Most security reviews fail before they begin. Not because the testing is weak, but because leadership walks in without knowing what it is trying to find out. Here are the questions I would want answered — and the ones I would be worried if nobody could answer.
Why I look at this like an auditor
I spent the first part of my career in finance and accounting before moving into cybersecurity. That background changed how I read a security review permanently. In audit, you are not asking whether someone is doing a good job. You are asking whether they can demonstrate it — with evidence, to a third party, after the fact. That distinction is the whole discipline.
Most security reviews are presented as technical exercises: a scan, a list of vulnerabilities, a severity rating, a remediation plan. All useful. But an audit-trained reader asks a different set of questions. Who owns this control? When was it last tested, by whom, and what did the test actually prove? If this failed tonight, how long before anyone knew? None of these are technical questions. All of them determine whether the technical work matters.
Key takeaways
- A US breach now averages $10.22 million; the global average is $4.44 million.
- Detection and containment average 241 days — a nine-year low, still eight months.
- Phishing remains the most common entry point, ahead of supply-chain compromise.
- 63% of breached organizations had no AI governance policy at all.
- Ungoverned shadow AI added roughly $670,000 to the average breach cost.
What the numbers actually justify
IBM’s Cost of a Data Breach report, now in its twentieth year and drawn from 600 organizations across 16 countries and 17 industries, put the global average cost of a breach at $4.44 million — a nine percent fall, and the first decline in five years. The improvement came from faster detection and containment, helped by automation.
The United States moved the other way, reaching a record $10.22 million, driven largely by regulatory penalties and slower detection. That divergence is the most instructive number in the report: the technology available to American and European firms is broadly identical. What differs is the regulatory cost of getting it wrong. Europe should read that as a forward indicator, not a curiosity.
Eight months of undetected access is not a security problem. It is a governance problem wearing a technical costume.
The figure I return to most often is 241 days: the average time to identify and contain a breach. It is the best result in nine years and it is still eight months. Ask what an intruder with eight months of quiet access could do to your payment flows, your client data or your intellectual property, and the abstraction disappears quickly.
The questions I would ask in the room
A security review is a business conversation that happens to involve technology. These are the questions I would want on the table, in this order.
- What are we actually protecting? Not “our systems” — the specific data, processes and revenue streams whose loss would change the business. If leadership cannot name the top five, the review has no scope.
- How would we know? Detection coverage matters more than prevention theatre. Which of our critical systems generate alerts that a human actually reads, and how quickly?
- Who has access, and who approved it? Access accumulates silently. Ask for a list of privileged accounts, when each was last reviewed and how many belong to people who have changed role or left.
- What have we tested, and what did it prove? A test that everyone passed usually means the test was too easy. Ask what failed, what was learned and what changed as a result.
- What depends on someone else? Supply-chain compromise is now among the leading entry vectors. Which third parties could stop our operations, and what have we verified about them beyond a signed questionnaire?
- What would the first 24 hours look like? Who declares an incident, who speaks to regulators and clients, and has anyone rehearsed it? A plan nobody has practised is a document, not a capability.
The AI gap nobody budgeted for
The most uncomfortable finding in this year’s data concerns artificial intelligence. Among organizations that suffered an AI-related security incident, 97 percent lacked proper access controls around those AI systems. Separately, 63 percent of breached organizations had no AI governance policy in place, and only around a third had any approval process for AI deployment.
The financial consequence is measurable. Where shadow AI was widespread — employees using unapproved tools on their own initiative — the average breach cost rose by roughly $670,000. This is the same pattern I described in our previous article on AI adoption: unofficial usage is a signal of unmet demand, and ignoring it does not make it stop. It simply moves your data somewhere you cannot see.
One number deserves a flag of its own. Only 49 percent of breached organizations said they intended to increase security investment, down from 63 percent the year before. Falling average costs appear to have been read as reassurance. I would read them as the temporary benefit of faster detection in a threat environment that has not softened.
Reading the report you are given
Executives are rarely short of security documentation. They are short of a way to interrogate it. This is the grid I use.
| If the report says… | The question to ask |
|---|---|
| “No critical vulnerabilities identified.” | What was in scope, and what was excluded? Exclusions are where the risk usually lives. |
| “Controls are in place.” | In place, or operating effectively? Design and operation are different findings, as any auditor will confirm. |
| “Remediation is underway.” | Owned by whom, funded from which budget, due on what date? Otherwise it is an intention. |
| “We follow industry best practice.” | Against which framework, assessed by whom, and when? Best practice is not a control. |
| “That system is managed by our provider.” | What does the contract oblige them to do, and have we ever verified that they do it? |
Where boards get this wrong
Treating security as a spending question
The board question is rarely “are we spending enough?” It is “what would break first, and how quickly would we recover?” Budget follows that answer; it cannot replace it.
Confusing compliance with security
Compliance proves you met a standard on a given date. Security is a property of a system on a continuous basis. Organizations that fully satisfy a framework and are still breached are not evidence that frameworks fail; they are evidence that certification is a floor.
Reviewing the review too late
A security review presented to the board only after completion invites acceptance rather than challenge. Leadership should shape the scope beforehand — because scope determines findings far more than tooling does.
Certification tells you what was true on the day of the audit. Resilience tells you what remains true on a bad night.
What to do before the next review
- Write down the five things that must not fail. Agree them at leadership level before any technical work starts. Everything else is prioritisation.
- Ask for evidence, not assurance. Logs, test results, dated approvals. The audit standard — could a third party verify this? — is the right bar.
- Put AI systems inside the perimeter. Inventory them, apply access controls, and give people sanctioned tools before shadow usage decides the matter for you.
- Rehearse the first 24 hours. A two-hour tabletop with the executive team surfaces more gaps than most technical assessments.
- Extend the review to critical third parties. Your exposure includes anyone who can stop your operations, regardless of who signs their payroll.
- Report findings in financial terms. Convert exposure into recovery time, revenue at risk and regulatory consequence. Boards act on that; they rarely act on severity ratings.
Closing
The purpose of a security review is not to be reassured. It is to find out what you do not know, while finding out is still cheap. The organizations that handle incidents well are almost never the ones with the most sophisticated tooling; they are the ones where somebody had already asked the awkward questions, written the answers down, and checked that they were still true.
If your next review is scheduled and you are not yet sure what you want it to prove, that is the most useful thing to fix first. It is also the conversation I most enjoy having.
All figures cited are drawn from the following publicly available sources, consulted in June 2026.

