Logo featuring the text 'Data Protection Matters' with a shield and circuit design.

10 Hard Questions to ask IT — 2026 edition

Business Resilience stakeholders and their IT teams are often disconnected because they’re not grasping how their IT strategies are creating or affecting their risk posture, often because they don’t share taxonomy or metrics.

Here’s 10 hard questions from a workshop I ran at MIT and am paring down for customer events, roadshows, CABs, PACs, SKOs, and offsites.

What would you add to get BC/RM and IT-DR/Cyber on the same page?

video transcript

Recently finished a 2-hour workshop called “10 Hard Questions to ask IT.” I spend half my time with data protection and cyber resilience vendors and service providers, and the other half with resilience leaders who focus on business continuity, risk management, emergency management, as well as those who also care about IT disaster recovery and cyber resilience. Sometimes those two groups aren’t using the same language, they’re not using the same methodologies, and part of that is because they’re not thinking about problems the same way. So when I speak with those folks, I’ve cultivated at least 10 hard questions for them to ask their IT teams to help discover where their IT resilience strategies may need to be reconsidered. Subsets of these topics will likely be fodder for customer roadshows, customer advisory boards, partner councils, internal team offsites, and SKOs. Here they are:

  1. Is our cyber resilience strategy too focused on data encryption? YES, if we’re more focused on hoodies and bitcoin than we are identity breaches, errors from agentic AI, and cloud disruptions like AWS or CrowdStrike events.
  2. What is our IT recovery-at-scale assessment? Let’s talk about the testing and metrics that matter.
  3. Is our hypervisor/hyperscale strategy creating additional risk? To Broadcom or not to Broadcom, that really is an impactful question.
  4. Are we protecting our SaaS’es? If you rely on any IT resource, even a natively durable one, then you have to back it up — period.
  5. Where are third parties helping our resilience? I’m a fan of managed services; let’s talk about why.
  6. Where are third parties endangering our resilience? When you outsource, you no longer affect the tech stacks nor the human policies. But when they are down, you are down.
  7. Which disruptions are we least prepared for? That’s a hard question, but I have over 500 opinions on the answer and you might be surprised what folks are really worried about.
  8. How aligned are our teams across the org’s strategies? I do not recommend a single org chart for all resilience scenarios, but that does mean that you have to do more to ensure alignment for preparedness and coordination when the bad thing inevitably comes.
  9. Where is AI affecting our resilience strategies? I could make another top ten list just on the intersections of AI and cyber resilience, but you’ll have to wait until DPM’s AI-Enhanced Resilience research comes out of embargo before I do. That said, I do have four conversation starters on this one.
  10. Are we over-confident in our resilience? (yes, we are) And I have the data to prove it and some homework to try to rectify it.

So, those are my favorite top ten for now — what other hard questions for IT do you have?

Leave your thoughts on the LinkedIn article.

Discover more from Data Protection Matters

Subscribe now to keep reading and get access to the full archive.

Continue reading