10 Questions Every Mid-Sized Organization Should Ask About Its Cybersecurity Program

October is Cybersecurity Awareness Month.

For organizations with 25 to 1,000 users, that’s a good reason to talk about cybersecurity.

But here’s the thing.

Cybersecurity can’t be something we think about for only 31 days.

I was talking with a organization executive once when she asked me:

“Brett, how do I know if we’re doing enough?”

That’s probably one of the hardest cybersecurity questions a CEO, COO, or board member can ask.

There is always another security product.

Another threat.

Another headline.

Another acronym.

And if you’re not a cybersecurity professional, it can be difficult to know what really matters.

So I gave her a different way to think about it.

You don’t need to know everything about cybersecurity.

You need to know which questions to ask.

That’s what I’d encourage every organization leadership team to do during Cybersecurity Awareness Month.

Get your CEO, operations leadership, IT team, compliance team, and technology partner around the table and work through these 10 questions.

1. What Are Our Three Biggest Cybersecurity Risks Right Now?

Notice I didn’t ask for a list of every vulnerability.

Ask for three.

Maybe it’s phishing.

Maybe it’s aging infrastructure.

Maybe it’s a third-party vendor.

Maybe it’s Microsoft 365 security.

Maybe it’s employees using unapproved AI tools.

The important thing is that leadership understands the biggest risks and what the organization is doing about them.

If your cybersecurity team can’t explain those risks in plain English, keep asking questions.

2. Is Multi-Factor Authentication Protecting the Accounts That Matter?

Passwords aren’t enough anymore.

Multi-factor authentication adds another barrier when someone tries to access an account with stolen credentials.

But don’t simply ask:

“Do we have MFA?”

Ask:

“Where is MFA being used—and where isn’t it?”

Review employee accounts, Microsoft 365, administrative accounts, remote access, critical applications, and vendor access.

One overlooked privileged account can create significant risk.

3. How Are We Protecting Microsoft 365?

For many mid-sized organizations, Microsoft 365 has become part of the daily operating environment.

Email.

Teams.

SharePoint.

OneDrive.

Employee identities.

That’s why Microsoft 365 security deserves more attention than simply asking whether email is working.

Leadership should understand how accounts are protected, how suspicious activity is monitored, who has administrative privileges, how external sharing is controlled, and what happens when an employee leaves.

Microsoft provides security capabilities.

Your organization still has to configure, monitor, and manage them appropriately.

4. Could Our Employees Recognize a Phishing Attack?

You can buy a lot of cybersecurity technology.

Attackers know that.

So sometimes they don’t attack the technology.

They attack the person using it.

An employee receives an urgent message.

“I need this wire processed immediately.”

Or:

“Your Microsoft password expires today. Click here.”

One click can become a serious problem.

Security awareness training shouldn’t be a once-a-year exercise employees rush through.

Teach people what suspicious activity looks like, how to report it, and—most importantly—make them comfortable asking for help.

5. When Did We Last Prove We Could Recover From an Attack?

I’ve said this before, and I’ll keep saying it:

A backup is not the same thing as recovery.

Your dashboard may say the backups completed successfully last night.

Good.

Now ask:

When did we last restore something?

When did we test recovery of a critical system?

How long did it take?

Which systems would come back first?

What would happen if ransomware affected our primary environment?

Cybersecurity isn’t only about keeping attackers out.

It’s also about making sure the organization can continue operating when something goes wrong.

6. Do We Know Who Has Access to Our Systems?

Access tends to accumulate.

Someone changes departments but keeps old permissions.

A vendor receives administrative access for a project.

An employee leaves.

A temporary account becomes permanent.

Over time, environments get messy.

Cybersecurity Awareness Month is a great time to ask:

Who has administrative access?

Which vendors can access our environment?

Are former employees fully removed?

Do employees have more access than their jobs require?

Good cybersecurity includes controlling who can get through the door.

7. Are Our Technology Vendors Part of Our Cybersecurity Program?

Mid-sized organizations depend on outside providers.

ERP and line-of-business platforms.

Cloud companies.

Software and platform partners.

Microsoft.

Internet providers.

Managed technology providers.

Cybersecurity companies.

