In short

A leadership cybersecurity review should establish critical services, privileged access, recovery capability and incident responsibilities. Ask for current evidence that controls work, agree which gaps matter most and involve qualified specialists where assessment or incident response is required.

In this guide

Start with what the business cannot afford to lose

Begin with the services that support customers, payments, payroll and day-to-day operations. For each, identify the business owner, system administrator, provider and information involved. Agree how long the business could operate without it and what information would be needed to restore service.

This makes the conversation more concrete than asking whether the business is "secure". A small company can have well-managed email but unclear access to its website, a shared finance login or no tested way to recover a key report. The review needs to cover the actual environment, including outsourced services.

Ask for evidence of the controls

The ASD Essential Eight addresses areas including patching, multifactor authentication, administrative privileges, application controls and backups. It is a useful reference for internet-connected IT networks, not a complete assessment of every business risk or specialised operational environment.

Management questionUseful evidenceFollow-up when unclear
Who has powerful access?Current privileged accounts and recent access reviewResolve shared, unused or unexplained accounts
Are updates actually applied?Coverage, failed deployments and exceptionsAssign responsibility for unsupported or excluded systems
Can we recover?A recent restore test with the service ownerTest a realistic recovery, not just backup-job success
Who responds?Contact path, escalation responsibilities and rehearsal notesConfirm after-hours coverage and external assistance

A green indicator should have a defined meaning, scope and date. Ask what it excludes. A successful backup does not establish the time needed to restore a complete service, and a policy does not establish that departed staff have lost access.

Make the provider boundaries visible

An IT provider, web developer, payroll vendor and internal manager may each assume another party handles a particular control. Record who configures access, monitors alerts, retains logs and communicates during an incident. Confirm those responsibilities against the actual service agreement.

The ACSC's questions for managed service providers cover secure administration, monitoring, vulnerability assessment and incident readiness. Use the answers to agree responsibilities and obtain evidence, not simply to collect yes-or-no assurances.

Do not run intrusive scans or recovery tests against production without an agreed scope and authorisation. Independent testing, forensics and response support may require specialists beyond the provider maintaining the system.

Include integrations and AI in the review

Automation introduces accounts, permissions, data copies and failure paths. List the systems it can read and change, who owns its credentials and how access can be revoked. Check that its logs are useful without exposing sensitive records or secrets.

For AI-enabled workflows, inspect what information reaches the provider, what actions are permitted and which decisions require review. Keep untrusted documents from supplying instructions that grant the tool new authority. Test attempts to access unrelated records and to perform an unapproved action before release.

Turn the review into an owned improvement plan

Prioritise gaps by business consequence and exposure. Give each an owner, expected evidence and review date. Track exceptions openly, including the reason they remain and the temporary protection. Avoid treating an aggregate score as permission to ignore a critical unresolved weakness.

Advery can help leadership map dependencies, coordinate providers and make control responsibilities and follow-up visible. Specialist penetration testing, formal assurance and incident response should be separately scoped with appropriately qualified providers. No review can guarantee that a business will not experience an incident.

Sources and guidance

ScopeThis article provides general operational information for Australian businesses. It is not legal, privacy, cyber security, financial or accounting advice. Confirm obligations for your business and use case.