You Run the Business. You Also Make the Security Decisions. That Is the Problem.

In a business with fewer than 50 or 100 people, there is rarely a Chief Information Security Officer. There is rarely a dedicated Chief Financial Officer either. There is usually a founder, an owner, or a CEO making most of the significant decisions across both of those functions simultaneously.

That sounds efficient. In many ways it is. But it creates a security problem that larger organizations pay specialists to solve, and smaller ones often do not notice until something goes badly wrong.

When the same person is both approving the security budget and evaluating whether it is adequate, there is nobody in the room to ask the hard question.

What does this spending actually protect?

The Conversation You Are Having With Yourself

Here is how security decisions typically get made in a smaller business.

Your IT person, your managed service provider, or a vendor recommends something. Antivirus. A backup solution. A firewall upgrade. Multi-factor authentication. Maybe a security awareness training platform. The recommendation comes with a price.

You ask whether you need it. They say yes. You ask whether it is important. They say very. You approve it, or you push back on the price, or you defer it to next quarter because cashflow is tight.

At no point in that conversation does anyone ask what specific part of your business this spending protects, why that part is the priority, or what happens to revenue and operations if it fails.

That is not a criticism of your IT provider. They are answering the question they were asked. The missing question is the business one. And in a smaller business, nobody is structurally positioned to ask it except you. They assume you know what you are asking for and why. After all, you are the CEO, the owner, the person in charge.

But do you really?

What the Vendor Conversation Actually Sounds Like

Most small business owners recognize this exchange immediately.

Vendor: We recommend upgrading your endpoint protection. Your current solution is outdated.

Owner: How much?

Vendor: $3,200 per year for your size.

Owner: Is it really necessary right now?

Vendor: Ransomware attacks on small businesses are up significantly. I would strongly recommend it. Did you know businesses like yours are actively targeted, and when attackers succeed the average loss exceeds one million dollars? If you do not believe me, look at the Verizon Threat Report or the IBM findings. Do not just take my word for it.

And there the business decision ends. No discussion of which systems this protects. No clarity on what a ransomware attack would actually cost your specific business. No connection between the $3,200 and any revenue stream, operational capability, or customer commitment.

You either approve it because the fear is real, decline it because cashflow is tight, or defer it because you are not sure. None of those is a business decision. All of them are guesses.

The Question That Changes the Conversation

Now consider the same conversation with one question asked before the vendor starts talking. This is not a question for any vendor. It is one you must ask yourself and answer honestly.

What specific parts of my business cannot afford to stop working?

For most small businesses the answer is surprisingly focused. Customer order processing. Invoicing and payment collection. The production system or service delivery platform. The client data your reputation depends on. Often three to five things that, if unavailable for 48 hours, would create a serious business problem. Just think about it. If revenue stops arriving, how long can you last?

Once you know what those things are, every security conversation changes.

Owner: My order processing system and my client data are the two things I cannot lose. Does this endpoint protection specifically cover those?

Vendor: Yes. It covers all devices on your network including the server running your order system.

Owner: If that server goes down from ransomware, what does recovery look like with this solution versus without it?

That is a business conversation. The vendor can now answer it specifically. You can now evaluate the $3,200 against a real business risk rather than a general fear.

You Do Not Need Enterprise Resources to Think This Way

Larger organizations hire CISOs and CFOs and put them in a room together to work this out. The conversation is still often unproductive, but at least the roles exist.

In a smaller business, you play both roles. Which means you have to ask both sets of questions yourself, or find a trusted advisor who will ask them with you and challenge every answer given until it stops changing. Do not misunderstand — these are tough questions and they demand serious consideration.

The framework is the same regardless of company size. Identify the specific business assets your operations depend on. Define what protection of those assets looks like in practical terms. Evaluate every security recommendation against that standard.

A 40-person business has fewer assets to protect than a 4,000-person enterprise. That makes the framework simpler to apply, not harder. The conversation is shorter. The decisions are clearer. The results are measurable.

What you cannot afford to do is continue making security decisions based on vendor recommendations, fear, or available budget alone. Those are the decisions that leave the production line running while everyone looks for someone who can code COBOL.

Cybersecurity Needs You was written specifically for business owners and leaders who are making these decisions without a security team behind them. It is a short, practical read at $9.95 and it starts exactly where you are.

Find it at TorsettiLabs.com


Dr. Stuart Broderick is the founder of Torsetti Labs and the author of the Business-Driven Cybersecurity series. He has 40 years of practitioner experience across five continents.

Share:

More Posts

Send Us A Message