Skip to content

Is Your Current IT Provider Actually Protecting You?

IT Management

You already have an IT provider. Every renewal, someone tells you security is handled. The dashboard looks green, the invoice gets paid, and nothing has gone wrong yet. None of that actually tells you whether something would be prevented if it started tomorrow, or whether you would just find out about it after the fact.

Most business owners cannot evaluate their own IT provider from the outside. You are not going to read endpoint detection logs or audit firewall rules yourself, and you should not have to. What you can do is ask specific, checkable questions and pay attention to whether the answers are concrete or vague. A provider who is actually doing the work can answer these without hesitation. A provider who is not will reach for reassurance instead of detail.

None of this is about catching your provider doing something wrong. Most are doing their job reasonably well most of the time. It is about the gap between a policy that exists on paper and a policy that is actually enforced day to day, because that gap is where real incidents start, and it is invisible from where you sit unless you go looking for it.

Here is what to ask, and why each answer matters.

Ask to see the actual MFA exclusion list

Almost every provider will tell you multi-factor authentication is turned on across your company. That can be entirely true and still leave a real hole. MFA rollouts almost always come with an exclusion list: an executive who found the prompts annoying and got carved out, a service account that predates the policy, a legacy sign-in protocol nobody turned off because one line-of-business app still needs it. Each exclusion looks small on its own. Together, they are usually where an actual account compromise starts, because that is where the door was left unlocked.

Do not ask whether MFA is enabled. Ask to see the exclusion list itself, by account, not a summary that says “a few legacy accounts remain.” If your provider cannot produce that list quickly, either it does not exist as a tracked set and nobody has been watching it, or it exists and nobody wants to show it to you. Neither is a good sign.

Ask for a response time commitment in writing

Ask your provider directly for a response time commitment, in writing, and ask whether it changes based on how many people are affected. A vague answer like “we get to things quickly” will not hold up on the day your whole office is down.

At TTS Cyber, clients under a signed service agreement get a one-hour first-response target when the whole company is down or disrupted, two hours when three or more people cannot work or are severely degraded, and four hours when it affects a single person. The first category is covered around the clock; the other two run during business hours. Those are response targets, meaning how long before someone acknowledges the problem, not how long the actual fix takes, and that distinction matters when you compare answers. That is also our own published target, not an industry norm. Most providers do not publish a number at all, which is itself worth noticing. If your provider has never given you one, ask for it. If they give you one, ask what happens when they miss it.

Ask when they last restored a backup, not whether one runs

Backups almost always show green. A backup job can complete successfully every night for years while quietly missing the files that matter, keeping too short a retention window, or never once having been proven to actually restore.

The only way to know a backup will work is to have pulled data back out of it. Ask when your provider last tested a restore for your business specifically, and ask what it looked like: what was restored, how long it took, and what they learned. “The backups are running” and “we restored this file set on this date in this amount of time” are very different answers. Only one of them tells you anything about whether you are actually protected.

Ask what monitoring covers, and when

Ask whether monitoring and alerting run continuously, including nights and weekends, or whether alerts sit in a queue until the next business morning. Ask who looks at an alert when it fires at 2 a.m., and what that person is authorized to do about it without waking you up first.

A lot of real incidents move fastest during the hours nobody is watching, and that is not a coincidence. A coverage gap between Friday evening and Monday morning is worth knowing about before it matters, not after. Ask specifically whether that gap is filled by a person, an automated alert that waits for a human on Monday, or nothing at all.

For what it is worth, here is our own answer to that question. TTS Cyber’s network monitoring runs Monday to Friday, 8:00 AM to 5:00 PM Eastern. First response is a separate commitment: under a signed service agreement, a whole-company outage carries a one-hour first-response target around the clock. Watching for a problem and answering when one is reported are two different things, and a provider should tell you plainly which one they are offering, and for which hours.

Ask whether an outside assessment would make them nervous

A provider grading its own work has an obvious incentive problem, even when everyone involved is honest. It is hard to notice your own blind spots, and harder to volunteer them to a client who is paying you to have none.

An independent assessment sidesteps that entirely. TTS Cyber runs a fixed-price, $349 security analysis for businesses in Columbus and beyond that does not require buying anything, and the findings belong to your business either way. Use it to confirm your current setup is solid, or to see the gaps in it. Either outcome is useful. If nobody outside your current provider has ever looked at your environment, that is worth fixing before anything else on this list.

A short version

If you only have time for one pass, ask your current provider these five questions:

  1. Can we see the actual MFA exclusion list, not a summary?
  2. What is your written response time commitment, and does it change by severity?
  3. When did you last test a restore from our backups, and what did it involve?
  4. Does monitoring run continuously, including nights and weekends?
  5. Would you be comfortable with an independent assessment of what you have set up?

The last question tells you the most. A provider confident in their own work will not mind another set of eyes on it.

If you want that outside look, tell us what you are running today and we will walk you through the $349 security analysis. If it confirms your current provider already has this covered, that is a useful answer too.

Questions this post answers

Our IT provider says MFA is turned on. What should we ask to check?

Ask to see the MFA exclusion list itself, by account. MFA can be on and still leave a real hole, because rollouts almost always come with exclusions. Examples include an executive who found the prompts annoying, a service account that predates the policy, or a legacy sign-in protocol one app still needs. Together, those exclusions are usually where an account compromise starts. If your provider cannot produce the list quickly, either nobody has been watching it or nobody wants to show it. Neither is a good sign.

How can we tell if our business backups would actually restore?

The only way to know a backup will work is to have pulled data back out of it. Backups almost always show green. A backup job can complete successfully every night for years while quietly missing the files that matter, or without ever being proven to restore. Ask your IT provider when they last tested a restore for your business specifically. Ask what was restored, how long it took, and what they learned. Hearing that “the backups are running” does not tell you whether you are actually protected.

What should we ask our IT provider about response times?

Ask for a response time commitment in writing, and ask whether it changes with how many people are affected. For comparison, TTS Cyber publishes its own first-response targets for clients under a signed service agreement. The target is one hour, around the clock, when the whole company is down or disrupted. During business hours, it is two hours when three or more people cannot work or are severely degraded, and four hours when one person is affected. These targets measure only how long before someone acknowledges the problem.

More on this topic

Get Artificially Informed

A weekly read on what actually happened in AI and cybersecurity, written for people who run businesses rather than data centers. One email a week.

No spam, and we never sell your address. Unsubscribe in one click.

Ready to talk to someone?

Tell us what you are running today and what is not working. We will tell you how we would approach it.

Security Analysis

Find out where you actually stand.

Most businesses do not discover a gap until something goes wrong. This is a fixed-scope analysis of your environment, run independently, so you get an answer rather than an opinion.

What the analysis covers