A policy, an audit, or a security badge can help describe your intentions. The next question is how those intentions show up in everyday work.
Ask about the working controls.
Review the accounts people use, the devices they work on, and the way information is shared. Look for gaps between the policy and the actual setup.
- Who has access to important accounts and business files?
- Which devices are managed and kept up to date?
- What information is backed up, and how would it be restored?
- Who reviews an alert and takes the next step?
Make responsibility visible.
A list of tools is only part of the picture. Understand who looks after each part, what gets reviewed, and where a staff member should report a concern.
A useful security plan connects the safeguards to the people responsible for them.
Start with a clear priority.
You do not need to solve every gap at once. Establish the current picture, decide what deserves attention first, and agree on a practical next step.
Back to the journal