ValorTech Logo
Solutions
Services
Partners
Resources
Company
Get Started
Get Started
Client Portal
(414) 410-9440
By Business Need
Identify Gaps in My Cybersecurity Plan
Identify Gaps in My IT Plan
Fulfill Compliance Assessments & Requirements
Replace Current IT Provider
Manage Business Continuity
Manage Complex Cybersecurity Technologies
Enhance & Scale My Internal IT Environment
By Industry
/api/icon/file/icon_healthcare.svg
Healthcare
/api/icon/file/icon_legal.svg
Legal
/api/icon/file/icon_Insurance.svg
Insurance
/api/icon/file/icon_finance.svg
Finance
/api/icon/file/icon_manufacturing.svg
Manufacturing
/api/icon/file/icon_education.svg
Education/NPO
/api/icon/file/icon_government.svg
Government
Solutions Hero
Save 10% With Cyber Warranty

ValorTech’s Cyber Warranty helps clients qualify for up to a 10% discount on cybersecurity insurance.

Learn More

Have an urgent need?

>>

Consult with an Expert
Discover ValorTech
We’re not your average MSSP. Born from a security-first mindset and built by people who care deeply about doing the right thing, ValorTech blends technical excellence with real-world purpose. From veteran roots to community impact, we lead with integrity—and back it up with bold, reliable tech that just works.
Learn more
/api/icon/file/icon_leadership.svg

Our Leadership

Meet our Visionaries

/api/icon/file/icon_culture_values.svg

Culture & Values

What Drives Us

/api/icon/file/icon_news_media.svg

News & Media

Latest Updates

/api/icon/file/icon_social_impact.svg

Social Impact

Rooted in Service

Contact Us
Have a challenge? Let’s talk—we’re the kind of partner who actually shows up and solves it.
Consult with an Expert
Current Client Support
Careers
Do work that matters—join a team that backs each other, builds boldly, and gives a damn. At ValorTech, we invest in our people the same way we invest in our tech—with purpose, trust, and a long-game mindset.
Learn more
Consult with an Expert
Services Header
Cybersecurity

Cybersecurity

Battle-tested and trusted to keep your business secure when it matters most.

Managed IT Services

Managed IT Services

Proactive, security-first IT support built to scale with your business.

IT Consulting

IT Consulting

Strategic guidance from engineers who actually understand your world—and speak your language.

Cloud Solutions

Cloud Solutions

Custom cloud environments optimized for agility, compliance, and growth.

Apple First Environments

Apple First Environments

Certified Jamf support for Apple-first environments — because great tech deserves great service.

Microsoft 365

Microsoft 365

Secure, streamlined collaboration powered by expert Microsoft 365 deployment and management.

Resources
/api/icon/file/icon_blog.svg

Blog

Proactive, security-first IT support built to scale with your business.

/api/icon/file/icon_downloadassets.svg

Downloadable Assets

Practical tools, checklists, and guides built to make your next move smarter and faster.

/api/icon/file/icon_trustcenter.svg

Trust Center

Where transparency meets accountability—see how we keep your data secure, always.

Featured Articles
Article

Why Troop Salute Hits Home for Me

Article

5 End-of-Year IT Quick Wins: The C-Suite Q4 Checklist

Have an urgent need?

>>

Consult with an Expert

10 Cybersecurity Questions Every Business Leader Should Ask in 2026

Cybersecurity
avatar
Bryan Sevener

CEO

July 20, 2026

Table of contents:

10 Cybersecurity Questions Every Business Leader Should Ask in 2026

10 Cybersecurity Questions Every Business Leader Should Ask in 2026

Cybersecurity conversations often begin with technology.


Which firewall does the business use? Is antivirus installed? Are software updates automatic? Who manages Microsoft 365?


Those are important questions, but they are not the only questions business leaders should be asking.


Cybersecurity is also about operational continuity, financial risk, employee behavior, vendor relationships and the organization’s ability to respond when something goes wrong.


The National Institute of Standards and Technology organizes cybersecurity risk management around six core functions: Govern, Identify, Protect, Detect, Respond and Recover. Its small-business guidance emphasizes that managing cyber risk is an ongoing business process, not simply a collection of technical products.


Business leaders do not need to become security engineers. However, they should be able to get clear answers to the following ten questions.




1. Do we know which technology and information we need to protect?

An organization cannot protect technology it does not know exists.

Businesses frequently add new software, cloud applications, devices and vendor integrations as needs arise. Over time, that can create an incomplete or outdated picture of the technology environment.

A useful inventory should include:

  • Computers, mobile devices and servers
  • Business applications
  • Cloud platforms
  • Email and collaboration tools
  • Network equipment
  • Administrative accounts
  • Customer and employee information
  • Backups
  • Vendor integrations
  • Internet-facing systems

The inventory should also identify which systems are most important to daily operations.

