Questions for Management

These are the security questions Vid Grosek, Slovenia's first OSCE3 and OSCP+ certified penetration tester based in Ljubljana, recommends every executive ask their security team. Engagements are delivered through Telprom d.o.o. for organizations in Slovenia and the EU, where frameworks such as NIS2 increase leadership accountability for cybersecurity.

Questions management should ask their security team - and the answers they should expect.

Basic Security Questions to Ask

  • "When were we last tested and what were the findings?" - Expect a specific date within the last 12 months and a clear remediation status, not "we test regularly". An external penetration test should run at least annually.
  • "Have all critical findings from the last test been fixed?" - Expect a tracked list of findings with remediation status and retest dates, not a blanket assurance that "it's all handled".
  • "Would we detect if someone broke into our systems today?" - Expect specific detection sources (EDR, logs, SIEM) and a mean time to detect, not just "we have a firewall".
  • "What is our incident response capability?" - Expect a documented incident response plan, defined roles, and evidence the plan has been tested at least once.
  • "Who has admin access and do they all really need it?" - Expect a current list of privileged accounts with a justification for each; excess admin access is one of the most common causes of fast domain takeover.

Questions That Reveal the Truth

  • "If someone stole all our data today, when would we find out?" - Expect a concrete estimate in hours or days backed by detection sources, not "we'd know immediately".
  • "What is our security capability without key person X?" - Expect an honest acknowledgement of single points of failure and a knowledge-transfer plan, not "everyone is interchangeable".
  • "Which system, if compromised, would hurt us the most?" - Expect clearly identified critical systems with tailored protection, not "they're all equally important".
  • "What would happen if all our employees received a convincing phishing email?" - Expect data from real attack simulations and a click-through rate, not "our staff are trained".

Red Flags in Answers

  • "Everything is secure" - No one knows everything
  • "We have [vendor solution]" - Tools aren't strategy
  • "IT/vendor handles that" - Responsibility isn't transferable
  • "We've never had a problem" - Lack of detection isn't lack of attacks

Want these answers verified by an independent test? Contact Vid Grosek or learn more about Vid Grosek and his methodology.