Risk in Plain Language
Leadership LensPart 5 of 5

The Five Questions Every Leader Should Be Asking About Cyber Risk

You don't need to understand firewalls to make good decisions about cybersecurity. You need to ask the right questions — and know what a good answer looks like.

7 min read

There is a scene that plays out in organizations of every size, in board rooms and executive offices and nonprofit leadership team meetings: someone raises cybersecurity, and the people in the room with decision-making authority go quiet. Not because they don't care. Because they don't know what to say.

The conversation gets handed off to whoever is most technical, or it gets deferred to the next meeting, or it produces a general agreement that "we should do something about this" that never translates into a specific decision. The technical complexity of the subject has become a way of avoiding ownership of it.

Here is what I want to make clear: you do not need to understand the technical details of cybersecurity to be an effective leader on cyber risk. You need to ask good questions and recognize good answers. You need to make the decisions that belong to you and ensure that someone else is accountable for the ones that don't. That is leadership. It is exactly the same skill set you apply to financial risk, operational risk, and legal risk — all of which you engage with without being an accountant, an engineer, or an attorney.

"Boards think in terms of probability and financial impact. The job of security leadership is to speak that language. The job of executive leadership is to demand it."

What follows are five questions that belong in every executive and board conversation about cybersecurity. They are written for the non-technical leader. They are questions you can ask today, without preparation, that will immediately improve the quality of the security conversation in your organization.

1
Ask this first
If our most critical systems went down tomorrow, what would actually stop working — and for how long?

This is an operational continuity question, not a technical one. It forces a concrete answer about business impact rather than an abstract discussion about threat types or security tools.

A strong answer names specific systems, identifies which operations depend on each one, and gives you a realistic recovery time estimate based on actual tested procedures. A weak answer is vague ("we would have some disruption"), overly optimistic ("we could be back up in a few hours"), or defers to a technical team member who then also gives a vague answer.

The follow-up that reveals the most: "When did we last test that?" A backup or recovery plan that has never been tested is a hypothesis, not a capability. Organizations that tested their recovery procedures in advance of an incident consistently recover faster and cheaper than those that did not. The testing question separates preparedness from assumption.

Why this question matters
Half of all small businesses take 24 hours or longer to recover from a cyberattack. Downtime alone averages $53,000 per hour for businesses of all sizes. The answer to this question tells you whether your organization knows its own exposure — and whether anyone has actually checked.
2
Ask this about people
Who currently has access to our most sensitive data and systems — and does that still make sense?

This question surfaces one of the most common and most preventable sources of breach: access that was granted for a reason that no longer exists. Former employees whose accounts were never closed. Contractors given broad access for a short project who still have it years later. Shared passwords that nobody changed after the person who set them up left.

A strong answer demonstrates that someone has reviewed access levels recently, that there is a process for removing access when people leave or change roles, and that the organization applies the principle of least privilege — people and systems have access to exactly what they need, and not more. A weak answer is not knowing who has access, or acknowledging that nobody has reviewed it recently.

For nonprofits, this question has an additional dimension: volunteers. Many nonprofits give volunteers access to CRM systems, email lists, donor records, and financial platforms out of operational necessity. Few have a process for reviewing or revoking that access as volunteers rotate in and out. Each former volunteer with an active login is a door that remains unlocked.

Why this question matters
Identity-based attacks — where an attacker uses legitimate credentials to access systems — are now the leading cause of breaches across every sector. Most of those credentials are not stolen through sophisticated hacking. They are obtained because organizations accumulate access over time and never clean it up.
3
Ask this about money
What is our actual financial exposure if something goes wrong — and does our insurance actually cover it?

This is a risk quantification question. It forces the conversation out of the abstract ("cyber threats are increasing") and into the concrete ("here is what this could cost us specifically").

A strong answer gives you a realistic range for potential losses — including direct recovery costs, legal and notification obligations, operational downtime, and reputational impact on donor relationships or client trust — and then addresses how much of that exposure is covered by insurance and under what conditions. A weak answer assumes the insurance will cover it without having verified this, or cannot estimate the financial exposure at all.

The insurance follow-up is particularly important given what was covered in last week's post: nearly one in four cyber insurance claims in 2024 was denied. Many policies exclude or severely sublimit social engineering and business email compromise losses — the most common category of claim. A leader who has not read the policy cannot know what the organization is actually protected against.

For nonprofit boards, this question also connects to fiduciary responsibility. The board oversees organizational risk. A board that cannot answer this question is not exercising its oversight duty — regardless of how technically complex the underlying subject matter is.

Why this question matters
88% of executives say quantifying cyber risk is essential for prioritizing investments. Only 15% actually measure financial impact in a meaningful way. The gap between those two numbers is where bad decisions live — and it is a leadership gap, not a technical one.
4
Ask this about decisions
If we discovered a breach right now, who would make the call — and do they know that?