Those relationships can improve your organization tremendously.

They can also introduce risk.

Ask which vendors have access to sensitive information or critical systems.

Understand how those vendors are evaluated.

And make sure someone inside the organization owns each important relationship.

You can outsource technology services.

You can’t outsource responsibility for understanding the risk.

8. What Would Happen During the First 24 Hours of a Cyberattack?

Imagine it’s 8:15 Monday morning.

Several employees can’t access files.

Your technology team believes you’re dealing with ransomware.

What happens next?

Who gets called?

Who leads the response?

Who contacts your insurance resources?

When do legal and compliance professionals become involved?

How will employees communicate if normal systems aren’t available?

Who communicates with the board?

If nobody knows, that’s something to fix before the emergency.

An incident response plan should be written, accessible, understood, and practiced.

9. Are Employees Using AI Safely?

This question probably wasn’t on many cybersecurity checklists a few years ago.

It should be now.

Employees may already be experimenting with generative AI tools to write emails, summarize documents, research questions, or improve productivity.

The technology can be incredibly useful.

But employees need guidance about what information can—and cannot—be entered into an AI system.

I like a simple framework:

STOP Before You Put Information Into AI

S — Sensitive: Does this contain customer, employee, or confidential information?

T — Tool: Is this AI tool approved by the organization?

O — Ownership: Do we understand how the information may be handled?

P — Pause: If you’re uncertain, stop and ask before entering it.

AI isn’t something mid-sized organizations should simply fear.

But it does need governance.

10. When Did Leadership Last Review the Cybersecurity Strategy?

This may be the most important question.

Not:

“When did IT install the latest security update?”

Ask:

“When did leadership last sit down and review cybersecurity as a business risk?”

Cybersecurity should be part of your annual technology strategy meeting and your quarterly technology reviews.

Discuss:

Current risks

Security improvements

Incidents

Employee training

Business continuity

Vendor risk

Cyber insurance

AI

Upcoming investments

Your board doesn’t need to become a cybersecurity department.

But leadership does need visibility.

Don’t Let Cybersecurity Awareness Month Become a Checkbox

October will end.

The cybersecurity risks won’t.

So don’t measure the success of Cybersecurity Awareness Month by how many training emails you send.

Use the month to start conversations that continue throughout the year.

Pick three cybersecurity improvements.

Give each one an owner.

Set a target date.

Review progress in 90 days.

That’s how awareness becomes action.

Final Thoughts

After more than 26 years working in technology, I’ve learned that cybersecurity confidence doesn’t come from knowing every technical detail.

It comes from knowing your organization is asking the right questions.

Do we understand our biggest risks?

Are identities protected?

Are employees prepared?

Can we recover?

Do we understand our vendors?

Do we have a response plan?

Are we using AI responsibly?

And are we getting better?

You don’t have to solve every cybersecurity problem during Cybersecurity Awareness Month.

Start with the next three things that will make your organization safer.

Then keep going.

Because ultimately, cybersecurity isn’t about firewalls, passwords, or software.

It’s about protecting something much more important.

Trust.

The trust your employees place in your systems.

The trust your board places in leadership.

And most importantly, the trust your customers place in your organization every single day.

Turn Cybersecurity Awareness Into a 12-Month Plan

Cybersecurity Awareness Month is a great time to ask questions.

At CTG, we help mid-sized organizations turn the answers into a practical technology and cybersecurity roadmap.

We can help your leadership team review cybersecurity risk, Microsoft 365 security, identity and access, ransomware recovery, business continuity, incident response, vendor risk, AI readiness, infrastructure, and long-term technology strategy.

For more than 26 years, CTG has helped organizations make technology decisions with confidence, backed by a team with more than 200 years of combined experience.

And because we’re vendor-agnostic, we start with your organization’s risks and goals—not with a product we’re trying to sell.

Talk with Brett Harney at Corporate Technologies Group

Phone: 330-655-8144
Email: brett.harney@ctgusa.net
Website: ctgusa.net

This Cybersecurity Awareness Month, don’t just ask whether your organization is secure.

Ask where you can become stronger—and let’s build the plan to get there.


Share:

Recent Blog Posts...