Five questions every executive should ask their IT team

You don't need to be technical to lead on security. You need the questions that reveal what isn't working.

What data would we lose permanently if we were attacked today? How fast can we get back to work? Who has administrator rights and why? What did we learn from the last incident? What have we postponed for budget reasons, and what risk did we accept by doing so?

These five questions require no technical knowledge, but they demand concrete answers. And if the answers are vague, you already have the diagnosis: it isn't tools that are missing, it's clarity.

I recommend asking them quarterly, in writing, with short answers. Not as an audit, but as a leadership routine. Organizations that do this reach, in three or four cycles, a maturity others try to buy with far more money.

Back to writing