← All insights
Security leadership

Seven cybersecurity questions to ask before buying another tool

A practical conversation guide for leaders who need priorities, ownership, and a clear next step.

September 24, 2026 · 4 min read

The short answer
Start with the business processes you need to protect, the people responsible for them, and evidence that existing controls work. Use those answers to decide whether the next investment should be a tool, a process change, or specialist support.

1. What must keep running?

Name the operations your organization cannot easily pause: receiving orders, processing payments, serving customers, or accessing critical records. Ask the business owner of each process what a disruption would prevent them from doing. A discussion about a named operation is easier to prioritize than a broad request to improve security.

2. Who owns the decision?

Identify the executive who can approve the next step and the person who will carry it out. A technology administrator may understand the system without having authority to accept business risk. Record both responsibilities before choosing a solution.

3. What evidence do we have?

Ask for a recent example of a control being checked. That might be a documented access review, a recovery exercise, or a completed corrective action. A purchased product and an effective operating practice are different things. Be clear about what has been verified and what is still an assumption.

4. What happens outside normal hours?

Discuss who receives an urgent alert, how that person is reached, and what decisions they can make. If an external provider is involved, review the responsibilities in the agreement. Do not assume that monitoring automatically includes every response action your organization might need.

5. What depends on a third party?

List the services, suppliers, and outside accounts that support your critical operations. Ask what information you would need from each provider during a disruption. Use the exercise to find unclear ownership or communication paths before an incident tests them.

6. What can we realistically improve this quarter?

Choose a small number of actions with an owner, completion date, and a way to demonstrate completion. A workable plan should reflect available staff time as well as budget. Explain which business concern each action addresses so that progress is visible outside the IT team.

7. What would make us change the plan?

Agree on review triggers, such as a new business service, a major supplier change, or findings from an exercise. Keep a short decision record: what was chosen, why, who owns it, and when it will be reconsidered. This makes the next conversation build on the last one.

Bring a one-page brief

Before speaking with a specialist, prepare three business priorities, the questions you cannot yet answer, and the outcomes you want from the conversation. Avoid including credentials, detailed system configurations, or sensitive incident evidence in an initial inquiry. Peter can help you frame the discussion with the Argent Reach team.

Further reading

General educational content. Apply it with the people responsible for your organization's security and operations.

What does this mean for your organization?

Ask to connect with Peter Reynolds for a practical conversation about your next step.

Talk with the team →

Keep exploring

Is your incident response plan ready for a real conversation? →

AI in cybersecurity: five questions before the pilot →