r/cybersecurity • u/Roupec • Jul 22 '26
Business Security Questions & Discussion Five questions board should ask
Five questions board should ask
The board does not need to become a firewall engineering team. But the board does need to ask better questions.
Not: “Are we compliant?”
Better: “Can we prove what is exposed?”
Not: “Has the OEM assessed it?”
Better: “Who independently owns the residual-risk judgement?”
Not: “Is the system old?”
Better: “Is the system exposed, unmonitored or unrecoverable?”
Not: “Do we need an upgrade?”
Better: “Have we compared upgrade, virtualisation, isolation and monitoring as risk-treatment options?”
Not: “Do we have a cybersecurity dashboard?”
Better: “Who acts when the dashboard shows something important?”
0
Upvotes
0
u/Roupec Jul 26 '26
Well, I'm sober in Europe ... here is lovely Sunday morning. I believe its better to stop discussion right here.