In short
A leadership cybersecurity review should establish critical services, privileged access, recovery capability and incident responsibilities. Ask for current evidence that controls work, agree which gaps matter most and involve qualified specialists where assessment or incident response is required.
In this guide
Start with what the business cannot afford to lose
Begin with the services that support customers, payments, payroll and day-to-day operations. For each, identify the business owner, system administrator, provider and information involved. Agree how long the business could operate without it and what information would be needed to restore service.
This makes the conversation more concrete than asking whether the business is "secure". A small company can have well-managed email but unclear access to its website, a shared finance login or no tested way to recover a key report. The review needs to cover the actual environment, including outsourced services.
Ask for evidence of the controls
The ASD Essential Eight addresses areas including patching, multifactor authentication, administrative privileges, application controls and backups. It is a useful reference for internet-connected IT networks, not a complete assessment of every business risk or specialised operational environment.
| Management question | Useful evidence | Follow-up when unclear |
|---|---|---|
| Who has powerful access? | Current privileged accounts and recent access review | Resolve shared, unused or unexplained accounts |
| Are updates actually applied? | Coverage, failed deployments and exceptions | Assign responsibility for unsupported or excluded systems |
| Can we recover? | A recent restore test with the service owner | Test a realistic recovery, not just backup-job success |
| Who responds? | Contact path, escalation responsibilities and rehearsal notes | Confirm after-hours coverage and external assistance |
A green indicator should have a defined meaning, scope and date. Ask what it excludes. A successful backup does not establish the time needed to restore a complete service, and a policy does not establish that departed staff have lost access.
Make the provider boundaries visible
An IT provider, web developer, payroll vendor and internal manager may each assume another party handles a particular control. Record who configures access, monitors alerts, retains logs and communicates during an incident. Confirm those responsibilities against the actual service agreement.
The ACSC's questions for managed service providers cover secure administration, monitoring, vulnerability assessment and incident readiness. Use the answers to agree responsibilities and obtain evidence, not simply to collect yes-or-no assurances.
Do not run intrusive scans or recovery tests against production without an agreed scope and authorisation. Independent testing, forensics and response support may require specialists beyond the provider maintaining the system.
Include integrations and AI in the review
Automation introduces accounts, permissions, data copies and failure paths. List the systems it can read and change, who owns its credentials and how access can be revoked. Check that its logs are useful without exposing sensitive records or secrets.
For AI-enabled workflows, inspect what information reaches the provider, what actions are permitted and which decisions require review. Keep untrusted documents from supplying instructions that grant the tool new authority. Test attempts to access unrelated records and to perform an unapproved action before release.
Turn the review into an owned improvement plan
Prioritise gaps by business consequence and exposure. Give each an owner, expected evidence and review date. Track exceptions openly, including the reason they remain and the temporary protection. Avoid treating an aggregate score as permission to ignore a critical unresolved weakness.
Advery can help leadership map dependencies, coordinate providers and make control responsibilities and follow-up visible. Specialist penetration testing, formal assurance and incident response should be separately scoped with appropriately qualified providers. No review can guarantee that a business will not experience an incident.