For example, losing access to an old file archive may be inconvenient. Losing access to email, financial systems, production software or customer records could interrupt the entire business.


The leadership question: Do we know what we have, where our sensitive information resides and which systems must remain available?



2. Is multifactor authentication required everywhere it should be?

Passwords alone are no longer enough to protect important business accounts.

Multifactor authentication adds another verification step when someone attempts to sign in. CISA recommends using phishing-resistant MFA when available, particularly for administrative access and other high-value accounts.

MFA should be reviewed for:

  • Email
  • Remote access
  • Administrative accounts
  • Financial applications
  • Cloud platforms
  • Customer-management systems
  • Password managers
  • Backup platforms
  • Cybersecurity tools
  • Vendor portals

Leadership should also understand which type of MFA is being used. Some methods provide stronger protection than simple text-message codes or repeated push notifications.


The leadership question: Which important accounts still rely on a password alone, and what is the plan for protecting them?



3. Are security updates installed, and is anyone verifying them?

Many businesses enable automatic updates and assume the problem is solved.

Automatic updates are useful, but updates can fail. Devices can remain offline. Applications may require manual intervention. Older systems may no longer receive security patches at all.

CISA lists software updates as one of its foundational recommendations for small and medium-sized businesses. Verizon’s 2026 Data Breach Investigations Report also found that vulnerability exploitation has become a major initial entry point for breaches.

A reliable update process should identify:

  • Which systems require updates
  • Which vulnerabilities are most urgent
  • Who owns remediation
  • Whether installation was successful
  • Which systems cannot be updated
  • What temporary protections are needed when a patch is unavailable


The leadership question: Can we prove that critical vulnerabilities are being identified, prioritized and corrected?



4. Can we restore the business from our backups?

Having backup software does not automatically mean a business can recover.

Backups can fail, become corrupted or remain connected to the same environment affected by an attack. A backup may also exclude a cloud application, database or configuration the organization needs to resume operations.

This matters because ransomware remains a widespread business risk. Verizon reports that ransomware is involved in 48% of breaches in its 2026 dataset.

A recovery strategy should define:

  • Which systems must be restored first
  • How much data the organization can afford to lose
  • How long systems can remain unavailable
  • Where backups are stored
  • Whether backups are isolated from the main environment
  • Who is responsible for restoration
  • When the last complete recovery test occurred

CISA’s ransomware guidance recommends planning for both prevention and response, including measures that reduce the operational impact of an incident.


The leadership question: When did we last perform a complete restoration test, and what did we learn?



5. How are employees expected to verify unusual requests?

Employees are often told to look for spelling mistakes, strange formatting and suspicious email addresses.

Those warning signs still matter, but modern phishing can be professionally written, accurately branded and delivered through a compromised account or legitimate online service.

Microsoft detected a sharp increase in QR-code phishing during the first quarter of 2026, with volume rising from 7.6 million attacks in January to 18.7 million in March. These campaigns often move targets from protected computers onto mobile devices where links and destinations are harder to inspect.

Employees need a clear verification process for requests involving:

  • Payments
  • Banking changes
  • Passwords
  • Authentication codes
  • Sensitive documents
  • Payroll information
  • Gift cards
  • New vendor instructions
  • Unusual downloads
  • Unexpected QR codes

The strongest defense is often a second communication channel. An employee can call a known telephone number, begin a new message to a trusted contact or ask a supervisor before acting.


The leadership question: Do employees know exactly how to verify a sensitive or unusual request?



6. Who has administrative access?

Administrative accounts can make major changes to systems, users and data.

That makes them useful for legitimate work and valuable to attackers.

Administrative access should be limited to people who genuinely need it. Employees should not use elevated privileges for routine activities such as reading email or browsing the internet.

Leadership should know:

  • How many administrative accounts exist
  • Who uses them
  • Why each account is required
  • Whether MFA is enabled
  • Whether administrative activity is logged
  • How access is removed
  • Whether vendors have privileged access
  • Whether shared administrator accounts exist


The leadership question: Could we produce an accurate list of everyone with elevated access today?



7. Which vendors can access our systems or information?

Most businesses depend on outside providers.

Software companies, consultants, accountants, payroll providers, equipment vendors and IT partners may all have access to company systems or information.

That access should have:

  • A documented business purpose
  • An internal owner
  • Appropriate security requirements
  • Limited permissions
  • MFA
  • Activity logging when possible
  • A review date
  • A removal process

Vendor access should not remain active indefinitely simply because no one remembered to disable it.

The same scrutiny should apply to software integrations. An application connected years ago may still be able to read files, access mailboxes or interact with customer data.


The leadership question: Which external organizations can access our environment, and when was that access last reviewed?



8. How quickly would we know something was wrong?

Prevention is important, but no organization can guarantee that every attack will be blocked.

