GovernanceSMEsDigital assets

Digital assets: 25 questions for business leaders

Your data, tools, brand and accounts: what are they worth if you lose access tomorrow? 25 questions for business leaders who want to know where they stand.

Hakim Djelili7 min read

When people talk about “assets”, business leaders think of property, machinery and patents. Yet in 80% of French SMEs, the company's real value now lies in its digital assets: customer data, intellectual property, online accounts, access to business tools and online reputation. For most of them, these assets are protected, at best, by a password in a shared Excel file.

What this covers

Your digital assets in 5 categories

Data

Customers, employees, R&D, finance

The asset attackers target most

Identity

Accounts, domains, trademarks

Losing it can lock you out of your own business

Tools

Software, cloud, SaaS, access

Blocked tools mean production stops

Reputation

Reviews, online presence, communications

Recovery takes 6 to 18 months after a crisis

Relationships

Suppliers, partners, bank

A preferred route for indirect attacks

Section 1: 5 questions

Data: what do you have, where is it and who can access it?

  • 1. Can you list the 3 categories of data most critical to your business in 5 minutes?
  • 2. Do you know where this data is physically stored—in the cloud, a data centre or a local NAS—and in which country?
  • 3. Do you have an up-to-date inventory of who can read, modify and delete each category of data?
  • 4. Are your backups tested through restoration every quarter and stored offline or immutably?
  • 5. When a key employee leaves, is their access removed within 24 hours with an auditable record?

Section 2: 5 questions

Identity: who owns what in your name?

  • 6. Is your company's domain name registered to the company itself rather than a former provider?
  • 7. Do all your Google, Microsoft 365 and social media accounts have at least 2 named internal administrators?
  • 8. Is your trademark registered with INPI in the classes that correspond to your business?
  • 9. Is multi-factor authentication (MFA) enabled on 100% of your critical administrator accounts?
  • 10. Do you have a company password vault—not a shared Excel file or a sticky note on a screen?

Section 3: 5 questions

Tools: what happens if one of them fails?

  • 11. Can you list your 5 critical business applications, and do you know how many days of downtime each could cause?
  • 12. Do you have a written business continuity plan that has been tested at least once in the past 12 months?
  • 13. Do your workstations and servers have EDR protection beyond traditional antivirus?
  • 14. Are critical security patches applied across all your systems within 14 days?
  • 15. Do you have an emergency communication channel if your primary email system is blocked?

Section 4: 5 questions

Reputation: can your image withstand a crisis?

  • 16. Do you have a crisis communication procedure ready, specifying who speaks to the media, customers and employees?
  • 17. Are your Google reviews and online presence monitored every month?
  • 18. Do you have a customer communication kit for a data breach, including a template letter, FAQ and CNIL process?
  • 19. Do your employees know not to comment publicly on an incident without approval?
  • 20. Have you identified the 5 priority stakeholders to inform after a major incident, such as your bank, insurer and key customers?

Section 5: 5 questions

Relationships: are your third parties a risk or a strength?

  • 21. Have you assessed the cybersecurity posture of your 5 critical IT and SaaS suppliers in the past 12 months?
  • 22. Do your supplier contracts include clauses requiring incident notification within 48 hours and ensuring reversibility?
  • 23. Do your accountant, bank and insurer know who your cybersecurity contact is?
  • 24. Do you have cyber insurance covering ransomware, payment fraud and liability?
  • 25. If an attack occurs, do you know who to call within the first hour—your internal team, an external partner and the authorities?

Your score

How to interpret your score out of 25

< 10

Digital assets highly exposed

Launch an emergency plan within a month

10 to 18

Average posture

Define and track an improvement roadmap

19 to 25

Strong posture

Have it confirmed through an independent audit

What next?

The 4-part action plan

  1. Week 1

    Map your digital assets

    List the 3 critical data categories, administrator accounts and business tools on a single page.

  2. Weeks 2 to 4

    Secure the fundamentals

    MFA everywhere, immutable backups, EDR and a password vault. These 4 measures remove 80% of the risk.

  3. Month 2

    Build the critical procedures

    Business continuity, crisis communication and emergency contacts. Test them at least once.

  4. Month 3

    Commission an independent audit

    An organisational audit or targeted penetration test to confirm that your controls can withstand a real attacker.

Need a second opinion?

Let's talk for 30 minutes — no commitment

A direct conversation with a senior consultant to frame your cybersecurity priorities and clarify your obligations.

Book a call