All Posts Security

How to Tell If Your IT Provider Is Actually Keeping You Secure

You are paying your managed IT provider $1,000 to $5,000 a month. They tell you the network is healthy, the backups are running, and your systems are secure.

To verify your IT provider is actually request a security review, ask for patch compliance reports, backup verification logs, MFA enrollment status, and firewall rule reviews — a good provider produces these immediately. A 2025 ConnectWise survey found 94% of MSPs are targeted by cyberattacks, making your IT provider a potential attack vector. This guide includes 40 specific evaluation questions and a scoring framework to grade their responses.

You are paying your managed IT provider $1,000 to $5,000 a month. They tell you the network is healthy, the backups are running, and your systems are secure. But here is the uncomfortable question: how do you actually know? How do you verify that the company you are trusting with your entire digital infrastructure is doing what they say they are doing? Because here is what we see when businesses in Volusia County Daytona Beach and across Volusia County come to us for a second opinion: outdated antivirus, firewalls with default passwords, backups that have not run in months, and MFA that was “in progress” for over a year.

This is not about bashing IT providers. Most are competent and genuinely care about their clients. But the gap between “we are handling it” and “we can prove we are handling it” is where breaches happen. And the only person who suffers when that gap exists is you — the business owner.

This guide gives you a concrete evaluation framework. Forty specific questions to ask your IT provider, a scoring system to grade their responses, and a list of red flags that should have you picking up the phone to other providers immediately.

The Uncomfortable Truth About MSP Security

Let us start with some context. A 2025 ConnectWise survey found that 94% of managed service providers (MSPs) report being targeted by cyberattacks. That makes sense — if you are an attacker, why hack one business when you can hack the MSP and get access to 50, 100, or 500 businesses at once? The Kaseya VSA attack in 2021, the SolarWinds breach, and the more recent MOVEit vulnerability all demonstrated this exact pattern.

This means your IT provider is not just a service vendor — they are a potential attack vector. The tools they use to manage your network (RMM tools, remote access, admin credentials) are exactly the tools an attacker would want to compromise. So “is my IT provider secure?” is not a paranoid question. It is the most important question you can ask.

The 40-Question Security Assessment

Here is the evaluation framework. Organize a meeting with your IT provider and walk through these questions. Their responses — and their willingness to answer transparently — will tell you everything you need to know.

Section 1: Access & Authentication (10 Questions)

These questions establish whether your provider follows basic access control principles.

  1. Is MFA enabled on every admin account that touches our systems? Not just your employees — their technicians’ accounts too. If their admin portal uses password-only authentication, a single phished password compromises your entire network.

  2. What MFA method do you use — app-based (Authenticator), hardware tokens, or SMS? SMS-based MFA is better than nothing but significantly weaker than app-based or hardware tokens. If they say “SMS,” that is a yellow flag.

  3. How many of your technicians have admin access to our network? The answer should be a specific number, not “the team.” The fewer people with admin access, the smaller the attack surface.

  4. Do technicians use unique credentials for our environment, or shared accounts? Shared “admin@msp” accounts mean you cannot track who did what. Every technician should have a unique, named account with their own MFA.

  5. How quickly do you revoke access when a technician leaves your company? The answer should be “immediately” or “same day.” If they hesitate, ask when the last technician left and whether access was revoked. If they cannot answer, that is a red flag.

  6. Do you use a Privileged Access Management (PAM) solution? Tools like CyberArk, Thycotic, or even self-hosted solutions like Bitwarden ensure admin credentials are rotated and access is logged. Smaller MSPs may not use full PAM, but they should have a documented credential management process.

  7. Can you show us an access log for who has connected to our systems in the last 30 days? If they cannot produce this within a day, they are not tracking access — which means they cannot detect unauthorized access either.

  8. Are our admin passwords rotated on a schedule? Domain admin, firewall admin, server admin — these should change at least quarterly. “We set it up and left it” is a failure.

  9. Do your technicians use VPN or zero-trust access to reach our network? Direct RDP exposure to the internet is one of the top ransomware entry points. Their remote access should go through an encrypted, authenticated tunnel.

  10. Is our RMM (Remote Monitoring and Management) tool secured with MFA and IP restrictions? The RMM tool has admin access to every machine on your network. If it is compromised, everything is compromised. It should have MFA, IP whitelisting, and audit logging at minimum.

