The Single Best Risk Assessment Interview Question

There is one question that I ask in every risk assessment interview that time and time again has yielded the best results.

It is a question that goes to the heart of understanding how the business works, not just how the IT department operates.

It is a question that IT and Security Pros get to use on a regular basis as a part of business-as-usual conversations with employees across the business.

But this question should not be asked as a conversation starter. I use trust and rapport building to prep the interviewee for this question.

Because if you don’t, you’ll get the unhelpful answer, “No.”

If I have done my job well and the interviewee feels safe talking to me and doesn’t think I’m out to get them, they will open up in ways that surprise even the IT and Security Managers in the room.

The single best question I use to identify risks during a risk assessment is always my closing question.

“Are there any security risks we haven’t yet discussed that you think I should be aware of as a part of this assessment?”

I get very interesting answers.

“Although the in-store credit application is now online, we still receive quite a few submissions via fax. We’re trying to phase this out, but we have a file cabinet full of older credit applications that we are not sure what to do with.” As the Security Manager looks at me with a glint in her eye that says, “This is the first I’ve heard about this.”


“When I’m visiting a patient at their home, I like to keep my notes on a notepad as I’m working and then transfer them to the computer later in the afternoon or evening when my home visits are done.” Which is when I ask, “Where do you store these notes and do you ever dispose of them?”

The organization needs to have these conversations to become aware of these issues. And as an IT or Security Pro, you get to lead them.

Building trust and rapport is crucial and is why this question doesn’t work well in a questionnaire.

