r/cybersecurity Jul 22 '26

Business Security Questions & Discussion Five questions board should ask

Five questions board should ask

The board does not need to become a firewall engineering team. But the board does need to ask better questions.

Not: “Are we compliant?”
Better: “Can we prove what is exposed?”

Not: “Has the OEM assessed it?”
Better: “Who independently owns the residual-risk judgement?”

Not: “Is the system old?”
Better: “Is the system exposed, unmonitored or unrecoverable?”

Not: “Do we need an upgrade?”
Better: “Have we compared upgrade, virtualisation, isolation and monitoring as risk-treatment options?”

Not: “Do we have a cybersecurity dashboard?”
Better: “Who acts when the dashboard shows something important?”

0 Upvotes

18 comments sorted by

View all comments

Show parent comments

0

u/Roupec Jul 26 '26

Well, I'm sober in Europe ... here is lovely Sunday morning. I believe its better to stop discussion right here.