Posted by Antonina McAvoy in Cybersecurity, Consulting, Risk Advisory, Business Risk, Artificial Intelligence.
Key topics covered in this article:
-
- Business interruption and recovery priorities that finance, operations, and IT should agree upon.
- AI use, payment verification, and vendor dependencies that warrant leadership visibility.
- Reporting unresolved risks, assigning accountability, and turning discussion into decisions.
Would your next leadership meeting reveal where the organization is exposed—or simply confirm that someone is handling cybersecurity? Make sure you get the answers you need to reduce your risk exposure, today.
A payment gets redirected. A critical vendor goes offline. An employee uploads confidential information into an AI tool. A new customer asks for evidence of security controls before signing a contract.
Each situation raises a business question: What could we lose, who is accountable, and how do we know our controls will hold?
Cybersecurity Awareness Month is an opportunity to move those questions onto the leadership agenda. As your organization plans budgets, evaluates vendors, and considers new technology, these five questions can help your board and executive teams identify where a deeper discussion is needed.
1. What could interrupt our business and how long could we tolerate it?
Start with the activities that keep the organization operating: collecting revenue, paying employees, delivering services, accessing customer records, or running production. Consider what happens if the systems supporting those activities become unavailable. A disruption at a payroll provider or cloud platform can affect operations even when your own systems remain accessible.
Ask management: “Which three business activities would cause the greatest harm if they stopped, and when did we last test our ability to restore them?”
Look for recovery priorities agreed upon by business leaders, realistic downtime expectations, maximum tolerable downtime acceptable, and documented test results. A successful backup job alone does not demonstrate that your organization can resume critical operations. Bring finance, operations, customer success, HR, and IT into the discussion together; they may have different assumptions about what needs to be recovered first.
2. Where is AI already being used and what can it access or do?
Begin with tools employees already use: meeting transcription, document summaries, browser assistants, or AI features embedded in existing software you purchased years ago. The questions become more consequential when AI can retrieve confidential records, change information, or initiate actions.
Ask management: “Can we identify our significant AI uses, the information involved, and who reviews the results before they affect a customer or business decision?”
Look for approved uses, clear data restrictions in contracts, accountable owners, and human review requirements proportionate to the risk. For tools that take action, ask who approves that authority and how your organization can stop or reverse an inappropriate action. The voluntary NIST AI Risk Management Framework provides a foundation for organizing these discussions. A policy is one part of the work; leadership also needs to understand actual use.
3. Would our payment controls hold up against a convincing request?
Consider an urgent message from an executive on your team, an email with updated banking instructions from a familiar vendor, or a request during a busy payment cycle. Does the process require independent verification when the request looks credible and the recipient feels pressure to act?
Ask management: “If a familiar vendor requested a bank-account change today, what would prevent us from sending money to the wrong account?”
Look for verification through a previously established contact method, separation between changing payment details and releasing funds, and retained evidence of approval. Ask whether the controls also apply to executive requests and exceptions. The FBI recommends using a secondary channel to verify changes in account information. This question connects cybersecurity with accounts payable, treasury, and business process controls.
4. Which outside organizations create our greatest exposure?
A new or existing vendor relationship can be important because it holds sensitive information, has privileged access, supports a critical service, or connects directly to your organization’s internal systems. Your leadership team should understand which relationships could create the greatest business impact.
Ask management: “Which vendors could materially disrupt operations or expose sensitive information, and what evidence supports our confidence in them?”
Look for reviews that consider the actual service, access, data, and business dependency. Where a SOC report is relevant, ask whether someone evaluated its scope, reporting period, exceptions, and the Complementary User Entity Controls (CUECs) your organization is expected to perform. Don’t create an avoidable gap by skipping the mapping exercise of mapping the CUECs listed in the vendor’s SOC report to your internal controls. Also ask how access is removed when the relationship ends and what happens if the provider becomes unavailable. The NIST Cybersecurity Supply Chain Risk Management Quick Start Guide is a resource to help strengthen evaluations of critical vendors and third-party relationships.
5 How do we know our cyber and fraud risks are decreasing and what requires a leadership decision?
Training completion reports, approved policies, and security dashboards can show that activities have occurred and safeguards are in place. They do not, by themselves, demonstrate that risk has decreased. Leadership needs evidence that those safeguards work in practice and that significant gaps are being resolved.
Ask management: “What are our three most significant unresolved cyber or fraud risks, what evidence shows progress since our last review, and what decisions do you need from us?”
Look for reporting that connects each significant risk to its business impact, an accountable owner, a corrective action, and a target date. Evidence of improvement could include a recovery test that meets business needs, verification that a payment-control weakness has been corrected, or confirmation that excessive vendor or AI access has been restricted.
Distinguish completed tasks from verified results. Closing a remediation ticket is meaningful when someone confirms that the underlying weakness has been addressed. Any remaining risk accepted by management should have a documented rationale, appropriate approval, and a date for reassessment.
NIST’s Enterprise Risk Management Quick-Start Guide explains how cybersecurity risk information can support broader enterprise risk management. Use leadership reporting to make clear which exposures need attention, which improvements are working, and where a decision is required.
Which question needs a clearer answer?
Bring one of these five questions to your next leadership meeting. Ask management to explain the business impact, provide evidence of how the risk is being managed, and identify any decision or support needed. If the answer is unclear, assign an owner, agree on what evidence is needed, and set a date when leadership will revisit it.
You don’t need to wait for an incident to have that conversation. PBMares’ Cyber & Risk Advisory team can help evaluate existing controls, identify gaps, and prioritize practical improvements. Contact your PBMares advisor or Partner Antonina McAvoy to discuss the question your leadership team needs help answering.
Be sure to consult with your financial or tax advisor on this topic as individual situations may vary. The information contained in this article or webinar, and any related materials, are for informational purposes only, and cannot be relied upon for legal, financial, tax, accounting, or other professional services advice. The content is provided on an “as is” basis and PBMares makes no representations or warranties about the accuracy or sustainability of any information for your purposes. For any specific questions you may have, please contact us.
This content is accurate at the time of publication. Always ensure you are reviewing the most recent information available. Contact your tax or financial advisor if you need clarification.
Contact Us
About the Author
Antonina McAvoy
CISA, CISM, QSA, PCIP
Partner, Risk Advisory Services
Norfolk
Antonina McAvoy specializes in cybersecurity, data protection, and privacy. She has 14 years of experience leading and performing a wide spectrum of cybersecurity reviews.
View Bio