The Cybersecurity Conversation Every Business Owner Needs to Have With Their IT Person
• BizVuln Staff
A must-read guide for small business owners. Learn the critical cybersecurity questions to ask your IT person in 2026, plus actionable steps and a partner like ZoeSquad.
The Cybersecurity Conversation Every Business Owner Needs to Have With Their IT Person
You trust your IT person to keep your business running. But do you know what they’re actually doing to protect it?
In 2026, the cybersecurity landscape for small and medium-sized businesses (SMBs) is more dangerous than ever. Ransomware-as-a-service kits are available on the dark web for a few hundred dollars. AI-generated phishing emails fool even experienced employees. And attackers no longer discriminate by company size—they target the weakest link, which is often a small business with a single overworked IT administrator.
According to the 2025 Verizon Data Breach Investigations Report, 43% of data breaches now involve small business victims. The average cost of a breach for a business with fewer than 500 employees has climbed past $120,000, a figure that can be devastating—and often fatal. Yet most business owners have never sat down with their IT person for a real, honest conversation about security.
This post is your guide to that conversation. By the end, you’ll know exactly what to ask, what answers to expect, and how to close the gaps that could put your company out of business.
---
Why This Conversation Is Non-Negotiable in 2026
The relationship between a business owner and an IT person often operates on a simple assumption: *“The IT person handles the tech stuff, so we’re covered.”* That assumption is dangerous.
Many IT professionals are experts in keeping systems running—installing software, managing networks, resetting passwords. But cybersecurity is a distinct discipline. It requires proactive threat hunting, continuous monitoring, incident response planning, and compliance awareness. A good help desk technician is not automatically a good security analyst.
New threats in 2026 make the distinction critical:
- **AI voice cloning** – Attackers call employees imitating your voice to authorize fraudulent wire transfers.
- **Deepfake video meetings** – A “CEO” asks the finance team to pay a fake invoice during a Zoom call.
- **Fileless malware** – Attacks that run entirely in memory, leaving no traces for traditional antivirus.
- **Supply chain attacks** – Hackers breach a small vendor to get access to its larger clients.
If your IT person is still relying on outdated antivirus software and a once-a-year password change policy, your business is at risk. This conversation is the first step in bridging the gap.
---
The Critical Questions Every Owner Must Ask
1. “How do we manage backups, and can you prove they work?”
Backups are the single most important defense against ransomware. But having a backup is not enough—it must be immutable (unchangeable by attackers), air-gapped (disconnected from the network when not in use), and tested regularly.
What to look for:
- Daily automated backups with versioning.
- Offline or cloud backups with write-once, read-many (WORM) storage.
- Quarterly restoration tests documented and reviewed.
Red flags:
- “We have a USB drive that we plug in once a week.”
- “We’ve never actually restored from backup—we assume they work.”
- “We store backups on the same server as production data.”
2. “Are we using multi-factor authentication (MFA) everywhere?”
MFA blocks 99.9% of automated account compromise attacks, according to Microsoft. Yet many businesses only enable it for email, leaving VPNs, financial software, and remote desktop ports exposed.
What to look for:
- MFA enabled on all external-facing systems (email, payroll, banking, CRM).
- MFA enforced for remote access (VPN, RDP, admin portals).
- Use of app-based authenticators or hardware security keys, not SMS (which can be intercepted).
Red flags:
- “MFA is optional for users who find it annoying.”
- “We only use MFA for the CEO’s email.”
- “We don’t use MFA on our administrative accounts.”
3. “How quickly do we patch software, and what’s our process?”
Exploits for unpatched vulnerabilities are published within hours of a patch release. Attackers scan the internet for unpatched systems immediately. In 2026, a patch delay of even 48 hours can be catastrophic.
What to look for:
- A formal patch management policy with clear timelines (e.g., critical patches within 24 hours, high within 72 hours).
- Automated patching for operating systems and common software.
- Regular scanning for outdated or unsupported software.
Red flags:
- “We patch when we have time—maybe once a month.”
- “We don’t track what software is installed.”
- “We still run Windows 7 or Server 2012.”
4. “What happens if we get hit by ransomware tomorrow?”
Your IT person should be able to describe a detailed incident response plan—not just for ransomware, but for any major security event. This plan should include:
- Who is contacted first (internal team, legal, insurance, forensics).
- How systems are isolated to stop the spread.
- Where the offline backup set is stored.
- How employees and customers will be notified.
- Who has authority to shut down the network.
What to look for:
- A written, annually tested incident response plan.
- Contact information for a third-party incident response firm (like ZoeSquad for IT remediation).
- A ransomware-specific runbook with screenshots.
Red flags:
- “We’ll figure it out if it happens.”
- “We’ll just pay the ransom—it’s cheaper.” (Note: paying often doesn’t restore data, and it makes you a repeat target.)
5. “Who has access to what, and how do we manage it?”
Overprivileged users are a leading cause of breach severity. An employee who only needs email and a CRM should not have local admin rights on their laptop. Ex-employees should have accounts disabled immediately.
What to look for:
- A formal onboarding/offboarding process.
- Role-based access control (RBAC) for all critical systems.
- Quarterly access reviews to remove unnecessary permissions.
- Privileged access management (PAM) for admin accounts.
Red flags:
- “Everyone is a local admin—it’s easier.”
- “We don’t really remove accounts when people leave, we just forget about them.”
- “The same password is used for all shared accounts.”
