There is a scene that plays out in organizations of every size, in board rooms and executive offices and nonprofit leadership team meetings: someone raises cybersecurity, and the people in the room with decision-making authority go quiet. Not because they don't care. Because they don't know what to say.
The conversation gets handed off to whoever is most technical, or it gets deferred to the next meeting, or it produces a general agreement that "we should do something about this" that never translates into a specific decision. The technical complexity of the subject has become a way of avoiding ownership of it.
Here is what I want to make clear: you do not need to understand the technical details of cybersecurity to be an effective leader on cyber risk. You need to ask good questions and recognize good answers. You need to make the decisions that belong to you and ensure that someone else is accountable for the ones that don't. That is leadership. It is exactly the same skill set you apply to financial risk, operational risk, and legal risk — all of which you engage with without being an accountant, an engineer, or an attorney.
"Boards think in terms of probability and financial impact. The job of security leadership is to speak that language. The job of executive leadership is to demand it."
What follows are five questions that belong in every executive and board conversation about cybersecurity. They are written for the non-technical leader. They are questions you can ask today, without preparation, that will immediately improve the quality of the security conversation in your organization.
This is an operational continuity question, not a technical one. It forces a concrete answer about business impact rather than an abstract discussion about threat types or security tools.
A strong answer names specific systems, identifies which operations depend on each one, and gives you a realistic recovery time estimate based on actual tested procedures. A weak answer is vague ("we would have some disruption"), overly optimistic ("we could be back up in a few hours"), or defers to a technical team member who then also gives a vague answer.
The follow-up that reveals the most: "When did we last test that?" A backup or recovery plan that has never been tested is a hypothesis, not a capability. Organizations that tested their recovery procedures in advance of an incident consistently recover faster and cheaper than those that did not. The testing question separates preparedness from assumption.
This question surfaces one of the most common and most preventable sources of breach: access that was granted for a reason that no longer exists. Former employees whose accounts were never closed. Contractors given broad access for a short project who still have it years later. Shared passwords that nobody changed after the person who set them up left.
A strong answer demonstrates that someone has reviewed access levels recently, that there is a process for removing access when people leave or change roles, and that the organization applies the principle of least privilege — people and systems have access to exactly what they need, and not more. A weak answer is not knowing who has access, or acknowledging that nobody has reviewed it recently.
For nonprofits, this question has an additional dimension: volunteers. Many nonprofits give volunteers access to CRM systems, email lists, donor records, and financial platforms out of operational necessity. Few have a process for reviewing or revoking that access as volunteers rotate in and out. Each former volunteer with an active login is a door that remains unlocked.
This is a risk quantification question. It forces the conversation out of the abstract ("cyber threats are increasing") and into the concrete ("here is what this could cost us specifically").
A strong answer gives you a realistic range for potential losses — including direct recovery costs, legal and notification obligations, operational downtime, and reputational impact on donor relationships or client trust — and then addresses how much of that exposure is covered by insurance and under what conditions. A weak answer assumes the insurance will cover it without having verified this, or cannot estimate the financial exposure at all.
The insurance follow-up is particularly important given what was covered in last week's post: nearly one in four cyber insurance claims in 2024 was denied. Many policies exclude or severely sublimit social engineering and business email compromise losses — the most common category of claim. A leader who has not read the policy cannot know what the organization is actually protected against.
For nonprofit boards, this question also connects to fiduciary responsibility. The board oversees organizational risk. A board that cannot answer this question is not exercising its oversight duty — regardless of how technically complex the underlying subject matter is.
This is a decision rights question. It is not technical. It is a governance question that belongs squarely with leadership, and the answer to it determines whether your organization responds to an incident as a functional team or as a group of people looking at each other in a hallway waiting for someone else to go first.
A strong answer names a specific person with the authority to make decisions under pressure — including whether to disconnect systems, whether to engage outside counsel, whether to pay a ransom, and what to communicate to clients, donors, or partners before the full scope of an incident is known. A weak answer is "it depends" or "we would figure it out at the time."
The follow-up question is equally important: "Does that person know they have that authority, and have they thought about what they would do?" Decision-makers who encounter these questions for the first time during an active incident make worse decisions. Organizations that have named the decision-maker, thought through the scenarios in advance, and documented a basic response plan consistently handle incidents better than those that have not — regardless of the size of their security budget.
This is the accountability question. For most small businesses and nonprofits, nobody has a dedicated security role. That is a resource reality, not a character flaw. But "nobody has this as a full-time job" does not mean nobody should own it. It means someone needs to carry the responsibility of keeping leadership informed, escalating when something requires a decision, and maintaining the basic hygiene that keeps the risk manageable.
A strong answer names a person — not a team, not "IT," not a vendor — who is accountable for tracking the organization's security posture and bringing relevant information to leadership on a regular basis. That person does not need to be technical. They need to be organized, to have the organizational standing to raise issues, and to understand their own limits well enough to know when to bring in outside expertise.
The follow-up that matters: "When will you next bring this to my attention?" Cybersecurity is not a project with a completion date. It is an ongoing condition that changes as the threat environment changes, as your organization's systems change, and as your staff changes. A leader who asks this question once and considers the matter handled is not exercising oversight. They are checking a box.
What good answers actually sound like
Asking good questions is the first step. Recognizing a good answer is the second. There is a pattern to weak answers that every leader should be able to identify: they are vague, they defer to technical complexity, they reference tools or vendors rather than outcomes, or they conflate activity with results.
"We have a firewall" is not an answer to any of these five questions. Neither is "our IT vendor handles that." Neither is "we're working on it." Good answers are specific. They reference actual tested procedures, named accountable individuals, and concrete cost estimates. They say "we tested our backup recovery in March and it took four hours" rather than "we have backups." They say "our policy requires all vendor accounts to be reviewed quarterly and we last did this in February" rather than "we manage access carefully."
What this series has covered
Over the past five weeks, this series has moved from the foundational argument for why organizations like yours face real cyber risk, through real-world incident examples, into practical action steps, through the myths that prevent action, and now to the leadership posture that sustains it. These are not five separate conversations. They are five parts of a single one.
- Post 1 Risk in Plain Language: Cybersecurity isn't just a big-company problem — why small organizations and nonprofits face the same threats with fewer resources to absorb them.
- Post 2 Real-World Stories: The email that cost everything — three documented business email compromise incidents and what would have stopped each one.
- Post 3 Practical How-To: Where to start when you have no security team — five sequenced steps, most of them free, that close the gaps driving most attacks.
- Post 4 Myths and Mistakes: Five widely held beliefs that are actively keeping nonprofits exposed — and what the evidence actually says about each one.
- Post 5 Leadership Lens: The five questions every leader should be asking — and what good answers actually look like.
The through-line across all five posts is the same idea that sits at the center of what Defensible Cyber Risk does: security that serves your organization, not the other way around. Not enterprise complexity. Not checkbox compliance. Defensible decisions made with clear eyes about what matters and why.
Ready for a clearer picture of where you actually stand?
A 90-day or 30-day Security Business Review translates your organization's risk into clear, prioritized decisions leadership can act on. No enterprise complexity. No vendor lock-in. Just defensible outcomes.
Start a Conversation