Insights

Who Owns GIS Security at Your Organization?

GIS mapping and underground utility data displayed on a tablet during a site visit.

September 25, 2026

By Alex Johnson, Lead Solution Architect, WSB

Geographic information systems, or GIS, rarely remain just mapping systems. Over time, GIS becomes connected to infrastructure, assets, permitting, planning, emergency response, field operations, regulatory compliance, and public-facing applications. As GIS becomes more integrated into daily operations, protecting it becomes increasingly important.

The challenge is that responsibility for GIS security is not always clear. IT teams may manage infrastructure and cybersecurity, GIS administrators manage the platform and user access, and department leaders rely on GIS to support critical business functions. As GIS grows across an organization, security responsibilities can become fragmented or unclear.

Why Does GIS Security Matter?

For executive and department leaders, GIS security is not simply a technology issue. It is a business continuity and organizational risk issue The key question is not whether a particular security setting has been enabled, it is whether your organization understands which services, decisions, and business processes depend on GIS, and what would happen if that information became unavailable or could not be trusted.

GIS often supports infrastructure management, planning and permitting, emergency response, field operations, public-facing applications, and integrations with other business systems. Not every GIS application carries the same level of risk. A public reference map has very different security requirements than an application supporting emergency response, regulated assets, or critical operations. Leadership does not need to manage technical controls, but it should identify which GIS capabilities are most important and establish expectations for protecting and restoring them.

Who Is Responsible for GIS Security?

GIS security works best when responsibilities are clearly defined across the organization.

IT teams typically manage network security, servers, identity management, backups, and cybersecurity policies. GIS administrators oversee platform configuration, user roles, sharing settings, and service dependencies. Executive and department leaders determine which services are most critical and what level of disruption the organization can tolerate.

A useful starting point is identifying ownership for:

  • Infrastructure security
  • GIS platform configuration
  • User access and permissions
  • Software updates and patches
  • Backup and recovery testing
  • Vulnerability remediation
  • Business continuity planning

The goal is not to assign everything to one person, but to eliminate assumptions and establish accountability across GIS, IT, and leadership teams.

Where Should Organizations Start?

A practical GIS security review can begin with five steps:

  1. Identify what depends on GIS. Document the services, applications, and processes that rely on GIS.
  2. Define responsibilities. Establish ownership for key security and operational functions.
  3. Assess the current environment. Review user access, public sharing settings, software versions, patches, backups, and platform configurations.
  4. Prioritize improvements. Address issues based on risk and operational impact.
  5. Create a recurring review process. Regular reviews help keep pace with evolving systems, users, and integrations.

For enterprise GIS platforms, reviews should consider both the supporting technology environment and the GIS platform itself. GIS and IT teams should evaluate findings together, while leadership helps prioritize efforts based on operational needs.

Five Questions Leadership Can Ask

Executive and department leaders do not need to become GIS security specialists, but they should ask:

  1. What important organizational functions depend on GIS?
  2. Who owns security for the GIS environment?
  3. When was the environment last reviewed against current vendor guidance?
  4. Do GIS and IT review security findings together?
  5. Is there a tested way to restore essential GIS capabilities?

If these questions are difficult to answer, governance may need attention.

GIS has become essential operational infrastructure for many organizations. Protecting it starts with understanding what depends on it, defining ownership, and creating alignment between leadership, IT, and GIS teams.

WSB helps organizations assess GIS environments, identify security risks, clarify governance responsibilities, and develop practical strategies that support security and operational continuity. Whether evaluating a current GIS environment or strengthening long-term governance, our team can help build a more secure and resilient GIS program. Contact WSB to learn how a GIS security review can help reduce risk and strengthen organizational preparedness.

Alex Johnson is a Lead Solution Architect at WSB with more than 11 years of GIS experience. He helps organizations strengthen their GIS environments, align technology with operational needs and develop solutions that support complex workflows and long-term goals.

651.286.8483
WSB Staff working in the lobby of the WSB headquarters.

Discover Our Difference

We partner with our clients and communities to build what’s next in infrastructure – the places, spaces, and systems that support our lives.