Insights

This Is Where I Talk About the Things Leaders Usually End Up Talking About After Something Goes Wrong.

SPARK Insights is not meant to be a news feed. It is a place for practical thoughts, questions, examples, and lessons that executives and boards can actually use.

Insight

Doing Nothing Is Still a Decision

By: Jerry Beckley Doing nothing is easy. The hard part is doing something. Doing something means taking the time to ask uncomfortable questions. It means getting people in the same room and admitting that maybe your organization is not as prepared as everyone assumes it is. It means rallying people around the idea that there […]

Doing nothing is easy. The hard part is doing something. Doing something means taking the time to ask uncomfortable questions. It means getting people in the same room and admitting that maybe your organization is not as prepared as everyone assumes it is. It means rallying people around the idea that there is a vulnerability, there is a risk, and somebody needs to own it.

That is not always an easy conversation.

I have been doing this for more than 30 years, and when I look back, organizations used to have a little more room to make things up as they went. Technology was simpler. There were fewer systems, fewer vendors, fewer connections, and fewer people trying to find a way into your environment.

Today, that is not the world we live in.

If you are an executive leader, part of your responsibility is making sure the organization is delivering good service, but there is also a public service and public safety side to leadership. People depend on your organization. Your customers depend on you. Your community depends on you. And if something significant happens, the questions are going to come pretty quickly.

What did you know? When did you know it? What did you do about it?

That is where I think leadership has changed. Years ago, maybe a leader could say, “I did not know.” Today, I am not sure that answer is going to work very well with your board, your governing body, your regulators, your customers, or whoever you answer to.

You do not have to be the cybersecurity expert. You do not have to know how every system works. But you do need to know enough to ask the right questions. Do we have a plan? Who owns it? When did we last look at it? Has anybody actually tested it? What happens if one of our critical systems is unavailable? What happens if the one person who knows how everything works is not there?

Those are not technical questions. Those are leadership questions.

Think About Going on Vacation.

If you are going somewhere, you usually plan the big things first. Are we driving or flying? Where are we staying? How long are we going to be gone?

Then you get into the smaller details. Where are we going to park when we get to the airport? How early do we need to leave? What happens if the flight is delayed?

Nobody would plan a major trip by saying, “We do not know how we are getting there, where we are staying, or what we are doing when we arrive, but we will figure it out.”

But organizations do that all the time with cybersecurity, incident response, disaster recovery, and business continuity. “We will figure it out if something happens.” That is not much of a plan.

Pay Attention to the Headlines.

When you see cybersecurity incidents involving water systems, municipalities, hospitals, manufacturers, schools, and other organizations people depend on, that should get an executive's attention. You do not have to work in the same industry to understand the bigger message. The question is not whether your organization looks exactly like the one in the headline. The question is whether something similar could expose a weakness you have not taken the time to understand.

That is why I think every executive should stop and ask: If something happened tomorrow, would I know where we stand? Not where I hope we stand. Not where somebody told me we stand six months ago. Where do we actually stand?

That Is Really What SPARK Does.

SPARK is not there to take sides. I am not coming in to defend one department or criticize another. I am not trying to prove somebody right or somebody wrong. I am there to give leadership a clear set of eyes.

Here is what I found. Here is what looks good. Here is what concerns me. Here is what I think you should do about it.

Sometimes the answer may be simple. Maybe a policy needs to be reviewed. Maybe a plan exists but nobody has tested it. Maybe leadership thinks something is covered and the people doing the work know that it is not. Maybe too much depends on one person. Or maybe you are in much better shape than you thought.

Either way, you should know.

And if I do not know the answer, I will find the answer. I have been doing this long enough to know that nobody knows everything. What matters is knowing when to ask another question and when to bring in the right person to help answer it.

Stay Out of the News for the Wrong Reasons.

At the end of the day, part of what SPARK is trying to do is pretty simple. I want to help keep your organization out of the news for the wrong reasons.

I mean the kind of headline no executive wants to wake up to. The kind where everybody suddenly wants to know what happened, who knew what, why the organization was not prepared, and what leadership is going to do about it now.

If we can identify a problem before it becomes a headline, that is a win. If we can help you ask the right question before a regulator, a reporter, a board member, or a customer asks it for you, that is a win.

Doing something does not mean fixing everything tomorrow. It does not mean spending a fortune. It does not mean buying every new tool on the market. Sometimes doing something means starting with one conversation, one assessment, one policy, or one exercise.

Doing nothing is easy. Doing something takes leadership. And in today's world, I think knowing where you stand is part of the job.

Coming Next

More Questions Worth Asking.

Five Questions Every CEO Should Ask About Cybersecurity Readiness

A short executive checklist built around ownership, critical systems, testing, recovery, and accepted risk.

Where Is Your Disaster Recovery Plan—Right Now?

If the answer is “I think somebody in IT has it,” there is probably a larger question leadership needs to ask.

What Happens When the Person Who Knows Everything Is Not There?

A look at key-person dependency, undocumented knowledge, and why organizational resilience is often a people problem before it is a technology problem.

Not sure how your organization would answer these questions?

That is a good place to start.

START WITH SPARK