CEO
July 20, 2026
Table of contents:
Cybersecurity conversations often begin with technology.
Which firewall does the business use? Is antivirus installed? Are software updates automatic? Who manages Microsoft 365?
Those are important questions, but they are not the only questions business leaders should be asking.
Cybersecurity is also about operational continuity, financial risk, employee behavior, vendor relationships and the organization’s ability to respond when something goes wrong.
The National Institute of Standards and Technology organizes cybersecurity risk management around six core functions: Govern, Identify, Protect, Detect, Respond and Recover. Its small-business guidance emphasizes that managing cyber risk is an ongoing business process, not simply a collection of technical products.
Business leaders do not need to become security engineers. However, they should be able to get clear answers to the following ten questions.
1. Do we know which technology and information we need to protect?
An organization cannot protect technology it does not know exists.
Businesses frequently add new software, cloud applications, devices and vendor integrations as needs arise. Over time, that can create an incomplete or outdated picture of the technology environment.
A useful inventory should include:
The inventory should also identify which systems are most important to daily operations.
For example, losing access to an old file archive may be inconvenient. Losing access to email, financial systems, production software or customer records could interrupt the entire business.
The leadership question: Do we know what we have, where our sensitive information resides and which systems must remain available?
2. Is multifactor authentication required everywhere it should be?
Passwords alone are no longer enough to protect important business accounts.
Multifactor authentication adds another verification step when someone attempts to sign in. CISA recommends using phishing-resistant MFA when available, particularly for administrative access and other high-value accounts.
MFA should be reviewed for:
Leadership should also understand which type of MFA is being used. Some methods provide stronger protection than simple text-message codes or repeated push notifications.
The leadership question: Which important accounts still rely on a password alone, and what is the plan for protecting them?
3. Are security updates installed, and is anyone verifying them?
Many businesses enable automatic updates and assume the problem is solved.
Automatic updates are useful, but updates can fail. Devices can remain offline. Applications may require manual intervention. Older systems may no longer receive security patches at all.
CISA lists software updates as one of its foundational recommendations for small and medium-sized businesses. Verizon’s 2026 Data Breach Investigations Report also found that vulnerability exploitation has become a major initial entry point for breaches.
A reliable update process should identify:
The leadership question: Can we prove that critical vulnerabilities are being identified, prioritized and corrected?
4. Can we restore the business from our backups?
Having backup software does not automatically mean a business can recover.
Backups can fail, become corrupted or remain connected to the same environment affected by an attack. A backup may also exclude a cloud application, database or configuration the organization needs to resume operations.
This matters because ransomware remains a widespread business risk. Verizon reports that ransomware is involved in 48% of breaches in its 2026 dataset.
A recovery strategy should define:
CISA’s ransomware guidance recommends planning for both prevention and response, including measures that reduce the operational impact of an incident.
The leadership question: When did we last perform a complete restoration test, and what did we learn?
5. How are employees expected to verify unusual requests?
Employees are often told to look for spelling mistakes, strange formatting and suspicious email addresses.
Those warning signs still matter, but modern phishing can be professionally written, accurately branded and delivered through a compromised account or legitimate online service.
Microsoft detected a sharp increase in QR-code phishing during the first quarter of 2026, with volume rising from 7.6 million attacks in January to 18.7 million in March. These campaigns often move targets from protected computers onto mobile devices where links and destinations are harder to inspect.
Employees need a clear verification process for requests involving:
The strongest defense is often a second communication channel. An employee can call a known telephone number, begin a new message to a trusted contact or ask a supervisor before acting.
The leadership question: Do employees know exactly how to verify a sensitive or unusual request?
6. Who has administrative access?
Administrative accounts can make major changes to systems, users and data.
That makes them useful for legitimate work and valuable to attackers.
Administrative access should be limited to people who genuinely need it. Employees should not use elevated privileges for routine activities such as reading email or browsing the internet.
Leadership should know:
The leadership question: Could we produce an accurate list of everyone with elevated access today?
7. Which vendors can access our systems or information?
Most businesses depend on outside providers.
Software companies, consultants, accountants, payroll providers, equipment vendors and IT partners may all have access to company systems or information.
That access should have:
Vendor access should not remain active indefinitely simply because no one remembered to disable it.
The same scrutiny should apply to software integrations. An application connected years ago may still be able to read files, access mailboxes or interact with customer data.
The leadership question: Which external organizations can access our environment, and when was that access last reviewed?
8. How quickly would we know something was wrong?
Prevention is important, but no organization can guarantee that every attack will be blocked.
Businesses also need the ability to detect suspicious behavior.
That may include monitoring for:
Detection only creates value when alerts reach someone who can investigate and respond.
The leadership question: Who receives security alerts, and what happens after an alert is generated?
9. Do we have a practiced incident-response plan?
A written incident-response plan is useful.
A practiced plan is much better.
During an actual cyber incident, leaders may need to make decisions involving operations, customers, employees, legal obligations, insurance coverage, public communication and law enforcement.
The plan should identify:
A tabletop exercise allows the team to test those decisions without waiting for a real emergency.
The leadership question: Has our leadership team practiced what it would do during the first hour of an incident?
10. Who is accountable for cybersecurity?
Cybersecurity frequently falls into a gap between departments.
Leadership assumes IT owns it. IT assumes executives have accepted certain risks. Human resources handles training. Finance manages insurance. Department leaders add new software. Vendors manage portions of the environment.
Everyone plays a role, but unclear ownership creates risk.
NIST added Govern as a core function of the Cybersecurity Framework 2.0, emphasizing that organizations should establish cybersecurity policies, responsibilities, oversight and risk-management priorities.
Accountability should include:
The purpose is not to make one person responsible for every task. It is to ensure every important task has an owner.
The leadership question: Who is responsible for cybersecurity outcomes, and how does leadership know whether the program is improving?
Strong cybersecurity begins with clear answers
Business leaders do not need to understand every technical configuration.
They should understand the organization’s risks, priorities, responsibilities and ability to recover.
The most concerning answer to any of these questions is not always “no.”
Sometimes, it is:
Those answers reveal where the organization needs greater visibility and accountability.
Turn these questions into an actionable plan
ValorTech helps businesses understand their technology environment, identify cybersecurity gaps and develop practical plans for reducing risk.
Whether your organization needs stronger identity protection, tested backups, security monitoring, employee education or a broader cybersecurity strategy, the first step is knowing where you stand today.
How many of these ten questions could your organization answer with confidence?
Talk with ValorTech about building a more secure and resilient technology environment.