HomeBlog5 Shocking Questions to Ask Before Hiring a Cybersecurity Provider
All PostsSmall Business Cybersecurity Basics

5 Shocking Questions to Ask Before Hiring a Cybersecurity Provider

Kevin MabryJuly 20, 2026
small business cybersecuritymanaged security service providercybersecurity for law firmsdata breach preventionIT vs cybersecuritybusiness continuity planningcyber risk management
5 Shocking Questions to Ask Before Hiring a Cybersecurity Provider

Don't let a generic IT guy leave your firm vulnerable. Learn the 5 critical questions to ask your cybersecurity provider to ensure your business stays secure.

I started Sentree Systems in 1999. Back then, "cybersecurity" wasn't even a word most small business owners used. We talked about "antivirus" and "firewalls," and if you had a tape drive that successfully backed up your data once a week, you were ahead of the curve. Fast forward twenty-six years, and the landscape has shifted from a nuisance to an existential threat. Today, I see small professional service firms—lawyers, accountants, and medical practitioners—getting hit with attacks that would have made headlines twenty years ago. According to the 2024 IBM Cost of a Data Breach Report, the average cost of a data breach has climbed to $4.88 million. For a firm with 20 employees, that isn't just a "bad quarter"—that is a business-ending event. In fact, various industry studies suggest that 60% of small businesses that suffer a major cyberattack go out of business within six months.

I’ve spent more than two decades in the trenches, and I’ve noticed a dangerous trend: small business owners are hiring "cybersecurity providers" who are actually just general IT guys with a new marketing brochure. They use big words and fancy acronyms to hide the fact that they aren't actually protecting you; they are just managing your printers and making sure your email works. Over the years, I’ve had to walk into firms that were mid-disaster—files encrypted, phones ringing with angry clients, and insurance companies refusing to pay out—only to find that their "security provider" was nowhere to be found. This post is designed to stop that from happening to you. These are the five shocking questions you must ask to strip away the vendor hype and find out if a provider is actually capable of keeping your firm alive.

Selecting a provider isn't about buying a product; it’s about entering a high-stakes partnership. You are essentially handing over the "keys to the kingdom" to an outside entity. If they drop the ball, your reputation, your client trust, and your personal bank account are the ones on the line. I’ve seen small firms lose decades of built-up trust in forty-eight hours because they assumed their provider was doing "security things" in the background. If you don't ask these questions, you are essentially flying blind through a thunderstorm, hoping the pilot knows how to use the radar. Let’s get into what you actually need to know before you sign another contract.

Key Takeaways:

  • The "IT vs. Security" Gap: Most general IT providers (MSPs) focus on uptime and convenience, while true cybersecurity providers (MSSPs) focus on risk and protection. They are not the same thing.
  • The Restoration Reality: Having a backup is useless if you haven't tested a "bare metal" restoration. If your provider can’t tell you your exact Recovery Time Objective (RTO), your data is at risk.
  • Compliance is Not Security: Being HIPAA compliant does not mean you are secure. Compliance is a legal baseline; security is an active defense.
  • Human Risk is the #1 Vector: According to the 2024 Verizon Data Breach Investigations Report (DBIR), 68% of breaches involve a non-malicious human element. If your provider isn't training your staff, they aren't protecting you.
  • The Liability Shift: A provider that won't sign a Business Associate Agreement (BAA) or provide an attestation of their own security controls is a liability, not an asset.
  • 24/7/365 is Non-Negotiable: Hackers don't work 9-to-5. If your "security" only monitors your network during business hours, you are wide open for 128 hours every week.

Question 1: Are You an IT Company That Does "Security on the Side," or a Security Firm?

In my 26 years, this is the biggest bait-and-switch in our industry. Most small businesses hire a Managed Service Provider (MSP). An MSP is great at making sure your internet is fast, your software is updated, and your new hires have laptops. But security is a different discipline. It’s like the difference between a general contractor who builds a house and a security consultant who designs a bank vault. They both know about buildings, but their priorities are polar opposites. An IT guy wants things to be "easy" for the user. A security guy knows that "easy" is often "vulnerable."