Section 2: Endpoint Protection (8 Questions)

  1. What endpoint protection are you running — traditional antivirus or EDR? In 2026, traditional antivirus is not enough. Endpoint Detection and Response (EDR) tools like SentinelOne, CrowdStrike, or Microsoft Defender for Business detect behavioral threats that signature-based antivirus misses.

  2. Is endpoint protection installed on every device — including servers? It is common to find servers without protection because “the server does not browse the web.” Servers need protection — they are the highest-value target.

  3. Can you show us a report of which devices have endpoint protection active right now? Not “all of them.” Show us the dashboard. Are there any devices showing as offline, unprotected, or out of date? Every gap is a potential entry point.

  4. How quickly do you respond to an endpoint alert? The answer should include an SLA — like “critical alerts within 15 minutes, high within 1 hour.” If there is no SLA, ask what happens at 2 AM on a Saturday.

  5. Do you have tamper protection enabled? Tamper protection prevents anyone (including malware running as admin) from disabling the endpoint protection. If an attacker can turn off your antivirus, having antivirus is pointless.

  6. Is web filtering enabled? Blocking known malicious websites and inappropriate content categories prevents drive-by downloads and phishing sites from loading in the first place.

  7. Are USB devices restricted or monitored? Unrestricted USB access means anyone can plug in an infected drive or copy your data to a thumb drive.

  8. What is your patch management process and timeline? Critical patches should be applied within 14 days. Ask for a report showing current patch compliance across your endpoints. If more than 10% of machines are behind on patches, that is a problem.

Section 3: Backup & Recovery (7 Questions)

  1. Where are our backups stored — onsite, offsite, or both? The correct answer is both, plus cloud. If backups are only onsite, a fire, flood, or ransomware attack destroys everything including the backups.

  2. Are backups encrypted? Unencrypted backups are a data breach waiting to happen if someone gains access to them.

  3. Are backups immutable? Immutable backups cannot be modified or deleted, even by an admin account — even by ransomware. This is the single most important backup feature in 2026. If your provider’s backup solution does not support immutability, it will not survive a ransomware attack.

  4. When was the last time you tested a restore from backup? Not “the backups run every night.” When did you actually restore data from a backup to verify it works? If the answer is “I’m not sure” or “we have not done that,” your backups are unverified assumptions.

  5. What is our Recovery Time Objective (RTO) and Recovery Point Objective (RPO)? RTO is how long it takes to get back online. RPO is how much data you lose (if backups run nightly, RPO is up to 24 hours). Your provider should know these numbers and they should match your business needs.

  6. Can you show us a backup verification report from this week? A report showing backup job status, success/failure, data volume, and completion time. If they cannot produce this, backups are not being monitored.

  7. Do you have a documented disaster recovery plan for our environment? Not a generic template — a plan specific to your environment that includes server rebuild order, critical application recovery steps, and communication procedures. Ask to see it.

Section 4: Network Security (8 Questions)

  1. Is our firewall running current firmware? Firewall vulnerabilities are a top attack vector. If your firewall is running firmware from 2023, it has known vulnerabilities that are actively exploited in the wild.

  2. Has anyone changed the default admin password on our firewall? You would be shocked how often the answer is no. “admin/admin” or “admin/password” on a business firewall is like leaving the front door of a bank unlocked.

  3. Is our network segmented? At minimum, your guest WiFi should be on a separate network from your business systems. Ideally, servers, workstations, IoT devices, and payment systems are all on separate VLANs. Without segmentation, one compromised laptop gives an attacker access to everything.

  4. Do you monitor our network for unusual traffic or behavior? This is employee offboarding security checklist monitoring — the topic we covered in our security monitoring guide. If your provider does not monitor for anomalies, attacks go undetected.

  5. Are we using a VPN for remote access, or is anything exposed directly to the internet? Check for exposed RDP (port 3389), exposed admin panels, or exposed database ports. These should never be directly accessible from the internet.

  6. When was our last external vulnerability scan? External scans check what attackers can see from the internet. This should happen at least quarterly, and the results should be shared with you.

  7. Do you have DNS filtering enabled? DNS filtering blocks malicious domains at the network level before a connection is even established. It is one of the simplest and most effective security layers.

  8. Is our email properly configured with SPF, DKIM, and DMARC? These email authentication protocols prevent attackers from sending emails that appear to come from your domain (spoofing). If they are not configured, anyone can send an email that looks like it came from your business.

Section 5: Compliance & Documentation (7 Questions)

  1. Can you provide documentation of all systems you manage for us? A current network diagram, asset inventory, and configuration documentation. If your provider cannot list every device they manage, they cannot protect devices they do not know about.

