Skip to content

Leadership1 publisher3 min readPublished

IP Services' CEO would audit a security program by asking when it last restored from backup

Scott Alldridge argues that the standard controls all exist on paper and go untested under pressure. His replacement audit is four operational questions. Three of them can only be answered by running the test.

The Board Room · Leadership desk

Photograph accompanying IP Services' CEO would audit a security program by asking when it last restored from backup
Photo: apple.com

What happened

  • Scott Alldridge, chief executive of IP Services, wrote in a Forbes Technology Council column that most organizations already own firewalls, endpoint protection, MFA, backups, scanners, awareness training and response plans.
  • He proposes judging a program by four questions instead: the date of the last restore, whether ransomware can reach a production server from one laptop, over-privileged accounts, and readiness at 2 a.m. on a Sunday.
  • The column locates the "tip of the spear" in the small set of capabilities standing between an initial compromise and a major business event, and recommends focusing on eight areas.
  • In one assessment he describes, a significant amount of confidential data was sitting in places the organization had not counted as part of its primary risk profile.
  • He argues that a count like 4,000 vulnerabilities says very little on its own, and that prioritization should weigh exposure, exploitability, business impact and system relationships.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • constraint If operational maturity caps security maturity, the next control purchase cannot repair change management or configuration drift. The work lands on an IT operations budget that no security committee controls.
  • decision Accepting these questions commits a CIO to scheduling a restore and a path test, and those hours come out of the same team already running the tool rollout.
  • exposure A board that treats the control inventory as its answer is accepting an untested claim. The first real measurement of the restore happens during the incident.
  • precedent Putting AI agents inside the identity inventory sets the expectation that agent scope becomes an audited control rather than a project detail.

The gap those questions open is between a control that exists and a control that has been exercised. A firewall rule can be confirmed from a change record. A restore cannot be confirmed by anything except a restore. That asymmetry is why the tool inventory is the artefact that travels upward: it is auditable from paperwork, and it is available in any quarter you ask for it [4].

The arithmetic inside Alldridge's own piece is the useful part. The list of what most organizations already own runs to seven line items [4][5]. The audit he proposes runs to four questions [7][8]. Three of the four can only be answered by performing the test, and only the question about over-privileged accounts can be settled from records an organization already holds [19].

On segmentation he reports a specific failure mode. Firewalls, VLANs and policies all read correctly, and everyone involved believed the controls were in place, until the actual communication paths were tested and systems were found talking in ways nobody intended [13]. "The documentation looked secure, but the environment told a different story," Alldridge wrote [14].

The conflict of interest is worth stating: an IT services chief executive telling buyers their controls are untested is describing a market. The answer is in where his argument sends the money. He names poor change management, configuration drift and unmanaged systems as the things quietly undermining security, and writes that "Security maturity cannot sustainably exceed operational maturity" [16]. That points spending at operational discipline. On most security budgets that is the least fundable item.

The evidence has a clear limit. The assessments in the column are described without naming an organization, a date, or a count, and there is no measured population behind any of it [18]. So this is a hypothesis about which failures matter, resting on one practitioner's casework. The four questions are testable whether or not his casework is representative.

The tradeoff he does not price is time. A restore rehearsal and a 2 a.m. drill draw on the same operations hours as the next tool rollout, and the restore consumes production capacity to prove a negative. That makes the split between this quarter and this decade fairly sharp. The privileged-account review and a single restore test fit in a quarter. Mapping actual communication paths across an estate is the multi-quarter programme, and it is the one that overturned the documentation in his account [13].

One item on his list is newer than the rest. AI agents appear in the inventory he wants built, alongside users, privileged accounts and service accounts [10], and again in behavioral detection, where he asks whether an agent is operating outside its intended scope [17]. They appear nowhere in the seven controls he opens with [4].

What to watch

  • Whether the three capabilities beyond behavioral detection in Alldridge's list of eight address measurement or add further controls.
  • Whether any organization publishes restore-test or path-test results. Published results would turn this casework into a number.
  • Whether agent scope and agent identity start appearing in audit and insurance questionnaires, where controls become procurement requirements.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories