top of page

A security strategy is a set of decisions, not a shopping list.

Writer: Toga EMEA FZC LLC
Toga EMEA FZC LLC
Jul 27
2 min read

Most cybersecurity checklists are not wrong. Risk assessments, policies, training, detection tools, patching, encryption, backups and incident plans all belong in a mature programme. The problem is the order. A business can own every one of them and still be unable to answer the two questions that decide most outcomes.

Security dashboard on a monitor

The two questions.

What are we actually protecting? And who acts when this alerts at three in the morning — with what authority, and who do they call first?

If either answer is vague, buying more tooling is premature. You will have more alerts and nobody clearly responsible for them.

Start with what matters.

Name the systems and data whose loss or exposure would materially hurt the business or breach an obligation. Give each one an owner. The list is usually shorter than expected, and it tells you where controls earn their cost and where they are decoration.

Then fix the gaps that fail quietly.

Many incidents do not start with an exotic attack. They start with an ordinary gap nobody owned:

  • Leavers who keep access, because nobody reconciles HR records against accounts.

  • A certificate that expires and takes a service down.

  • Penetration test findings still open eighteen months later.

  • Backups that have never been restored, so nobody knows whether they work.

  • Alerts from tools that were bought and are not reviewed.

Each of these is a process with a missing owner, not a missing product.

Rehearse before you need it.

An incident response plan that has never been exercised is a document, not a capability. Run the scenario with the people who would actually be on the call — including the executive who would have to approve taking a production system offline. Most of what the exercise reveals is about authority and communication, not technology.

Be honest about round-the-clock cover.

If you need 24/7 monitoring, you need someone who genuinely provides it: an in-house team staffed for it, or a managed provider under contract. We design detection and staff security functions. We do not run a 24/7 operations centre, and where that is what you need we will help you specify and select one rather than pretend.

Evidence you can stand behind.

Customers, regulators and cyber insurers increasingly ask for evidence rather than assurances. If a questionnaire cannot be answered honestly today, the unanswerable questions are your work plan.

If you cannot answer both questions today, that is a short conversation, not a programme. Speak with Toga.

 
 
 

Comments


bottom of page