Why leadership teams need to treat cybersecurity as business risk, not technical noise.
|
Author Greg “Dutch” Holland-Merten, MSc, MSyI Reviewed by HMH Cyber Assessment Team |
Best for CFOs, COOs, business owners, board members, MSP-managed companies, law firms, dealership groups, clinics, and organizations handling sensitive client data. |
Key takeaway: Cybersecurity tools do not equal assurance. Leadership needs evidence that controls work and a clear view of where business risk sits.
Cyber Risk Is Not an IT Problem.
A vulnerability scan is useful. But it is not a penetration test.
Cyber risk is often pushed into the IT department. That is understandable. The language is technical. The tools are technical. The alerts, patches, firewalls, endpoints, cloud settings, and access controls all sit in technical places.
But cyber risk is not just an IT problem. It is a business exposure problem.
When cyber controls fail, the impact does not stay neatly inside the server room. It lands on operations, finance, legal, insurance, client trust, staff productivity, reputation, and leadership credibility.
The IT team may manage the systems. Leadership owns the risk. That distinction matters.
The boardroom mistake.
The common mistake is simple: leadership asks, “Are we secure?” IT or the MSP replies, “We have tools in place.”
That answer may be true, but it is not complete.
Security tools are not the same as security assurance. A company may have endpoint protection, MFA, backups, firewall management, email filtering, vulnerability scans, and policies – and still have serious exposure.
Why? Because tools only matter if they are deployed properly, monitored properly, tested properly, and supported by good process.
A control that exists on paper but fails in practice is not a control. It is a comfort blanket. And comfort blankets are not much use when the building is on fire
What recent incidents should teach leadership.
Recent cyber incidents around the world have made one thing clear: cyber attacks are no longer just data events. They are business disruption events.
In 2025, Jaguar Land Rover publicly stated that a cyber incident severely disrupted retail and production activities. That is the point leadership should focus on: not just whether data was stolen, but whether the business could operate.
When systems go down, the impact becomes immediate. Manufacturing can stop. Retail operations can be interrupted. Invoices may not go out. Staff may be unable to work. Clients may lose confidence. Legal and insurance teams may become involved before the technical team has finished understanding the incident.
That is why cybersecurity must be discussed as operational resilience, not just IT housekeeping
What cyber risk really means.
Cyber risk is not only the possibility that someone gets into a system. That is just the entry point.
The real questions are: what can they reach, what can they change, what can they steal, what can they stop, and what would the business lose if the system went down?
A proper cyber conversation asks whether the business could continue operating, whether clients would need to be notified, whether insurance would respond as expected, whether the company could prove reasonable steps were taken, and whether leadership understands what risk it is accepting.
That is a very different conversation from “do we have antivirus?”
Cybersecurity should be tested, not assumed.
The biggest issue HMH sees is assumption.
Leadership assumes the MSP has it covered. The MSP assumes the vendor configured it correctly. The vendor assumes the client understands the risk. The client assumes the tools are working. Nobody tests the full picture.
That is where risk hides.
A proper cyber assessment should look at what exists, how it is configured, how it is managed, whether it can be exploited, and what business impact would follow if it failed.
A serious assessment may include.
- External infrastructure testing
- Internal network testing
- Web application testing
- Cloud exposure review
- Email security review
- Credential exposure checks
- Active Directory assessment
- Remote access review
- Vulnerability validation
- Security policy review
- Incident response readiness
- Backup and recovery assumptions
- Vendor and third-party exposure
Compliance is not the finish line.
Compliance has value. Cyber insurance questionnaires have value. Client security requirements have value. Policies have value.
But none of them prove that the environment can withstand attack.
A business can look compliant and still be vulnerable. A business can have policies and still have weak access control. A business can have cyber insurance and still be operationally unprepared.
Compliance asks, “Did you say you do the thing?” Testing asks, “Does the thing actually work?” That is the difference.
The human element still matters.
Cybersecurity is not only a technical discipline. People remain central to the risk.
Staff click links. Executives approve payments. Admins reuse credentials. Vendors get too much access. Departing employees retain accounts. Helpdesks reset passwords. Managers bypass process for convenience.
Attackers understand this. They do not care how good the policy looks. They care where the business is weak.
Sometimes the weakness is a missing patch. Sometimes it is a poor password. Sometimes it is an over-permissioned user. Sometimes it is a vendor account nobody reviewed. Sometimes it is a rushed employee on a mobile phone approving something they should have questioned.
Security needs technical controls, but it also needs discipline, training, verification, and leadership attention.
What good cyber leadership looks like.
A good leadership team does not need to become a room full of engineers. But it does need to understand the right questions.
- What systems are critical to business operations?
- Who has administrative access?
- Where is sensitive data stored?
- Which vendors have access?
- Is MFA enforced properly?
- Are backups tested?
- Are systems patched in a reasonable timeframe?
- Has external exposure been tested?
- Has internal movement been tested?
- Do staff know how to report suspicious activity?
- Has incident response been rehearsed?
That is governance. Not technical micromanagement. Governance.
What HMH looks for.
When HMH reviews a cyber environment, we are not interested in theatre. We are interested in exposure.
- What can be reached from the outside?
- What can be exploited?
- What happens if one user account is compromised?
- Can access be escalated?
- Can sensitive data be reached?
- Can systems be disrupted?
- Are vendors creating risk?
- Are controls actually working?
- Can leadership understand the findings?
- Can the business fix issues in a practical order?
Security should be understandable. A CFO should not need a computer science degree to understand whether the business is exposed. The technical team needs the detail. Leadership needs the impact. A good report gives both.
Leadership checklist
- When was our last independent cyber assessment?
- Did it include real penetration testing or only scanning?
- Were findings ranked by business impact?
- Did we remediate the findings?
- Was remediation retested?
- Do we know our critical systems?
- Do we know who has admin access?
- Do we know where MFA is not enforced?
- Do we know which vendors can access our environment?
- Do we know whether backups have been tested?
- Do we have an incident response plan?
- Has that plan ever been exercised?
If those questions create silence in the room, that is the starting point. Not a reason to panic. A reason to act.
The HMH view
Cyber risk is not an IT problem. It is a business problem with technical components.
The IT team may operate the environment. The MSP may support it. Vendors may provide tools. The insurance broker may help transfer some financial exposure. But leadership still owns the decision-making.
At HMH Consulting, we help businesses remove assumption from cyber risk. We assess the environment, test the controls, explain the business impact, and give leadership a practical path forward.
No fearmongering. No bloated technical theatre. No box-checking dressed up as security.
Just clear findings, direct advice, and a proper view of where the business stands.
If your company has not had an independent cyber assessment in the last 12 months, now is the time to ask whether your controls have actually been tested or simply trusted.
Scope a penetration test with HMH Consulting.
Discreet outreach. No obligation