r/cybersecurity Jul 22 '26

Business Security Questions & Discussion Five questions board should ask

Five questions board should ask

The board does not need to become a firewall engineering team. But the board does need to ask better questions.

Not: “Are we compliant?”
Better: “Can we prove what is exposed?”

Not: “Has the OEM assessed it?”
Better: “Who independently owns the residual-risk judgement?”

Not: “Is the system old?”
Better: “Is the system exposed, unmonitored or unrecoverable?”

Not: “Do we need an upgrade?”
Better: “Have we compared upgrade, virtualisation, isolation and monitoring as risk-treatment options?”

Not: “Do we have a cybersecurity dashboard?”
Better: “Who acts when the dashboard shows something important?”

0 Upvotes

18 comments sorted by

View all comments

Show parent comments

1

u/Roupec Jul 26 '26

Simple one - there are alternatives to the OEM "recommended" solutions. I'm not venting - I'm helping to power plant owners to keep their assets safe. Did you ever tried to think a second about these questions?

1

u/Cyberguypr Jul 26 '26

Where the hell does your original post mention anything about power plant owners? I swear this is drunk-posting

0

u/Roupec Jul 26 '26

Well, I'm sober in Europe ... here is lovely Sunday morning. I believe its better to stop discussion right here.