6. “Do we have cyber insurance, and what does it require?”
Cyber insurance is no longer a checkbox—it requires evidence of specific controls: MFA, endpoint protection, employee security training, and often a vulnerability scan. Your IT person should be working with your broker to meet these requirements.
What to look for:
- An active cyber liability policy with adequate limits (typically $1M-$5M for SMBs).
- Evidence that your IT controls meet the insurer’s requirements.
- Regular communication between IT and your insurance agent.
Red flags:
- “I don’t know if we have cyber insurance.”
- “Our broker said we’re fine, but we’ve never shown them our security setup.”
- “We have general liability—that covers cyber, right?” (It doesn’t.)
---
The Knowledge Gap: Why Your IT Person Might Not Be a Security Expert
It’s uncomfortable, but many business owners need to hear this: most IT generalists are not cybersecurity specialists. They may be great at setting up networks and fixing printers, but security is a different field requiring separate certifications (CISSP, CISM, OSCP) and ongoing education.
A 2025 survey by the SANS Institute found that 68% of IT professionals in small businesses reported having no formal security training. They learn on the job, often reactively. They may not know about the latest attack vectors or how to configure a SIEM (Security Information and Event Management) system.
This doesn’t mean you need to fire your IT person. It means you need to have an honest conversation about their skill set—and be willing to bring in specialized help where needed. That’s where partners like ZoeSquad come in: they provide remediation and security-adjacent services that fill the gaps between your in-house IT and true enterprise-grade protection.
---
Actionable Cybersecurity Checklist for Your Next IT Meeting
Before your sit-down, print this checklist. Use it as a conversation guide.
| ✅ | Item | Notes |
|---|---|---|
| [ ] | Backup Restoration Test – Ask to see a dated restoration test report from the last 90 days. | |
| [ ] | MFA Audit – Request a list of all systems with MFA enabled. Identify any gaps. | |
| [ ] | Patch Status – Get a current patch compliance report for all endpoints and servers. | |
| [ ] | Incident Response Plan – Review the plan together. Walk through the first 15 minutes of a ransomware scenario. | |
| [ ] | User Access Review – Run a report of all active users and their permissions. Look for stale accounts. | |
| [ ] | Endpoint Protection – Confirm you have EDR/XDR (not just legacy antivirus) with 24/7 monitoring. | |
| [ ] | Security Awareness Training – Verify that all employees have completed training in the last 12 months with simulated phishing tests. | |
| [ ] | Cyber Insurance Documentation – Collect your insurer’s requirements and cross-check with your controls. | |
| [ ] | Vendor Security – Ask how your IT person vets third-party software and cloud providers. | |
| [ ] | Logging & Alerting – Confirm that security logs are collected and reviewed (or monitored by a SOC). | |
Priority action items:
1. If you check fewer than 6 boxes, schedule a second meeting with a security specialist this month.
2. If you have a critical gap (no backup testing, no MFA on email), initiate a remediation project immediately.
3. Consider engaging a remediation partner like ZoeSquad to address complex gaps your IT person may not be equipped to handle.
---
Frequently Asked Questions
Q1: What should I do if my IT person gets defensive during this conversation?
Make it clear the discussion isn’t about blame—it’s about shared risk. Frame it as: “I want to make sure we’re both protected. Help me understand where we stand so we can make smart investments.” If defensiveness persists, it may be a sign they are out of their depth and unwilling to acknowledge it.
Q2: How often should we have this conversation?
At least twice a year, and after any major security incident or change in your business (new software, remote workforce, merger). Quarterly is better.
Q3: My IT person says we’re too small to be a target. Is that true?
No. Small businesses are targeted precisely because they have weaker defenses. Many attacks are automated—they scan the entire internet for vulnerable systems regardless of size. In fact, 60% of small businesses that suffer a cyberattack go out of business within six months.
Q4: Do I need to hire a dedicated security person, or can my current IT person handle it?
If your business has more than 25 employees, handles sensitive data (PHI, PII, credit cards), or accepts online payments, you likely need a security specialist—either as a consultant or through a managed security service provider (MSSP). A remediation partner like ZoeSquad can supplement your IT person without replacing them.
Q5: What is the biggest mistake I can make in this conversation?
Treating it as a one-time checkbox. Cybersecurity is a continuous process. The questions above will evolve as threats evolve. The most important outcome is establishing a regular rhythm of transparency and accountability.
Q6: What is ZoeSquad, and how can it help?
ZoeSquad is a technology remediation partner that helps small and medium businesses close security gaps. They can provide expert guidance on backup systems, endpoint protection, incident response planning, and recovery operations—working alongside your existing IT person to strengthen your overall posture without overhauling your team.
---
Conclusion: From Trust to Transparency
As a business owner, you can’t afford to stay in the dark about your cybersecurity posture. The conversation with your IT person is not about finding fault; it’s about building a shared understanding of risk. Threats in 2026 are more sophisticated, more automated, and more financially damaging than ever. Relying on assumptions is a gamble you will likely lose.
Use this guide to start the dialogue today. Ask the hard questions. Verify the answers. Fill the gaps with expertise when needed—whether from your own team or from specialized partners like ZoeSquad. The cost of prevention is a fraction of the cost of a breach.
Your business’s future depends on the conversation you’re willing to have right now.
---
*BizVuln.com provides cybersecurity intelligence and services to protect small and medium-sized businesses. For more resources, visit our blog or contact us for a risk assessment.*
```