promise to people
Ransomware has always been a business model built around leverage. Encryption created leverage over availability. Data theft created leverage over confidentiality and reputation. Personal intimidation creates leverage over fear, loyalty and the instinct to protect the people closest to us.
The response cannot be another product added to the security stack. It requires a stronger social contract between organisations and the people trusted to run them.
That contract should be simple. No employee should face a threat alone. No critical process should depend on one person’s courage. No administrator should be expected to choose between protecting a family and protecting an employer. And no board should describe ransomware as an IT problem when criminals are deliberately exploiting the way the business distributes power and care.
The 40-something IT manager is not merely the latest target in an evolving threat report. They are a mirror held up to the organisation. They reveal where knowledge has been concentrated, where authority has been withheld, where resilience has been confused with personal sacrifice and where duty of care stops too early.
The next generation of ransomware preparedness must protect systems, but its maturity will be measured by something more human: how difficult it is for an attacker to isolate one person and make them carry the weight of an entire corporate crisis.



