The questions to ask your IT supplier

By S. Sridhar Thewar · 7 min read · Published September 2026
Short version: Ask who holds the administrative passwords, when the firewall rules were last reviewed, whether a restore has ever been tested, and what happens to your documentation if you leave. The answers separate a supplier who has taken ownership from one who has been closing tickets, and none of the questions require you to be technical.

Most small and mid-sized businesses did not choose their security posture. They chose an IT supplier, and the posture arrived as a side effect. That is not unreasonable, but it does mean nobody has ever checked whether the arrangement is actually protecting anything.

Why this is worth an hour of your time

An IT support contract and a security engagement look similar from the outside and are very different underneath. Support is reactive by design: something breaks, a ticket opens, the thing gets fixed, the ticket closes. That is a real service and most suppliers do it competently.

What it does not include is anyone owning the question of whether the network is designed correctly, whether the firewall rules still match the business, or whether a restore would actually work. Those are not tickets. They never break loudly enough to open one. So in many businesses nobody has looked at them for years, and everyone assumes somebody has.

The eight questions

What good answers sound like

You are not looking for perfection. You are looking for a supplier who knows the answer, or who says plainly that they do not and offers to find out. "I would need to check the firewall, give me a day" is a completely acceptable answer and a good sign.

What should concern you is confident vagueness. "Everything is secured", "we follow best practice", "that is all handled" are not answers. They are the shape of an answer, and they usually mean nobody has looked.

This is not an argument for replacing your supplier

We do infrastructure and security work, so read this with that in mind: in most cases the right outcome is not a new supplier. It is the existing one being asked questions nobody has asked them before, and being given the budget and the mandate to fix what surfaces.

Support suppliers frequently know exactly what is wrong. They have been carrying a list in their head for years and have never been asked. The businesses that get the best outcome are usually the ones that turn that list into a plan rather than starting again with someone new.

Where an outside pair of eyes helps is in producing the list independently, which is what a security assessment is for. Your supplier then has something concrete to work from, and you have something to measure progress against.

If you want a neutral yardstick

The CIS Critical Security Controls and the NIST Cybersecurity Framework both open with asset inventory and secure configuration, which is where most of the eight questions above land. The CIS Benchmarks carry the device-level detail. None of these require adopting a framework; they are simply a way of checking that what your supplier tells you lines up with what the rest of the industry considers baseline.

What to do this week

Send four of the questions by email: who holds the passwords, when the firewall was last reviewed, when a restore was last tested, and what is reachable from the internet. Email rather than a call, because you want the answers in writing and you want to see how long they take. The response tells you most of what you need to know.

Frequently asked questions

How do I know if my IT supplier is handling security?

Ask for specifics: the current firewall rule base, the date of the last tested restore, and the list of internet-facing systems. A supplier who has taken ownership can produce these or will say honestly that they need to check.

Is IT support the same as security?

No. Support is reactive and ticket-driven, which is a legitimate service. Security requires somebody to own questions that never open a ticket, such as whether the network is designed correctly or whether backups actually restore.

Should we replace our IT supplier?

Usually not. Most suppliers already know what is wrong and have never been asked or funded to fix it. An independent assessment gives both sides a concrete list to work from.

What if our supplier will not answer these questions?

That is itself the answer. A reluctance to share the rule base, the documentation or the credential arrangement is a continuity risk quite apart from any security concern.

Want the list produced independently?

An assessment gives you and your existing supplier the same set of facts to work from, in writing.

Book a free consultation