Businesses also need the ability to detect suspicious behavior.

That may include monitoring for:

  • Unusual sign-in locations
  • Repeated failed logins
  • New administrative accounts
  • Unexpected forwarding rules
  • Disabled security tools
  • Large file transfers
  • Unusual remote access
  • Changes to backup settings
  • Suspicious inbox activity
  • Connections to known malicious destinations

Detection only creates value when alerts reach someone who can investigate and respond.


The leadership question: Who receives security alerts, and what happens after an alert is generated?



9. Do we have a practiced incident-response plan?

A written incident-response plan is useful.

A practiced plan is much better.

During an actual cyber incident, leaders may need to make decisions involving operations, customers, employees, legal obligations, insurance coverage, public communication and law enforcement.

The plan should identify:

  • Who declares an incident
  • Who leads the response
  • How affected systems are isolated
  • How the organization communicates when email is unavailable
  • When legal counsel is contacted
  • When the cyber-insurance provider is notified
  • Who communicates with customers
  • How evidence is preserved
  • How recovery priorities are determined

A tabletop exercise allows the team to test those decisions without waiting for a real emergency.


The leadership question: Has our leadership team practiced what it would do during the first hour of an incident?



10. Who is accountable for cybersecurity?

Cybersecurity frequently falls into a gap between departments.

Leadership assumes IT owns it. IT assumes executives have accepted certain risks. Human resources handles training. Finance manages insurance. Department leaders add new software. Vendors manage portions of the environment.

Everyone plays a role, but unclear ownership creates risk.

NIST added Govern as a core function of the Cybersecurity Framework 2.0, emphasizing that organizations should establish cybersecurity policies, responsibilities, oversight and risk-management priorities.

Accountability should include:

  • Executive oversight
  • Defined technical responsibilities
  • Documented policies
  • Regular risk reviews
  • Measurable improvement goals
  • Budget planning
  • Vendor accountability
  • Reporting to leadership

The purpose is not to make one person responsible for every task. It is to ensure every important task has an owner.

The leadership question: Who is responsible for cybersecurity outcomes, and how does leadership know whether the program is improving?

Strong cybersecurity begins with clear answers

Business leaders do not need to understand every technical configuration.

They should understand the organization’s risks, priorities, responsibilities and ability to recover.


The most concerning answer to any of these questions is not always “no.”

Sometimes, it is:

  • “We think so.”
  • “Our vendor probably handles that.”
  • “We have never tested it.”
  • “That is an IT question.”
  • “I am not sure who owns it.”

Those answers reveal where the organization needs greater visibility and accountability.


Turn these questions into an actionable plan


ValorTech helps businesses understand their technology environment, identify cybersecurity gaps and develop practical plans for reducing risk.

Whether your organization needs stronger identity protection, tested backups, security monitoring, employee education or a broader cybersecurity strategy, the first step is knowing where you stand today.


How many of these ten questions could your organization answer with confidence?


Talk with ValorTech about building a more secure and resilient technology environment.

Stay Ahead with Our Expert Insights
Get the latest IT security strategies, business tips, and tech updates — straight to your inbox.

Related Articles

  • What the 2026 Verizon DBIR Means for Small and Mid-Sized BusinessesThe 2026 Verizon DBIR reveals rising vulnerability exploitation, ransomware and mobile attacks. Learn five actions businesses should take now.
  • The $112,000 Email: How AI Is Making Invoice Fraud Harder to Spot AI is making invoice fraud and business email compromise harder to spot. Learn how businesses can reduce risk with email security, MFA, payment verification, and proactive IT support.
  • How to Make Grandma's "Weird Chip Dip" (As Heard on Bob & Brian)Get the 7-generation recipe for Grandma's Weird Chip Dip, as heard on The Hog with ValorTech CEO Bryan Sevener. Perfect for your 4th of July cookout!

Powered By

ValorTech Logo
(414) 410-9440

N85W16186 Appleton Ave
Menomonee Falls, WI 53051

Follow Our Social Media

Solutions

HealthcareLegalInsuranceFinanceManufacturingEducation/NPOGovernment

Services

CybersecurityManaged IT ServicesIT ConsultingCloud SolutionsApple First EnvironmentsMicrosoft 365

Service Areas

IT Support in WisconsinCloud Solutions in Wisconsin

Resources

BlogDownloadable AssetsTrust Center

Partners

Partners

Company

About ValorTech
Our Leadership
Culture & Values
News & Media
Social Impact
Careers

Partners

Partners

Contact Us

Consult with an ExpertCurrent Client Support

Contact Us

Consult with an ExpertCurrent Client Support

ValorTech Insights

Get the latest IT security strategies, business tips, and tech updates—straight to your inbox.

© 2026 All Rights Reserved

Privacy PolicyTerms of Service