BY FULTON MAY SOLUTIONS
Most businesses have some form of cybersecurity in place. Antivirus software. Regular patching. Maybe a firewall. Backups somewhere.
Most businesses also have no real idea whether those measures are actually protecting them.
There’s a significant difference between having security tools in place and having a security posture. Tools are the minimum. A posture is an active, tested, continuously improving approach to defending your business.
Here’s how to tell the difference.
The questions that reveal whether your security is real
1. When did you last test your backups?
Having backups is not the same as having working backups. Backup systems fail. Data corrupts. Configurations drift. If your backups have never been tested with a full restore — or if the last test was more than 12 months ago — you don’t know whether your recovery plan actually works until you need it. By then, it’s too late.
2. Do you have a documented incident response plan?
If a ransomware attack hit your business tomorrow, what’s the first call your team makes? What’s the second? Who makes decisions about paying or not paying? Who notifies customers and partners? How long does recovery take?
If those answers aren’t written down and tested, your response to an incident will be improvised under pressure. That improvisation costs time, money, and often data.
3. Is identity and access management in place?
More than 80% of breaches involve compromised credentials. If an employee’s password is stolen — through phishing, a data breach at another service, or simple reuse — how much damage can an attacker do with those credentials? Multi-factor authentication, least-privilege access, and regular access reviews are the controls that limit that damage.
4. Have you had a third-party security assessment in the last two years?
Your IT provider checking their own work is not a security assessment. A genuine assessment is conducted by an independent party that reviews your environment against established frameworks, identifies gaps, and produces a prioritized remediation plan. Without this, your security posture has blind spots your provider may not be incentivized to find.
5. Can you pass a customer security questionnaire?
If you work with larger customers — especially in manufacturing, financial services, or healthcare — you may already be receiving supplier security questionnaires. These ask for documentation: security policies, incident response plans, evidence of testing, multi-factor authentication status.
If you can’t answer these questions with documentation, you’re not just a security risk. You’re a business risk to the customers evaluating your supply chain.
What proactive security looks like
A genuine security posture includes all the basics — antivirus, patching, backups, MFA — but it doesn’t stop there. It includes:
- Regular, tested backup restoration to verify recovery capability
- A documented and rehearsed incident response plan
- Identity and access management with least-privilege controls
- Annual or biannual third-party security assessments
- Security awareness training for employees
- Documented security policies that can be shared with customers and insurers
This is not an exhaustive list. But businesses that have these things in place are meaningfully more protected than those that don’t — and they’re in a much stronger position when a customer asks about their security posture or when a cyber insurance renewal requires evidence of controls.
If you’re not sure whether your security is genuinely protecting your business — or if a recent security questionnaire from a customer surfaced gaps you weren’t aware of — this is a conversation worth having before something goes wrong.