The Rise of the "Checkbox" Security Provider

I recently spoke with a law firm owner who was paying $2,000 a month for what he thought was "advanced cybersecurity." When I looked at the contract, the provider was literally just running the built-in Windows Defender and a basic firewall. There was no active monitoring, no threat hunting, and no log management. The provider was checking a box and hoping nothing happened. This is common because true security is expensive to run. It requires a Security Operations Center (SOC) staffed by people who do nothing but watch for anomalies. If your provider tells you they "do security," ask them how many full-time, dedicated security analysts they have on staff who do not handle help-desk tickets for printers.

Comparing MSP vs. MSSP Services

Feature Standard IT Provider (MSP) Cybersecurity Provider (MSSP)
Primary Goal Productivity and Uptime Risk Mitigation and Data Protection
Monitoring Checks if servers are "on" Analyzes behavior for "odd" activity
Staffing Generalists / Help Desk Certified Security Analysts (CISSP, CISM)
Response Reboots and patches Containment, Forensics, and Eradication

The Accenture State of Cybersecurity Resilience report found that 43% of all cyberattacks are now aimed specifically at small businesses because hackers know these firms use general IT providers who lack specialized security tools. If your provider doesn't have a separate "Security Stack" from their "Management Stack," you are just paying for a glorified help desk.

Question 2: Can You Prove—With Data—The Last Time You Performed a Full Bare-Metal Restoration?

Every provider will tell you "we back you up." I’ve heard it a thousand times. But in my experience, a backup is nothing more than a "maybe" until it has been successfully restored to different hardware. I remember a medical practice I helped back in 2018. They had a server failure and called their previous IT guy. He said, "Don't worry, we have backups." When he tried to restore them, the data was there, but it was corrupted because the backup software hadn't been updated in two years. That practice was down for 11 days. They lost over $140,000 in billable revenue because they couldn't see patients without their electronic health records.

The Difference Between Backups and Business Continuity

You shouldn't just ask if they take backups. You need to ask about their Recovery Time Objective (RTO) and Recovery Point Objective (RPO).

  • RTO: How long will it take to get us back online? (Is it 4 hours or 4 days?)
  • RPO: How much data are we willing to lose? (If we crash at 4:00 PM, is our last backup from 3:30 PM or yesterday at midnight?)

The "3-2-1-1-0" Rule

In the modern era of ransomware, the old "3-2-1" backup rule (3 copies, 2 media types, 1 offsite) isn't enough. Hackers now actively look for your backups and encrypt them first so you have to pay the ransom. I advocate for the 3-2-1-1-0 rule:

  • 3 copies of data.
  • 2 different media types.
  • 1 offsite copy.
  • 1 offline (air-gapped or immutable) copy that hackers cannot touch.
  • 0 errors after daily backup verification.

If your provider can't show you a log of "restoration tests"—not just "backup success" emails—they are gambling with your firm’s life. A "success" email just means the software ran; it doesn't mean the data is actually usable.

Question 3: How Do You Address the "Human Element" Beyond a Once-a-Year Training Video?

I’ve seen $50,000 firewalls defeated by a $15-an-hour receptionist clicking on a link that said "Invoice Attached." According to KnowBe4's 2024 Phishing Industry Benchmarking Report, approximately 30% of users in small organizations will click on a phishing link if they haven't had recent training. This is where most providers fail. They treat security as a technical problem when it is actually a human behavior problem.

The Failure of Annual Training

If your provider’s plan for your staff is to make them watch a 20-minute video every January, you are not protected. Cybersecurity awareness is a muscle; if you don't exercise it, it withers. A real provider will run "simulated phishing attacks." They will send fake "bad emails" to your staff to see who clicks. If a staff member clicks, they get immediate "teachable moment" training. This turns your employees from your biggest liability into your "human firewall."

"In my 26 years, I’ve never seen a breach that couldn't have been stopped—or at least mitigated—by a well-trained employee who simply paused before clicking 'Enable Macros'." — Kevin Mabry

What to Look For in Staff Training Programs

A comprehensive program should include:

  1. Baseline Testing: Finding out how "click-happy" your office is right now.
  2. Monthly Micro-Learning: 2-3 minute videos that stay fresh.
  3. Simulated Phishing: Regular, varied tests (Amazon delivery alerts, HR policy updates, etc.).
  4. Reporting: A leaderboard or report showing you which departments are the highest risk.

