Skip to content
Question Vault?
Free to readNo accountNo email wallNo invented statisticsNo ads on medical, legal or end-of-life pagesCopy or print any set and take it with you
06 · Learning & Knowledge-Based

Questions to Ask Cyber Security Expert

Questions for a small business owner, office manager or team lead sitting down with a security consultant. They are aimed at getting a short list of things to fix in priority order, a plan for the first hour of an incident, and an honest view of what you can do yourselves.

20 questions · each with a note on why · conversation guide

The questions

Open any question for the note

  1. If you only had a week and a small budget here, what would you change first?

    Why ask it

    Forcing a constraint produces a ranked answer instead of a full framework, and it shows whether the person can triage. Consultants who cannot start anywhere without a full audit tend to produce long reports and few completed changes.

  2. What is the most likely way an organisation like ours actually gets compromised?

    Why ask it

    You want the boring, common route rather than the interesting one, because that is where your money should go. An answer built around stolen credentials, invoice fraud and unpatched remote access is a sign of someone who works with real incidents rather than headlines.

  3. If you were trying to get into our systems, how would you do it?

    Why ask it

    This turns an abstract discussion into a specific path through your own organisation, usually involving a named service or a particular person's inbox. Note whether they start with technology or with people, since the second is where most successful attacks begin.

  4. Which of our accounts would an attacker go for first, and why?

    Why ask it

    The answer is often not the chief executive but whoever can approve payments, reset passwords or access the customer database. Identifying those few accounts is what makes stronger controls affordable, because you protect ten accounts properly rather than a hundred loosely.

  5. Where is our data actually stored, and who has access to each place?

    Why ask it

    Most organisations discover files in personal drives, old file shares and a departed employee's cloud account. Asking for the inventory is unglamorous and tends to surface the largest single risk in the room.

  6. Which forms of multi-factor authentication do you consider strong enough, and which do you not?

    Why ask it

    The forms are not equivalent: codes sent by text can be intercepted or redirected, app-based codes are stronger, and hardware keys are stronger again. A consultant who treats all of them as one box to tick has not dealt with an account takeover.

  7. What stops one compromised email account from turning into a fraudulent payment?

    Why ask it

    This is the most common expensive incident for small organisations, and the defences are mostly procedural: verified changes to bank details, a second approver, calling a known number. If the answer is only technical, the gap is in your process rather than your software.

  8. What happens to us tomorrow if everything is encrypted tonight?

    Why ask it

    Asking for the practical consequence forces a walk through payroll, orders, customer contact and records, which is where the real dependencies appear. It also reveals whether anyone has ever thought about how the business would operate on paper for a week.

  9. Have our backups ever actually been restored, and how would we test that?

    Why ask it

    A backup that has never been restored is an assumption, not a safeguard, and it is common to find them incomplete or reachable from the same compromised network. Ask specifically whether a copy is kept offline or cannot be altered, and when the last successful restore was.

  10. How would we know if someone were already inside?

    Why ask it

    Intrusions are frequently found weeks later, and often by a third party rather than the organisation itself. You are listening for what is being logged, who looks at it and how often, because monitoring nobody reads is the same as no monitoring.

  11. Who do we call in the first hour of an incident, and in what order?

    Why ask it

    This should be a written list of names and numbers, including someone technical, your insurer, and whoever can authorise taking systems offline. If it does not exist, producing it is the cheapest useful thing to come out of the conversation.

  12. What are we required to tell customers or regulators, and how quickly?

    Why ask it

    Notification duties depend on where you operate, what sector you are in and what data is involved, so you need this checked against your own circumstances rather than assumed. Ask who would draft the notice, because the drafting is slower than people expect while the clock is running.

  13. Which of our suppliers could hurt us most if they were breached?

    Why ask it

    Payroll providers, accountants, booking systems and IT support often hold more of your data or access than anyone internally. Ranking them shows where to ask questions and where a contract clause about notification would be worth having.

  14. What do we do about accounts belonging to people who have left?

    Why ask it

    Dormant accounts with valid passwords are a standard route in, and small organisations rarely have a reliable removal process. Ask for the leaver checklist, and ask who is responsible for running it, since this fails when it belongs to nobody.