  2. Do you have cyber insurance? What does it cover? Your IT provider should carry their own cyber insurance. If they get breached and your data is exposed, their insurance (not just yours) needs to cover it.

  3. Do you carry Errors & Omissions (E&O) insurance? E&O insurance covers negligence — like if they forget to apply a critical patch and you get breached as a result. If they do not carry E&O, you are absorbing all the risk.

  4. What compliance frameworks do you follow for your own operations? Look for SOC 2 Type II certification, ISO 27001, or at minimum documented security policies. If they are asking you to trust them with your security but cannot demonstrate their own, that is a problem.

  5. How do you handle our data when we terminate the contract? They should have a documented data destruction or return process. Your data should not sit on their systems indefinitely after you leave.

  6. Can you provide a monthly security report showing our current posture? Not just “everything is fine” — a report with specific metrics: patch compliance percentage, backup success rate, endpoint protection coverage, and open vulnerabilities.

  7. Do you conduct annual security awareness training for your own staff? If their technicians are not trained on security best practices, how can they implement them for you? A phished MSP technician with admin access to your network is a nightmare scenario.

Scoring Your Provider

Use this rubric to score each response:

Score Criteria
3 — Strong Clear, specific answer with evidence (dashboards, reports, documentation). Proactive approach.
2 — Adequate Reasonable answer but lacks evidence or specifics. Reactive rather than proactive.
1 — Weak Vague answer, defensiveness, or inability to provide evidence.
0 — Absent Cannot answer, refuses to answer, or admits the practice does not exist.

Scoring by Section

Section Max Score Concerning Acceptable Strong
Access & Auth (10 Q) 30 Below 15 15-24 25-30
Endpoint (8 Q) 24 Below 12 12-19 20-24
Backup (7 Q) 21 Below 10 10-16 17-21
Network (8 Q) 24 Below 12 12-19 20-24
Compliance (7 Q) 21 Below 10 10-16 17-21
Total 120 Below 60 60-95 96-120

Below 60 total: Serious security gaps exist. Start evaluating alternative providers. Your business is at significant risk.

60-95 total: Your provider covers the basics but has notable gaps. Have a candid conversation about specific areas where they scored poorly. Give them 90 days to improve, then re-evaluate.

96-120 total: Your provider is doing a strong job. The remaining gaps are likely minor and can be addressed through normal improvement cycles.

The Red Flags That Should Worry You

Some responses are not just “weak” — they are disqualifying. If your provider exhibits any of these, it is time to seriously consider switching:

Immediate Red Flags

  • “We do not use MFA on our admin accounts.” This is inexcusable in 2026. If they cannot protect their own access, they cannot protect yours.

  • “We have never tested a backup restore.” Unverified backups are Schrodinger’s backups — they might work, they might not, and you will not find out until the worst possible moment.

  • “We do not track which technicians access your systems.” No access logging means no accountability, no breach detection, and no audit trail.

  • “Our RMM tool does not have MFA.” The RMM tool has admin access to every machine on your network. Without MFA, a compromised RMM password is a skeleton key.

  • Defensiveness or refusal to answer questions. A provider confident in their security practices will answer these questions transparently. Defensiveness suggests they know the answers will not look good.

Yellow Flags (Concerning But Fixable)

  • Cannot produce reports within a few business days. Reports should be routine, not special requests.
  • Uses SMS-only MFA. Better than nothing, but should be transitioning to app-based.
  • Has not updated firewall firmware in 12+ months. Indicates reactive rather than proactive maintenance.
  • No documented disaster recovery plan. Shows a “we will figure it out” mentality that fails under pressure.
  • No SOC 2 or equivalent certification. Smaller MSPs may not have this, but they should have documented security policies.

How to Have This Conversation

Do not ambush your provider. This evaluation works best as a collaborative process, not an adversarial one. Here is how to approach it:

  1. Frame it positively: “We are working on our security compliance and want to make sure we are aligned. Can we schedule a meeting to review our security posture together?”

  2. Share the questions in advance: Give them the 40 questions a week before the meeting. This gives them time to gather evidence and reports rather than answering off the cuff.

  3. Focus on evidence, not promises: “We are doing that” is not evidence. A dashboard showing current MFA enrollment is evidence. A report showing last week’s backup status is evidence.

  4. Be willing to invest: Some gaps may require additional services that cost more. A provider offering $500/month all-inclusive for 20 users is probably cutting corners somewhere. Security costs money — the question is whether you pay for it now or pay exponentially more after a breach.