Question 4: Will You Sign a BAA and Provide Your Own Audit Reports?

This is the "shocking" part for many providers. If you are in the medical or legal field, you have regulatory obligations. If your cybersecurity provider has access to your network, they have access to your Protected Health Information (PHI) or privileged client communications. Under HIPAA, any vendor with access to PHI is a "Business Associate."

I’ve seen many IT companies refuse to sign a Business Associate Agreement (BAA) because they don't want the legal liability. If they won't sign a BAA, fire them immediately. It means they aren't confident in their own security controls. Furthermore, you should ask for their SOC 2 Type II report. This is an independent audit that proves they are actually doing what they say they are doing. If a provider is managing your security but they aren't even auditing their own, that’s a massive red flag.

The Cost of Non-Compliance

The Office for Civil Rights (OCR) at HHS has been increasing fines for small practices. In 2023, the average settlement for a small healthcare provider regarding "failure to manage risk" was between $30,000 and $250,000. That doesn't include the cost of the actual breach. If your provider says, "We'll make you HIPAA compliant," but they aren't HIPAA compliant themselves, you are the one who will pay the fine, not them.

Question 5: What Happens at 2:00 AM on a Sunday When an "Anomalous Login" Occurs?

Cybercriminals love holidays and weekends. They know that most small business IT guys are at home, asleep, or at a barbecue. If your provider's "monitoring" consists of an email alert that goes into an inbox that nobody checks until Monday morning, you are already too late. Ransomware can encrypt an entire server in less than 45 minutes.

Real-Time Threat Detection vs. Passive Monitoring

You need to ask: "Who is watching the alerts in real-time?" A true cybersecurity provider uses an EDR (Endpoint Detection and Response) tool linked to a 24/7 SOC. If an attacker tries to brute-force a password at 2:00 AM, the SOC sees it, recognizes the pattern, and kills the connection automatically before the attacker can get in. This is the difference between a "Security Alarm" (which calls the police) and a "Security Camera" (which just records you getting robbed).

The Economics of 24/7 Protection

Many small business owners think they can't afford 24/7 monitoring. But consider the ROI. The Verizon DBIR notes that the "Mean Time to Identify" (MTTI) a breach is often over 200 days for companies without active monitoring. During those 200 days, hackers are stealing data and preparing their final "kill shot."

Cost Comparison Table:

Service Level Estimated Monthly Cost (per user) Potential Loss Exposure
No Managed Security $0 $1M+ (Total Business Loss)
Basic IT (9-5) $100 - $150 $500k+ (Ransom/Downtime)
Full MSSP (24/7/365) $200 - $350 $0 - $50k (Deductible/Minor Cleanup)

Implementation Best Practices: 10 Steps to Hiring the Right Provider

  1. Inventory Your Data: Before calling anyone, know where your "gold" is. Is it on a local server? In the cloud? On your staff’s personal phones?
  2. Demand a "Gap Analysis": Don't let them give you a quote without a thorough discovery process. If they don't look at your current setup first, they are just selling a generic package.
  3. Verify Certifications: Look for staff with CISSP (Certified Information Systems Security Professional) or CISM (Certified Information Security Manager) credentials.
  4. Ask for "Real" References: Don't just ask for a list of happy clients. Ask for a reference of a client who *had a security incident* and how the provider handled it.
  5. Check the SLA: Look at the Service Level Agreement. Does it guarantee a response time for *security* incidents, or just "general issues"?
  6. Evaluate the Tools: Ask what "stack" they use. Are they using name-brand, enterprise-grade tools like SentinelOne, CrowdStrike, or Huntress? Or are they using "white-label" junk?
  7. Look for Multi-Factor Authentication (MFA) Enforcement: If the provider doesn't *require* you to use MFA for everything, they aren't a security company.
  8. Question the Contract Length: Avoid 3-year "lock-in" contracts. In cybersecurity, the landscape changes every six months. You need the flexibility to move if they fall behind.
  9. Review the Insurance Requirements: Check with your Cyber Insurance carrier. Will they give you a discount if you hire this specific provider? Often, carriers have "approved lists."
  10. Trust Your Gut: If they use too much jargon and can't explain things in plain English, it's because they don't understand it well enough themselves.

