Proxurve Solutions
ServicesAboutExecutive QuestionsClient SupportSchedule a Conversation Indianapolis 317-664-7769 Lafayette 765-319-8869
The Proxurve Solutions building in Indianapolis
Home / Executive Questions

The questions executives actually ask us

Straight answers to the eight questions that come up most often, written for owners and executives rather than for technical staff.

These are real questions from real conversations. None of them require a follow up call to understand, and none of the answers are a sales pitch in disguise. If one of them is your question, the answer below is the same answer we would give you on the phone.

What should we do if our company's network has been hacked or breached?

Contain first, investigate second, and call someone before you start deleting things. Disconnect affected machines from the network but do not power them down, because volatile memory holds evidence that disappears when you do. Preserve logs. Stop anyone from wiping and rebuilding until somebody has looked.

Then get help. Our number is 317-664-7769. We handle ransomware attack restoration, and the first hours matter more than almost anything that follows. The most expensive breaches we have seen were not the most sophisticated ones. They were the ones where a well meaning person spent three days trying to fix it quietly.

Notification obligations may also apply depending on your industry and what data was involved. That clock often starts earlier than people expect.

How do I know if I have implemented the correct cybersecurity tools?

You cannot know from the purchase list. You can only know from testing. Nearly every organisation we assess has bought reasonable products. The gap is almost never what was bought. It is whether it was configured correctly, whether anyone is watching the alerts it produces, and whether anyone has ever tested that it does what it claims when something real happens.

The three questions worth asking your team this week: when did we last restore from a backup as a test rather than in an emergency, who receives the security alerts and what do they do with them, and what would happen if the person who set this up left tomorrow.

An independent assessment answers all three with evidence rather than assurance.

My IT team says we have cybersecurity measures in place, but how can I be sure?

By verifying independently, for the same reason you do not have employees audit their own accounts. This is not about doubting your people. A team that built and maintains an environment cannot see it fresh, and they are also unlikely to report that their own configuration is inadequate.

An outside review measures what is actually running against what the business needs, and produces something you can present to a board or an insurer. Occasionally the finding is that your team is doing well with too small a budget, and the recommendation is to fund them properly. We have delivered that finding more than once.

How can I help my IT staff learn more about cybersecurity?

Give them time, budget and someone senior to talk to. The most common failure we see is a capable person carrying security on top of a full support workload, with no path to keep current in a field that changes monthly.

Practical steps: fund a certification path, give them protected hours each month that are not interruptible, and put them in contact with engineers outside your organisation. We run proactive cybersecurity staff training and reporting, and a co managed arrangement where your person keeps ownership and gains a team behind them is often the strongest structure available to a mid sized business.

What if I am considering a change in IT providers?

Start by naming what is actually wrong, because it is not always the provider. Sometimes the problem is scope that was never agreed, or an internal expectation that was never communicated. A change that does not address the real cause reproduces the same frustration a year later with new logos on the invoice.

If a change is right, the things to check are: who owns your documentation, who holds your administrative credentials, what notice you owe, and how long a transition realistically takes. We will walk through all of that with you honestly, including the inconvenient parts, before you commit to anything.

Why do I need cybersecurity protection if I do not have data hackers would want?

Because most attacks are not targeted, and the thing being held hostage is usually your ability to operate rather than your data. Automated scanning finds reachable systems without caring who owns them. Ransomware does not need your information to be valuable to anyone else. It only needs it to be valuable to you.

There is also a second exposure most owners underestimate. You hold other people's information: client records, employee payroll, banking details, contracts. That obligation does not scale down with your headcount, and neither does the reputational cost of losing it.

Should the CEO or CFO be involved in technology decisions at all?

In the decisions about risk and spend, yes. In the implementation, no. The reason is that the consequences land on the balance sheet and on the leadership team, not in the server room. Someone has to decide what level of risk the business is willing to carry and what it is worth paying to reduce it, and that is not a technical judgement.

This is the whole reason our first conversation is with the CEO or CFO rather than with the IT contact. We are not trying to go over anyone's head. We are trying to have the risk conversation with the person who owns the risk.

What size of company do you usually work with?

Roughly fifteen to two hundred and fifty staff, with revenues between five and twenty million. That is where our model fits best. Below that range the economics rarely work for either side, and we would rather say so than sell something that does not fit.

The other half of the fit is attitude. Our best clients see technology as a way to move the business forward and want to work toward measurable return. If technology is regarded purely as a cost to be minimised, we are probably not the right firm.

Still your question is not here

Ask it directly.

Thirty minutes on Teams, with the president, the vice president and a senior consultant. We answer what you ask and give you our initial read on your situation. Nothing is presented and nothing is sold.

Schedule a Conversation
The Proxurve Solutions office at 4181 E 96th Street, Indianapolis