This is a decision rights question. It is not technical. It is a governance question that belongs squarely with leadership, and the answer to it determines whether your organization responds to an incident as a functional team or as a group of people looking at each other in a hallway waiting for someone else to go first.

A strong answer names a specific person with the authority to make decisions under pressure — including whether to disconnect systems, whether to engage outside counsel, whether to pay a ransom, and what to communicate to clients, donors, or partners before the full scope of an incident is known. A weak answer is "it depends" or "we would figure it out at the time."

The follow-up question is equally important: "Does that person know they have that authority, and have they thought about what they would do?" Decision-makers who encounter these questions for the first time during an active incident make worse decisions. Organizations that have named the decision-maker, thought through the scenarios in advance, and documented a basic response plan consistently handle incidents better than those that have not — regardless of the size of their security budget.

Why this question matters
The most expensive part of many incidents is not the attack itself — it is the delay between discovery and response. Every hour of confusion about who has authority is an hour the attacker may still be active in your systems, and an hour of mounting business impact that could have been contained.
5
Ask this about accountability
Who owns this — and how will I know if something changes?

This is the accountability question. For most small businesses and nonprofits, nobody has a dedicated security role. That is a resource reality, not a character flaw. But "nobody has this as a full-time job" does not mean nobody should own it. It means someone needs to carry the responsibility of keeping leadership informed, escalating when something requires a decision, and maintaining the basic hygiene that keeps the risk manageable.

A strong answer names a person — not a team, not "IT," not a vendor — who is accountable for tracking the organization's security posture and bringing relevant information to leadership on a regular basis. That person does not need to be technical. They need to be organized, to have the organizational standing to raise issues, and to understand their own limits well enough to know when to bring in outside expertise.

The follow-up that matters: "When will you next bring this to my attention?" Cybersecurity is not a project with a completion date. It is an ongoing condition that changes as the threat environment changes, as your organization's systems change, and as your staff changes. A leader who asks this question once and considers the matter handled is not exercising oversight. They are checking a box.

Why this question matters
The World Economic Forum's Global Cybersecurity Outlook found that 91% of business leaders believe a catastrophic cyber event is at least somewhat likely in the next two years. Less than a third report having a clear and up-to-date picture of their organization's security posture. The gap between believing risk is real and actually knowing your status is a leadership accountability gap.

What good answers actually sound like

Asking good questions is the first step. Recognizing a good answer is the second. There is a pattern to weak answers that every leader should be able to identify: they are vague, they defer to technical complexity, they reference tools or vendors rather than outcomes, or they conflate activity with results.

"We have a firewall" is not an answer to any of these five questions. Neither is "our IT vendor handles that." Neither is "we're working on it." Good answers are specific. They reference actual tested procedures, named accountable individuals, and concrete cost estimates. They say "we tested our backup recovery in March and it took four hours" rather than "we have backups." They say "our policy requires all vendor accounts to be reviewed quarterly and we last did this in February" rather than "we manage access carefully."

The test to apply: After receiving an answer, ask yourself — if something went wrong and I was later asked what I did to oversee this risk, could I describe a specific decision I made or a specific assurance I received? If the answer is no, the conversation is not finished.

What this series has covered

Over the past five weeks, this series has moved from the foundational argument for why organizations like yours face real cyber risk, through real-world incident examples, into practical action steps, through the myths that prevent action, and now to the leadership posture that sustains it. These are not five separate conversations. They are five parts of a single one.

The five-post series at a glance
  • Post 1 Risk in Plain Language: Cybersecurity isn't just a big-company problem — why small organizations and nonprofits face the same threats with fewer resources to absorb them.
  • Post 2 Real-World Stories: The email that cost everything — three documented business email compromise incidents and what would have stopped each one.
  • Post 3 Practical How-To: Where to start when you have no security team — five sequenced steps, most of them free, that close the gaps driving most attacks.
  • Post 4 Myths and Mistakes: Five widely held beliefs that are actively keeping nonprofits exposed — and what the evidence actually says about each one.
  • Post 5 Leadership Lens: The five questions every leader should be asking — and what good answers actually look like.

The through-line across all five posts is the same idea that sits at the center of what Defensible Cyber Risk does: security that serves your organization, not the other way around. Not enterprise complexity. Not checkbox compliance. Defensible decisions made with clear eyes about what matters and why.

The ask for this week: Take one of these five questions into your next leadership conversation. Not as a test, not as a challenge — as a genuine attempt to understand where your organization stands. The answer you get will tell you more than any security assessment summary.

Ready for a clearer picture of where you actually stand?

A 90-day or 30-day Security Business Review translates your organization's risk into clear, prioritized decisions leadership can act on. No enterprise complexity. No vendor lock-in. Just defensible outcomes.

Start a Conversation
Leadership Lens Board Governance Executive Communication Risk Management Decision Making vCISO