There is one situation more common than any other: the company depends on technology for everything, and nobody could name its three main risks. It is not that the answer is hard: it is that nobody knows what to ask. This piece exists for that.

Any company's technology risk fits into eight areas. You do not need to know what a firewall is to walk through them: it is enough to answer one question per area honestly.

  1. Governance. Does anyone have the job of looking at technology as a whole, or is every decision made wherever it comes up?
  2. Systems. Is there a list of the systems the company uses and which ones it truly depends on?
  3. Vendors. Do you know which vendors can get into your systems or touch your data?
  4. Access. When someone leaves the company, does anyone check that their access gets closed?
  5. Data. Do you know what personal data you hold, where, and who can see it?
  6. Cybersecurity. If an attack encrypted your systems tomorrow, do you know how long recovery would take?
  7. Change. When something changes in your technology, is it recorded anywhere, or do you find out "by asking around"?
  8. Artificial intelligence. Do you know where in your company AI is already being used, even if nobody approved it?

Every "no" and every "I don't know" is valuable information: it points at exactly where your exposure sits, with no hundred-page report required. And three "I don't know" answers in a row in the same area say more than any audit you have not yet done.

You do not need to be technical to know your technology risk. You need to answer simple questions honestly, and someone to ask them again every so often.

To make it practical we have prepared a downloadable two-page guide. The first page sums up the essentials: what technology risk is, the eight areas where it lives and the six terms worth knowing. The second is the self-assessment: the eight areas unfolded into 24 yes-or-no questions that a managing director can answer in about twenty minutes without technical help, with a guide to reading the result at the end. Print it, answer it with whoever runs your systems, and keep the sheet: repeating it in six months will tell you whether you are improving or just accumulating luck.

If the result leaves you feeling that the base map is missing, that list of systems everything else depends on is where to start: The inventory you don't have.