The Top 7 IT Questions
CEOs Should Be Asking
There is a lot to worry about when you’re a CEO. Typically, IT isn’t at the top of the list. There are other things that demand focus and should take priority like growth and culture. However, the best executives recognize that IT can have a huge impact on the bottom line. Here are the top 7 IT questions CEOs should be asking.
These questions will help you to identify and quantify risk to your organization. Understand the potential impact IT can have on operations. They will also help you get closer to understanding the costs of an outage. Raise awareness of current protections against cybersecurity threats. Help you learn how IT impacts culture. Finally, they can open conversations with your team that will allow you to quickly gauge where you’re at, and what actions to take.
What is the financial impact of downtime?
This question seems straightforward but is a little more involved to answer than you think. Assume you have a 10-million-dollar company. You have a server outage, or a cybersecurity incident that shuts down your entire network. You’re down for an entire workday. What does it cost you?
Just over $6,000/hour in lost productivity and revenue
How quickly could we recover from an outage?
Now that we have an idea of what downtime costs the company the next obvious question is how quickly can we recover? The answer will vary depending on what has caused the outage, and the disaster recovery solutions you currently have in place.
Asking your IT team this question will illuminate your risk as a company. If you don’t have a good backup solution, an outage could cause downtime for days or weeks. The general rule with disaster recovery is that the less downtime you want the more costly the solution typically is.
Where is our Data?
Covid has really complicated the answer to this question. Many companies had to quickly pivot their operational models when we were forced to work from home. This caused users to take matters into their own hands, and data suddenly got sucked up into a plethora of different cloud file sharing applications.
The problem with this type of shadow IT is that your IT team doesn’t know where your users are putting data. As a result, they are not able to secure or backup that data. We can’t protect what we don’t know exists.
Do we have a solution to protect against common cybersecurity threats?
There are a LOT of potential cybersecurity threats out there. However, in 2024 there are 3 that stand out as the most common. Having protections against these 3 threats will go a long way to secure your data.
Ransomware
Ransomware encrypts your data and demands payment for its return. This attack can be devastating to a business, frequently taking days or weeks to recover from.
BEC Attacks
Business Email Compromise attacks have edged out ransomware as the most common threat. Bad actors gain access to company email and intercept financial transactions.
Network Intrusion
With work from home, the most common attack is using password crackers to gain VPN access that isn’t secured with multifactor authentication.
Where do we have technical debt as an organization?
Technical debt can come in many forms. Legacy applications, operating systems, or end of life hardware can all add to your risk. Southwest airlines had a recent outage because of outdated technology that cost them an estimated $825 million.
Technical debt operates like compounding interest in a bad way. The farther behind your technology gets, the more complicated and expensive it is to move to a current solution.
How does our staff feel about IT?
This isn’t a technical question. However, CEOs should be focused on company culture and your employees’ experience with IT affects that. Any time your employee feels there isn’t a path to get their problems solved, it’s frustrating.
The CEO’s experience with IT is typically NOT representative. You get the best hardware and quickest response. If you want a real gauge, talk to your front-line workers.
Do you have adequate cybersecurity insurance coverage?
No matter what solutions you have in place for IT and cybersecurity, risk will always exist. To further protect your business, you’ll want to seek out appropriate insurance coverage to mitigate it.
Talk to an insurance professional that knows cyber. Ask them about various scenarios and whether you would be covered or not.
Three areas where companies are frequently not covered:
- Pre-existing vulnerabilities
- Human Error
- Insider Attacks
Conclusion
CEOs have a lot to think about. IT isn’t normally on the top of the list. If you take the time to ask these 7 questions to your IT team, the resulting conversations will be valuable to you and help you reduce your risk as a company.
You may also find out that things aren’t currently where you want them to be, and gaps exist in your current solution. Once you identify them you can start making things better.
Ready to Assess Your IT Infrastructure?
If you find yourself wanting to consult with an expert, we are happy to help. Book time to chat with us and discuss your specific IT challenges.
Book Time to Chat with Us HERE