  15. How should we handle staff using their own phones and laptops?

    Why ask it

    There is a real trade-off here between control and cost, and the honest answers range from full device management to simply keeping company data out of personal storage. Beware advice that assumes an enterprise budget you do not have.

  16. Which security training changes behaviour, and which just produces a certificate?

    Why ask it

    Annual modules are widely completed and rarely remembered, while short, specific drills about invoice changes and password prompts tend to stick. A consultant who distinguishes between them is thinking about outcomes rather than compliance paperwork.

  17. Looking at what we already pay for, what should we stop?

    Why ask it

    Small organisations often carry overlapping tools bought after previous scares, none fully configured. A consultant willing to recommend cancelling something is more credible than one who only adds, particularly if they would earn nothing from the removal.

  18. How much of this can we run ourselves, and what genuinely needs a specialist?

    Why ask it

    The dividing line matters for cost and for whether the work survives after the engagement ends. Be wary of an answer that puts everything on one side or the other, since routine hygiene is usually internal and detection and response usually are not.

  19. What surprised you at the last organisation like ours?

    Why ask it

    This gets you a real story rather than a category, and the surprise is often something mundane such as a shared administrator password or a server nobody knew was still running. It is also a fair test of how much comparable work they have actually done.

  20. What are you seeing at the moment that published guidance has not caught up with?

    Why ask it

    Kept for last, this invites them to speak from current experience rather than from a checklist. A specific answer with a caveat about uncertainty is a good sign; a confident sweeping prediction usually means you are being sold something.

How to use these questions

Practical guidance for the conversation itself

Getting a useful answer

Describe your organisation before you ask anything

Headcount, what systems you rely on, whether you take card payments, whether you hold health or financial data, and who currently looks after IT. Without that, the advice you get will be generic, and generic security advice is where most of the wasted spending comes from.

Ask for findings in priority order with effort attached

A list of thirty issues is not a plan. Ask for the top five with an estimate of cost and time for each, and ask which single one they would do if you could only do one.

Insist on plain language

If you cannot explain a recommendation to a colleague in two sentences, you will not be able to get it approved or maintained. Ask for the reason behind each item, not just the item.

Agree what finished looks like

Security work drifts without a defined end point. For each action, write down who does it, by when, and how you will verify it was done, then check the list again in a month.

What the answers tend to reveal

  • Whether they ask about your business before recommending anything. A consultant who starts with products has not started with your risk.
  • Whether their advice includes process changes and not only purchases. Payment verification and leaver checklists cost nothing and prevent common losses.
  • How they talk about the people who make mistakes. Contempt for users tends to produce controls that get bypassed.
  • Whether they will tell you something is good enough. An expert who finds every part of your setup unacceptable is either right or selling, and it is worth getting a second view.
  • Whether they mention testing restores, not just taking backups. It is the clearest single indicator of practical experience.

Common pitfalls

Buying from fear

Alarming statistics and worst-case stories are effective sales technique and poor prioritisation. Ask what the most likely loss is for an organisation your size, and spend against that rather than against the most dramatic scenario.

Treating a certificate as security

Passing an audit or holding a standard demonstrates that a process exists on a given date. It is useful for winning contracts and it is not the same as being difficult to attack, and the two budgets should be discussed separately.

Leaving the plan with the consultant

Whatever you agree needs an internal owner, even a part-time one. Recommendations that depend entirely on an outside party stop happening when the invoice ends.

Not asking about conflicts of interest

Many consultants resell the products they recommend, which is not automatically wrong but is worth knowing. Ask directly whether they earn anything from the tools on their list.

Follow-ups worth keeping ready

  • "What would that cost us, including the time from our side?" Internal effort is the cost most often left out of a quote.
  • "Who owns that once you have left?" Exposes recommendations that quietly depend on the consultant staying.
  • "What breaks for staff if we do that?" Controls that make ordinary work difficult are the ones people work around.
  • "How would we check in six months that it is still working?" Turns a one-off fix into something you can verify.