Frequently Asked Questions

Is "The Cloud" (like Microsoft 365 or Google Workspace) already secure?

No. This is a common misconception called the "Shared Responsibility Model." Microsoft and Google secure the *infrastructure*, but you are responsible for securing the *data* and the *identities* inside it. Without proper configuration, Microsoft 365 is one of the most targeted platforms for business email compromise (BEC).

Why is cybersecurity so much more expensive than my old IT bill?

Because the stakes are higher and the labor is specialized. Twenty years ago, a "computer guy" was a hobbyist. Today, a cybersecurity analyst is a highly trained professional using software that costs thousands of dollars in licensing fees. You aren't paying for "support"; you are paying for "insurance" and "defense."

Do I really need a SOC (Security Operations Center) for a 10-person office?

Yes. Hackers use automated bots. Those bots don't care if you have 10 employees or 10,000. They are looking for open doors. If you have an internet connection and a bank account, you are a target. A SOC is the only way to catch an automated attack before it spreads.

What is the most common way small firms get hacked?

Phishing and stolen credentials (usernames/passwords). The 2024 Verizon DBIR confirms that credentials are the "primary lever" for attackers. This is why MFA and password managers are no longer "optional."

Can’t I just buy a good cyber insurance policy and skip the expensive provider?

Insurance companies are not in the business of losing money. In 2024, if you don't have documented security controls (like MFA, encryption, and regular backups), your insurance company can—and will—deny your claim after a breach. You have to prove you weren't "negligent."

What should I do if my current IT guy gets offended when I ask these questions?

If they get defensive, it's a sign they know they are lacking. A true professional welcomes these questions because they want a client who understands the value of what they are providing. If they can't answer them, it's time to move on.

How long does it typically take to onboard with a real cybersecurity provider?

A proper onboarding should take 30 to 60 days. It involves a deep dive into your systems, installing agents, cleaning up old accounts, and training your staff. If someone says they can "set you up by Friday," they aren't doing it right.

Conclusion

I’ve seen a lot of changes since 1999, but one thing remains constant: the most successful small business owners are the ones who treat their data as their most valuable asset. Cybersecurity is no longer an "IT expense" to be minimized; it is a foundational pillar of your business, right alongside your legal counsel and your tax strategy. The cost of doing it right is high, but the cost of doing it wrong is total.

Think about the ROI of a proper cybersecurity provider not in terms of "money saved today," but in terms of "business equity preserved for tomorrow." If you pay $3,000 a month for top-tier security, that’s $36,000 a year. If that prevents even one $500,000 ransomware event—which is the average for small firms according to Sophos—the service has paid for itself for the next 13 years. And that doesn't even account for the "sleep well at night" factor. In my 26 years, I’ve never had a client regret investing in security *after* they saw their competitor get wiped out. My goal is to make sure you’re the one still standing. Don’t be afraid to ask the shocking questions. Your business depends on it.

Watch: STOP! Your Backup Plan Is Failing Your Business 🚨

7 viewsJun 27, 2025Watch on YouTube →
KM

Kevin Mabry

Founder & CEO, Sentree Systems

Kevin Mabry is the founder and CEO of Sentree Systems, a cybersecurity company serving small professional service firms with under 100 employees. Since starting his business in 1999, Kevin has spent more than 26 years helping organizations protect sensitive information and make smarter technology and security decisions.

His work focuses on helping business owners protect client data, reduce cyber risk, and avoid the operational disruption caused by ransomware, account takeovers, phishing, and other preventable threats. Kevin is known for explaining cybersecurity in plain English without vendor hype, unnecessary jargon, or treating cybersecurity like generic IT support.

Take Action

Is your business protected?

Get a free security assessment. We'll identify your biggest risks and give you a clear, plain-English action plan — no obligation.

Schedule Your Free Assessment