Skip to content
Question Vault?
Free to readNo accountNo email wallNo invented statisticsNo ads on medical, legal or end-of-life pagesCopy or print any set and take it with you
08 · Meta & Technology

Cyber Security Questions to Ask

For small business owners and anyone responsible for a small team's systems. These are questions to put to an IT provider, an internal IT lead, or yourself, and the answers are checkable: where multi-factor authentication is missing, who holds administrator accounts, when a backup was last restored, what happens after a stolen laptop or a changed invoice, and who has to be told when data leaks.

20 questions · each with a note on why · conversation guide

The questions

Open any question for the note

  1. What would happen to us if my email account was taken over tomorrow morning?

    Why ask it

    Email is the master key, because password resets for almost everything else arrive there. A good answer traces what an attacker reaches from the inbox alone: banking, cloud storage, the domain registrar, payroll. Anyone treating email as a low-risk system has the order of priorities backwards.

  2. Where is multi-factor authentication turned on, and where is it still missing?

    Why ask it

    The second half of the question is the useful half. Gaps cluster in the awkward places: shared mailboxes, the finance portal, the domain registrar, remote access, service accounts. Ask which factor too, since app codes and hardware keys resist phishing far better than text messages.

  3. Which of our accounts can reset everyone else's password?

    Why ask it

    Every setup has a few accounts that control the rest, typically the email tenant administrator, the domain registrar and the password manager. If nobody can list them without going away to check, nobody is watching the accounts that matter most.

  4. If someone left today, how long would their access last?

    Why ask it

    Leavers are where small organisations quietly leak. A confident answer describes a checklist and a same-day deadline. A vague one usually means former staff still have mail on a phone, and a shared password nobody has changed since they walked out.

  5. What backups do we have, and when did anyone last restore one?

    Why ask it

    A backup that has never been restored is a hope, not a backup. Ask for the date of the last test restore, whether one copy is offline or otherwise unchangeable, and how long a full restore takes, because ransomware deliberately goes after backups it can reach.

  6. Which of our systems are no longer getting security updates?

    Why ask it

    Unsupported software is the quiet risk: an old server, a network appliance nobody logs into, phones that stopped receiving updates two years ago. A straight answer comes with end-of-support dates and a replacement plan rather than reassurance.

  7. Who has administrator rights on the laptops, and does that include everyday users?

    Why ask it

    Day-to-day accounts with administrator rights turn one bad click into an installation. A good answer separates admin credentials from normal use. If everyone is an administrator because it saves time, that was a decision, not a technical necessity.

  8. What happens if a laptop is stolen from a car this afternoon?

    Why ask it

    This tests encryption and remote wipe in practice rather than in a policy document. You want three things confirmed: the disk is encrypted, a wipe can actually be triggered, and nothing important exists only on that machine.

  9. What would a phishing email that fooled us actually look like?

    Why ask it

    Advice about spelling mistakes and odd greetings is out of date, because convincing messages now arrive from genuinely compromised accounts and reference real invoices and real projects. A good answer sketches a scenario aimed at your business specifically.

  10. If somebody rang the office pretending to be me, how would we check?

    Why ask it

    Voice and video are cheap to fake now, so this asks for a habit rather than for vigilance. Look for a specific out-of-band step: a callback to a number already on file, a phrase agreed in advance, a second approver for anything involving money.

  11. What do we do when an invoice arrives with changed bank details?

    Why ask it

    Redirected payments are among the most reliable frauds there is, and it usually looks like an ordinary email from a supplier you know. The answer needs to be a fixed rule: verify by phone on a number already held, never on the number in the message.

  12. Which outside companies can reach our data, and what can they see?

    Why ask it

    Third party access is the part nobody has mapped: the bookkeeper, the agency, an app somebody connected to the shared drive, an integration left over from a system you stopped using. Ask for the list, then ask when it was last reviewed.

  13. What are we paying for that we're not actually using?

    Why ask it

    Security spending accumulates without being revisited: licences bought for a threat that passed, an agent installed on two machines, two products doing one job. An honest adviser will name something to cancel. One who never does is selling.

