Why do two competent people give opposite security advice?
Usually because each is answering for a different size of organisation without saying so. Advice that keeps a fifty-person company alive — use the defaults, do not build anything bespoke — is negligent at fifty thousand, and the advice that fits fifty thousand is unaffordable at fifty. The disagreement is about the unstated assumption, not the technique.
What is the first thing a small organisation should do?
Find out what of yours is reachable from the internet, and turn off what does not need to be. It is the only part of your estate an attacker can survey without any access at all, which makes it the one place your view and theirs can be compared directly.
How do I check a supplier's security without a security team?
Ask for the audit report rather than the certificate, and read its scope section before anything else — it names which systems were examined and over what months. A certificate covering one product line reads identically in marketing to one covering everything.
Should we manage employees' personal phones?
Decide first whether the phone holds company data or merely displays it. If it only displays it — browser access, no local copy, screen lock enforced — most of the management question disappears, and so does the argument with staff about wiping their photographs.
Is multi-factor authentication enough?
It depends entirely on the factor. Codes sent by message or generated in an app can be read out to a convincing caller, and routinely are. Factors bound to the site they authenticate to cannot be handed over that way, which is a different security property rather than a stronger version of the same one.
How often should we run a penetration test?
The frequency matters less than what happens to the findings. An organisation that tests annually and fixes everything is in better shape than one that tests quarterly and accumulates a backlog, and the second pattern is far more common. Fix rate is the number worth tracking.
Do we need cyber insurance?
It transfers some financial consequence and no operational consequence: the policy does not restore your systems or answer your customers. Read the conditions precedent closely, because several common ones — multi-factor coverage, patching windows, backup testing — are the controls you would want anyway, and failing them at claim time is the standard unpleasant surprise.
What logs should we keep, and for how long?
Authentication, administrative action and network egress, for longer than you think. With a mean of roughly six months between compromise and discovery, retention shorter than that guarantees the investigation begins after the evidence has already rotated away.
Is it safe to use free security tools?
The licence cost is not the risk; the maintenance is. A well-maintained free tool with an active project behind it is a better bet than a purchased one whose vendor was acquired last year. Check the date of the last release before checking the price.
How do we know our backups actually work?
By restoring one. Not verifying it, not checking a green tick — restoring a production system, timing it, and writing down what was still missing afterwards. Organisations discover the gap between backup and recovery at the worst possible moment with striking regularity.
Who should security report to?
Less important than whether the reporting line can say no to the business and survive it. The arrangement fails the same way regardless of the box on the chart: when the person raising the risk is also the person whose project it delays, the risk stops being raised.
What should we do first if we think we have been breached?
Write down the time and what made you think so, then stop changing things. The instinct to clean up destroys the evidence that determines scope, and scope determines what you are legally obliged to tell whom. Preserve first, then contain, then remediate.