Start with business dependency. You do not need to personally catalogue every device. Ask the IT owner for a current inventory and its gaps. You need a defensible view of the systems, people, vendors, and sites that would interrupt orders, production, shipping, payroll, cash collection, or month-end close.
Days 1–30: establish the facts
- Name the business systems that stop revenue, production, fulfillment, or close.
- Identify the executive, business owner, and technical owner for each critical system.
- Request the current IT budget, provider agreement, project list, asset lifecycle plan, and cyber-insurance questionnaire.
- Ask where critical knowledge lives: internal staff, a provider, a consultant, or an undocumented workaround.
Days 31–60: test the evidence
- For each critical system, ask for the last recovery test, its result, its owner, and its actual time to restore.
- Review current vendor access, privileged accounts, and what happens when a person leaves.
- Compare planned technology spend with open renewal, replacement, and implementation commitments.
- Confirm the status of ERP integrations, manual imports, data ownership, and reconciliations.
Days 61–90: turn findings into decisions
| Decision | Evidence to request | Useful output |
|---|---|---|
| Fund recovery | Restore-test record, RTO/RPO, system owner | Prioritized recovery plan |
| Change provider | Service history, access inventory, transition plan | Risk-managed transition decision |
| Approve ERP work | Dependencies, data-quality baseline, cutover plan | Go, pause, or phase decision |
| Set the budget | Run-rate, renewals, lifecycle, project estimates | 12-month investment roadmap |
The goal is not a technical audit. It is a short decision file that makes ownership, evidence, timing, and financial exposure visible.
Ask the team for a decision file
The CFO sponsors this review; the people who run the work supply the evidence. Have the operations lead name the processes that cannot stop, the controller identify close and cash dependencies, and the IT lead or provider map the supporting systems. Ask each owner to sign off on what is known, what has not been tested, and what needs a decision.
| Owner | What to bring | CFO decision |
|---|---|---|
| Operations | Critical production steps, tolerable interruption, manual capacity | Which process gets recovery priority? |
| Controller | ERP reconciliations, close workarounds, cash and order exposure | What financial control needs repair? |
| IT lead or provider | System inventory, dependencies, restore results, access exceptions | Which gap needs funding or escalation? |
| Broker and counsel | Policy terms, application answers, notice requirements | What exposure remains with the company? |
Include insurance in the review
Ask the broker to walk through the current cyber policy with the controller, operations lead, and IT owner. Record limits, retention, business-interruption waiting period, covered loss categories, exclusions, notice deadlines, and whether a provider or plant-control incident would meet the policy wording. Have the IT owner verify that the controls described in the application match current practice. Coverage is a financing tool, not proof that a plant can recover.
Decision record: one page per material gap with owner, business effect, evidence date, cost range, decision, and revisit date. The CFO accounts for the exposure and allocates capital; the responsible team executes the fix.