IT Security for Companies — Executive Behaviors

IT Security for Companies

IT Security for Companies — Executive Behaviors

These questions focus on safe executive behaviour in everyday company IT security. Test your knowledge on risk reduction, secure workflows, and security culture.

Anleitung: Choose the best answer. When you click, the correct answer appears in the sentence.

Score: 0 / 25

Interaktiver Vokabel- & Verhaltenstest (25 Fragen zu Executive IT Security)

1. What is the best executive habit to reduce cyber risk quickly?
The best answer is: ______

a) Lead by example: follow the same security rules as everyone else.
b) Skip security steps because your time is valuable.
[Welche Executive-Gewohnheit reduziert Cyber-Risiko am schnellsten?]

2. What is the safest approach to passwords at work?
The best answer is: ______

a) Reuse one strong password for all company systems.
b) Use a password manager and unique passwords.
[Was ist der sicherste Umgang mit Passwörtern im Unternehmen?]

3. Which is the safest response to a suspicious invoice email at work?
The best answer is: ______

a) Open the attachment to see what it is.
b) Verify using a known contact method before acting.
[Welche Reaktion ist am sichersten bei einer verdächtigen Rechnungs-E-Mail?]

4. What is the best rule for approving payments or bank detail changes?
The best answer is: ______

a) Approve immediately if it’s urgent.
b) Use a 2-person check and verify out-of-band.
[Welche Regel ist am besten für Zahlungen oder geänderte Bankdaten?]

5. Why should executives avoid bypassing MFA (2FA / Multi-Factor Authentication) prompts?
The best answer is: ______

a) Because MFA stops many account-takeover attacks.
b) Because it makes email faster.
[Warum sollten Executives MFA-(2FA)-Abfragen nicht umgehen?]

6. What is the risk of using personal email for company files?
The best answer is: ______

a) It improves compliance automatically.
b) It increases leakage risk and breaks control/auditing.
[Was ist das Risiko, private E-Mail für Firmendateien zu nutzen?]

7. What is a safe habit for executives when traveling?
The best answer is: ______

a) Disable screen lock to work faster.
b) Use VPN and avoid sensitive work on unknown Wi-Fi.
[Welche sichere Gewohnheit gilt für Executives auf Reisen?]

8. What is the best behavior around USB sticks in the office?
The best answer is: ______

a) Treat unknown USB sticks as unsafe; don’t plug them in.
b) Plug them in quickly to identify the owner.
[Was ist das beste Verhalten bei USB-Sticks im Büro?]

9. Which is the best policy for company laptops and phones?
The best answer is: ______

a) Allow shared logins to save time.
b) Use encryption, screen lock, and remote wipe.
[Welche Richtlinie ist am besten für Firmen-Laptops und -Handys?]

10. What is the safest approach to admin privileges for employees?
The best answer is: ______

a) Give admin rights to anyone who asks.
b) Use least privilege: only what’s needed, when needed.
[Was ist der sicherste Umgang mit Admin-Rechten für Mitarbeiter?]

11. Why is it risky to allow password sharing between employees?
The best answer is: ______

a) Because it improves accountability.
b) Because you lose accountability and increase breach impact.
[Warum ist Passwort-Teilen zwischen Mitarbeitern riskant?]

12. What is the risk of delaying security updates company-wide?
The best answer is: ______

a) It increases battery life.
b) It leaves known vulnerabilities exploitable.
[Was ist das Risiko, Sicherheitsupdates im Unternehmen zu verzögern?]

13. What is the best executive message about reporting mistakes?
The best answer is: ______

a) Encourage fast reporting without blame to reduce damage.
b) Punish every mistake to create fear.
[Welche Executive-Botschaft ist am besten fürs Melden von Fehlern?]

14. What is a safe practice for executive assistants handling calendars and email?
The best answer is: ______

a) Turn off MFA to avoid interruptions.
b) Use MFA and separate accounts with clear permissions.
[Welche sichere Praxis gilt für Assistenz bei Kalender und E-Mail?]

15. Which is the safest behavior for sharing sensitive documents internally?
The best answer is: ______

a) Send them as email attachments to many people.
b) Use controlled access links with permissions and expiry.
[Welche Handlung ist am sichersten beim Teilen sensibler Dokumente intern?]

16. What is the safest approach to onboarding new employees?
The best answer is: ______

a) Let them use personal devices with no controls.
b) Provide role-based access and security basics training.
[Was ist der sicherste Ansatz beim Onboarding neuer Mitarbeiter?]

17. Why should executives avoid approving requests under pressure?
The best answer is: ______

a) Because it improves teamwork.
b) Because urgency is a common social engineering tactic.
[Warum sollten Executives Anfragen unter Druck nicht einfach freigeben?]

18. What is the main risk of using shared meeting links publicly?
The best answer is: ______

a) It can enable unauthorized access and data leakage.
b) It reduces calendar invites.
[Was ist das Hauptrisiko, Meeting-Links öffentlich zu teilen?]

19. What is a safe rule for executives about confidential information in chats?
The best answer is: ______

a) Send passwords in chat because it’s encrypted.
b) Avoid sensitive data in chat; use approved secure channels.
[Welche sichere Regel gilt für vertrauliche Infos in Chats?]

20. What is the best executive habit for security culture?
The best answer is: ______

a) Ignore training and hope for the best.
b) Ask for simple metrics and follow up regularly.
[Welche Executive-Gewohnheit fördert Sicherheitskultur am besten?]

21. Which is safest when employees work from home?
The best answer is: ______

a) Use managed devices, VPN, and secure Wi-Fi practices.
b) Allow work on any device with no rules.
[Was ist am sichersten, wenn Mitarbeiter im Homeoffice arbeiten?]

22. What is the safest approach to employee offboarding?
The best answer is: ______

a) Keep access for a few months just in case.
b) Remove access promptly and recover company devices.
[Was ist der sicherste Ansatz beim Offboarding?]

23. Why is it risky to allow unapproved software ("shadow IT")?
The best answer is: ______

a) Because it reduces costs with no downside.
b) Because it can create unknown vulnerabilities and data leaks.
[Warum ist unfreigegebene Software ("Shadow IT") riskant?]

24. What is the main risk of ignoring phishing simulations or training?
The best answer is: ______

a) Because staff remain vulnerable to common attacks.
b) Because it improves email speed.
[Was ist das Hauptrisiko, Phishing-Training oder Simulationen zu ignorieren?]

25. What is a safe executive rule for “exceptions” to security?
The best answer is: ______

a) Remove controls permanently for VIPs.
b) Keep exceptions rare, documented, time-limited, and approved.
[Welche sichere Executive-Regel gilt für „Ausnahmen“ von Security?]

Zusammenfassung: IT Security & Executive Behaviors

Erfolgreiche Informationssicherheit im Unternehmen beginnt beim Management. Führungskräfte prägen durch ihr tägliches Verhalten die Sicherheitskultur (security culture) maßgeblich:

1. Vorbildfunktion & Richtlinien

Das Einhalten von Passwörtern über Password Manager, die Nutzung von Multi-Faktor-Authentifizierung (MFA) ohne Ausnahmen sowie das kritische Prüfen von Rechnungs- oder Zahlungsänderungen (out-of-band verification) schützen das Unternehmen vor gravierenden Cyber-Angriffen.

2. Reaktionssicherheit

Fehler im Alltag schnell und ohne Angst vor Bestrafung zu melden, minimiert den potenziellen Schaden von Sicherheitsvorfällen erheblich.

Score: 0 / 25