  14. If we were hit by ransomware on a Friday afternoon, what happens in the first hour?

    Why ask it

    You are asking for a plan that has a first hour in it: who gets called, what is disconnected, who speaks to staff and customers, and whether the phone numbers exist anywhere other than the systems that are down. An answer that opens with restoring backups has skipped containment.

  15. Who do we have to notify if customer data leaks, and how fast?

    Why ask it

    Notification is a legal duty with short clocks. In the UK and EU, qualifying breaches must be reported to the regulator within 72 hours, and in the United States the requirements vary by state and by sector. What you need is who decides, who files, and where those contacts are written down.

  16. What does our insurance require us to be doing?

    Why ask it

    Cyber policies commonly require named controls, multi-factor authentication and working backups among them, and claims get contested when those were not in place. Read the conditions rather than the headline cover, and check the incident hotline is somewhere findable when systems are offline.

  17. What's the one thing you'd fix first if I gave you the budget today?

    Why ask it

    The prioritisation question. A useful answer names a single item with a cost and a reason, and it should sound dull: multi-factor everywhere, an offline backup, patching, removing admin rights. Anything that starts with a new product deserves a second look.

  18. What have you already told us to do that we haven't done?

    Why ask it

    The most productive question here, and slightly uncomfortable to ask. Providers usually keep a list of recommendations that were declined on cost or convenience, and that list belongs in front of whoever made the decision.

  19. How would we find out we'd been breached, and how long might that take?

    Why ask it

    Detection is where small organisations are weakest. Honest answers admit the news might arrive from a customer, a bank or a supplier rather than from monitoring, which tells you whether any logging and alerting exists at all.

  20. If you wanted to get into this business, where would you start?

    Why ask it

    Asked plainly, this gets you the real assessment. Expect an answer about people rather than technology: the finance inbox, a reused password, remote access left open for a supplier, the one person who approves payments alone. Inability to answer means nobody has thought about you as a target.

Turning the answers into work

Practical guidance for the conversation itself

If the list feels long, this is the order

  1. 1Multi-factor authentication on email, the domain registrar and anything financial. Cheap, quick, and it removes most opportunistic account takeover.
  2. 2A password manager for everyone, then stop reusing passwords across accounts. Reuse is what turns one unrelated breach into your problem.
  3. 3One backup copy that is offline or cannot be altered, and a restore test with a date written down next to it.
  4. 4Remove administrator rights from everyday accounts, including yours.
  5. 5Automatic updates on everything, and a list of what can no longer be updated so replacement can be budgeted.
  6. 6A written half-page for the bad day: who to call, what to disconnect, which numbers to use when email is unavailable.

Asking a provider when you can't check the answers yourself

  • Ask for it in writing. Answers that were confident on a call often soften in an email, and the softening is informative.
  • Ask for evidence rather than assurance: a screenshot of the multi-factor report, the date on the last restore test, a list of accounts with admin rights.
  • Ask what they would show an auditor or an insurer. It reframes the question from opinion to record.
  • Be wary of an answer that is entirely product names. Naming the tool is not the same as saying what it is configured to do.
  • Get a second opinion before a large purchase. An hour of independent advice is cheaper than a three-year contract for something you did not need.

What actually hits small organisations

  • Changed bank details on a real invoice. No malware involved, and the money leaves the same day.
  • Email account takeover, then quiet monitoring of the inbox until a payment conversation appears.
  • Ransomware arriving through remote access that was set up for convenience and never restricted.
  • A message that appears to come from the owner, sent while they are visibly travelling, asking for something urgent and unusual.
  • A permission granted to a plausible-looking app that keeps access to a mailbox long after the person forgets approving it.

If something has already happened

  1. 1Disconnect affected machines from the network, and leave them switched on. Powering down can destroy evidence.
  2. 2Change passwords from a device you know is clean, and revoke active sessions rather than only resetting passwords.
  3. 3Call the bank immediately if money moved. Speed matters more than certainty about what happened.
  4. 4Tell your insurer before you engage anyone to help. Policies often require approved responders, and unauthorised costs may not be covered.
  5. 5Preserve logs and messages, including the original phishing email with its headers. Do not delete it.
  6. 6Report it: the national reporting body in your country, and the police where money or personal data is involved.
  7. 7Notify the people whose data was exposed, within the deadline that applies to you, and say plainly what happened and what they should do.