Policies & Planning 7 min read

Is Your IT Guy Actually Keeping You Safe?

I have done security assessments for small businesses where the MSP was charging $2,000 a month and hadn't enabled MFA on the email accounts. Here are the 10 questions to ask your IT provider β€” plus what a good answer sounds like.

The uncomfortable truth

Most MSPs (Managed Service Providers) are honest, competent, and genuinely care about their clients. But here is the thing: their incentives are not perfectly aligned with yours. They get paid to keep things running, not necessarily to keep things secure. Security costs money and causes friction β€” two things that make client relationships harder. If you never ask about security, some MSPs will never bring it up.

I am not saying your IT provider is bad. I am saying you should verify. Here is how.

The 10 Questions

1. "Do we have MFA turned on for email?"

This is the single most important question. Email is the master key to your business β€” if an attacker gets in, they can reset passwords on everything else. A good answer: "Yes, it is enforced for all users. We use [authenticator apps / hardware keys / Duo]." A bad answer: "We discussed it but didn't want to inconvenience people."

2. "When was our last backup test restore?"

A backup that has not been tested is not a backup β€” it is a wish. A good answer: "Three months ago. Here is the log showing what we restored and how long it took." A bad answer: "The backup software says everything is fine." (Backup software always says everything is fine. That is why you test.)

3. "Do we have a list of every employee and vendor with access to our systems?"

Former employees, ex-interns, old contractors β€” the average small business has 3-5 people with active access who should not. A good answer: "Yes, here it is. We review it quarterly." A bad answer: "Probably β€” we can pull something together."

4. "When was our last security risk assessment?"

A good answer: "Six months ago. Here is what we found and what we fixed." A bad answer: "We do not really do formal assessments."

5. "What happens if you get hit with ransomware?"

Your MSP is a prime target β€” they manage dozens of businesses, making them a force multiplier for attackers. A good answer: "We have our own EDR, separate backups, and an incident response plan. Here is how we would contain it and protect your data." A bad answer: "That would never happen to us." (I actually heard this once. I fired them on the client's behalf.)

6. "Are our computers set to update automatically?"

A good answer: "Yes, security patches install within 24 hours. We have a test group for feature updates." A bad answer: "We handle updates manually." (Manual updates means they will not happen consistently.)

7. "Do we have a written incident response plan?"

A good answer: "Yes. Here it is. It covers who to call, in what order, and what to do first." A bad answer: "We would handle it if something happens."

8. "What antivirus / EDR are we running?"

A good answer: "[Bitdefender / CrowdStrike / Sophos / Defender for Business] with EDR capabilities." A bad answer: "The free one that came with the computer." Or worse: silence.

9. "Do you have cyber insurance that covers our data?"

If your MSP causes a breach, their insurance should cover the damage β€” not yours. A good answer: "Yes, here is our certificate of insurance." A bad answer: "We are looking into it." (They have been "looking into it" for three years.)

10. "Can I see our admin account list?"

This is the panic test. If they hesitate or push back on this request, something is wrong. A good answer: "Here you go. Let me walk you through who each one is." A bad answer: Any form of resistance. You own the systems. You should be able to see who has access.

How to Have This Conversation Without Being a Jerk

Do not send these 10 questions in an email out of nowhere. That reads as aggressive and accusatory. Instead, schedule a quarterly review call (which you should be having anyway) and frame it like this:

"Hey, our insurance company asked us to verify a few things about our security setup. Can we go through this list together on our next call? I want to make sure I can answer their questions accurately."

Blaming the insurance company is the universal excuse for awkward security conversations. Use it. It works.

Red Flags That Mean "Start Looking for a New MSP"

  • They cannot answer questions 1-3 immediately. These are basic operational questions. If they do not know, nobody is watching.
  • They get defensive. A good MSP welcomes scrutiny β€” it proves they are doing their job.
  • They have never done a backup test restore. Not once. Ever. Run.
  • They discourage you from enabling MFA because "users find it annoying." This is not a technical opinion. It is negligence.
  • They charge extra for security basics. MFA setup, backup testing, and access reviews are not premium services. They are table stakes.

What a Good MSP Relationship Looks Like

The best MSP relationships I have seen look like this: quarterly review calls with a simple agenda. The MSP comes prepared with a one-page report β€” patching status, backup test results, access review, any security incidents. It takes 15 minutes. Both sides know what is happening. Trust is built on transparency, not assumption.

If your MSP cannot provide this, they are not providing security. They are providing tech support with a higher price tag.