  5. Set review cadence: Schedule this evaluation annually. Security is not static — threats evolve, tools change, and what was adequate last year may be insufficient this year.

What Good Looks Like

For comparison, here is what a strong IT provider’s responses look like in practice:

Access Control: “Here is our access matrix showing three named technicians with access to your environment. Each uses individual accounts with Microsoft Authenticator MFA. Our PAM solution rotates your admin passwords quarterly. Here is the access log from the last 30 days — you can see the four support sessions we had.”

Endpoint Protection: “We deploy SentinelOne EDR across all endpoints. Here is today’s dashboard — 47 of 48 endpoints active, one laptop offline (Sarah’s — she is on vacation). Tamper protection is enabled. Our SOC monitors alerts 24/7 with a 15-minute SLA on critical alerts.”

Backup: “Backups run to both your local NAS and Wasabi cloud storage. They are encrypted with AES-256 and immutable for 30 days. Here is this week’s backup report — all successful. We tested a full server restore in January and completed it in 4 hours. Here is the test documentation. Your RTO is 4 hours, RPO is 24 hours.”

Network: “Firewall firmware was updated last month — here is the change log. Your network has four VLANs: production, guest WiFi, payment terminals, and IoT. We run quarterly vulnerability scans — here is the last report, and here are the two findings we remediated.”

Notice the pattern: specific numbers, named evidence, timestamps, and documentation. Not “we handle that” — “here is how we handle that, and here is the proof.”

Building Your Own Verification Capability

Even with a great provider, trust but verify. Run our security audit checklist independently. If your provider says MFA is enabled everywhere, run a spot check. If they say backups are working, ask them to restore a specific file from last week’s backup and time how long it takes.

You do not need to become a security expert. You need to be a security-literate business owner who asks good questions and expects evidence-backed answers. The 40 questions in this guide give you that capability.

For a more structured approach to evaluating all your vendors — not just IT — see our vendor risk assessment template.

The Bottom Line

The right technology setup saves time, reduces costs, and lets you focus on running your business instead of troubleshooting IT problems. Start with the fundamentals, implement them properly, and build from there.

FAQ

Should I hire a different company to audit my IT provider?

For businesses handling sensitive data (healthcare, financial services, legal), yes — an independent third-party assessment provides unbiased validation. For general small businesses, the 40-question framework in this guide is sufficient as a starting point. If your provider scores below 60, then an independent audit is warranted before deciding whether to stay or switch.

How often should I evaluate my IT provider’s security?

Annually at minimum, with a quick quarterly check on the highest-risk items (MFA status, backup verification, patch compliance). Major evaluations should also happen after any security incident, after significant changes to your environment (new office, cloud migration), or if your provider has staff turnover in key positions.

My IT provider got defensive when I asked these questions. Is that a bad sign?

Yes. A provider confident in their security practices will welcome the opportunity to demonstrate their value. Defensiveness typically indicates one of three things: they know they have gaps and do not want to admit it, they have never been asked and are embarrassed, or they view security accountability as outside the scope of what you are paying for. None of these are acceptable.

What if my provider is great at support but weak on security?

This is common — many IT providers excel at help desk support and day-to-day maintenance but treat security as an afterthought. You have two options: give them 90 days to improve the specific areas where they scored poorly (with a written improvement plan), or retain them for support while hiring a security-focused firm (virtual CISO or security consultant) to handle the security layer. The worst option is doing nothing.

Is it reasonable to expect a small MSP to have SOC 2 certification?

SOC 2 certification is expensive ($30,000-$100,000+ for initial audit) and time-consuming. Many excellent small MSPs do not have it. What you should expect instead is documented security policies, regular staff training, access controls on their own systems, and a willingness to demonstrate their security practices. The absence of SOC 2 is not a red flag — the absence of any documented security practices is.

How do I switch IT providers without disruption?

Plan a 60-90 day transition. The new provider should conduct a full assessment during the first month while the old provider still manages the environment. During month two, the new provider takes over primary management with the old provider available for questions. Month three is full independence. Critical: ensure you have all admin credentials, documentation, and licenses before the old provider’s contract ends. Some providers make this difficult — another red flag.

Free Discovery Call

Start With a Conversation, Not a Commitment

Every engagement begins with a free 30-minute discovery call. We'll map what's slowing your business down and tell you exactly what we'd fix first – no pitch deck, no obligation.