
The question rarely comes out of nowhere. Usually something was in the newspaper that morning: a company in the region, production at a standstill, ransomware, the details stay vague. And somewhere between agenda item three and four, the managing director turns to the head of IT and asks: "How secure are we, actually?"
Then comes that pause.
We have seen this scene in many variations, and the answer is almost always a version of "we are in pretty good shape". Sometimes a reference to the firewall follows, sometimes to the backup. The managing director nods, the next agenda item comes up, and both are relieved that the meeting moves on. The pause before the answer was its most honest part.
"How secure is my company?" is one of the most reasonable questions a management team can ask. It has one catch: the way it is asked, it cannot be answered. There is no metric for it. Anyone who gets a simple answer anyway should listen more closely. In most cases, someone is about to sell them something.
Why "in good shape" answers nothing
The IT lead's answer is no sign of incompetence. He is saying something true: the systems run, the known measures are in place, nothing is on fire. But that answers a different question, namely "does our IT work?". Security describes your position against someone who does not play by your assumptions. About that person, "everything runs fine here" says nothing.
Add to that the roles in this conversation. The head of IT is being asked how well he has done his own job, in front of the assembled management. What answer do you expect? Even the most honest person in that position will phrase the gaps more carefully than they are. That is no character flaw; the question is structurally addressed to the wrong person.
The second shortcut is more tempting because it looks like precision: the number. There is an entire industry that answers "How secure is my company?" with a score: 87 out of 100, rating B+, a dashboard full of green tiles. These ratings now show up everywhere: cyber insurers use them for premium calculations, enterprise customers screen their suppliers with them, and at some point such a report lands unsolicited in your inbox, with a grade on it and an offer next to it.
These scores measure what can be queried from the outside in an automated way: certificates, open ports, known vulnerabilities on public systems, suspicious entries in the relevant databases. That is a narrow slice of your attack surface. Whether your admin account has a second factor, whether your backup has ever been restored, whether accounting picks up the phone when a payment instruction looks unusual: the score sees none of it. It sees your facade, and from the facade it draws conclusions about the house.
Such ratings are useful as an early warning for forgotten systems on the internet. As an answer to the management's question they are useless, and that is exactly how they are sold.
Which leaves the third shortcut: asking your own IT service provider. Here too, a look at the incentives pays off. A provider who lives off your licenses and operating hours will, in our experience, rarely answer "How secure are we?" with "you have bought too much". The answer is more often a list of what is still missing, and the list ends in a quote. That need not be bad faith. Someone who sells tools sees problems that look like tools. The result is a shopping list, and the question of whether what you already have is deployed and configured properly is one the list does not ask.
All three shortcuts have the same effect: an answer that seems to settle the question does more damage than no answer at all. It ends the conversation. The board notes down the 87, the agenda item counts as done, and the questions that would have mattered were never asked.
The four questions that can be answered
The good news: the big question breaks down into four small ones, and each of them has a verifiable answer. None of them requires technical knowledge. All four belong in the management meeting, and none of them can be settled with a nod.
What is reachable at our company, and what are we useful for? This is the inventory question. Which systems are accessible from the internet, which accounts hold far-reaching privileges, which remote access paths exist for suppliers and service providers? And behind that, the more uncomfortable half: what would make us interesting to an attacker? Someone at your company can transfer money. Customer data sits somewhere. Maybe you are useful mainly as a path to a bigger customer, as the weakest link in a supply chain someone else has in their sights. In our experience, the first honest inventory regularly contains surprises: the machine supplier's remote maintenance access nobody remembered, the test system from 2019 that still runs, or the admin account of an employee who left two years ago. None of this is dramatic as long as someone knows about it. The only dangerous inventory is the one nobody keeps.
Would we notice? Most attacks start quietly. Someone gains access and looks around, often for weeks, before anything gets encrypted or exfiltrated. In that window the damage could be averted, but only if someone is watching. So the question is: who at your company sees the alerts, who gets called, and does that hold at night and on weekends? A useful test is to look back: when did someone last follow up on an alert, and what happened then? If nobody can name a concrete example, detection is a concept and not an operation. And the answer "the antivirus handles that automatically" translates to: nobody is watching. The task may well sit with an external service; for many SMEs that is the most sensible solution. But then it must be clear who on your side takes the call and is allowed to decide.
How fast would we be back? That a backup exists says little. The question is whether anyone has ever restored from it, how long the most important processes take to bring back, and whether the answer comes from experience or from a concept paper. Between "we have a backup" and "we were able to deliver again after two days" lie, in a real incident, weeks of standstill. This includes the unpleasant variant: what if the backup was encrypted along with everything else because it sat on the same network? Whoever has never practiced the restore does not know their answer. They have deferred it to the day when it is most expensive. The exercise costs one afternoon: pick a system and restore it against the clock. After that, the answer to this question is no longer an estimate, and in most cases it also triggers a few quiet corrections to the backup concept.
Who decided which risks we carry? Every company carries residual risks, even the best protected one. The difference lies in whether that was a decision or an accident. Is it written down anywhere which risks the management knows about and consciously accepts? This question feels bureaucratic but is the one with the biggest personal consequences: after an incident, what counts is the evidence that decisions were made with due care. Why this is also a liability issue for boards of directors is something we covered in our post on cyber liability in the board of directors.
"Secure" is a decision, not a metric
When you work through these four questions, you get a picture instead of a score: here we stand solid. Here we have a gap that we are closing. Here we carry a risk, deliberately, because closing it would cost more than the risk justifies.
An example of that last category, one we regularly encounter in manufacturing companies: an older machine control system for which updates no longer exist. Replacing it would cost a six-figure amount, and the machine will run for years. The viable path lies in between: separate the system from the rest of the network, restrict access to a few people, and record the decision along with its reasoning. The risk remains. But it is chosen rather than suffered, and it is documented.
That is the grown-up form of "secure": the gaps are known, the important ones are closed, and someone with the authority to do so has decided on the remaining ones.
This picture has a side effect that often goes unnoticed. It shows both: where there is too little and where there is too much. In our experience, many SMEs are covered several times over in some places, three tools for the same job, while right next to that one of the four questions is completely open. More budget helps little at that point; reallocating does. Without the picture, budget allocation stays a blind flight; with the picture, it becomes arithmetic.
Working out exactly this picture with method and evidence, instead of from gut feeling: that is the core of a security assessment. It answers the four questions with evidence instead of estimates. How that differs from a penetration test is something we took apart here, and we talk openly about the costs in this post.
The better question for your next meeting
Back to the meeting room. The question "How secure are we, actually?" will not get a number as an answer, even after this article. But you can replace it.
Ask the four small questions. What is reachable, and what are we useful for? Would we notice? How fast would we be back? Who decided on our residual risks? Where the answers come easily, you can set the topic aside with a clear conscience. Where there is hesitation, you have found your priorities, without a score and without a new tool. The hesitation, by the way, is no reason to blame IT. Chances are the four questions were never asked there in this form.
Which of the four questions could your team answer today without hesitating?
If you would rather work out the answers once, in a structured way, we do that together. An initial conversation is free of obligation, and afterwards you know where you stand.



