Most small and mid-sized businesses did not choose their security posture. They chose an IT supplier, and the posture arrived as a side effect. That is not unreasonable, but it does mean nobody has ever checked whether the arrangement is actually protecting anything.
Why this is worth an hour of your time
An IT support contract and a security engagement look similar from the outside and are very different underneath. Support is reactive by design: something breaks, a ticket opens, the thing gets fixed, the ticket closes. That is a real service and most suppliers do it competently.
What it does not include is anyone owning the question of whether the network is designed correctly, whether the firewall rules still match the business, or whether a restore would actually work. Those are not tickets. They never break loudly enough to open one. So in many businesses nobody has looked at them for years, and everyone assumes somebody has.
The eight questions
- Who holds the administrative passwords, and where are they stored? If the answer is one person's memory or a spreadsheet on their laptop, you have a continuity problem regardless of anything security-related.
- When were the firewall rules last reviewed, and can I see the current rule base? A supplier who has taken ownership can produce it. One who cannot has probably not looked at it since installation. We cover what that review involves under firewall audit and rule review.
- Has anyone ever restored from our backups as a test? Ask for a date, not an assurance. Backups that run and backups that restore are different things, and you find out which you have at the worst possible moment.
- Can a laptop in the office reach the server, the accounts system and the CCTV? If the answer is yes, or nobody is sure, the network is flat. See why that matters.
- Is multi-factor authentication enforced on remote access? Not available. Enforced. On every account, including the supplier's own.
- What is our network diagram, and when was it last updated? If one does not exist, the estate lives in somebody's head, and that person can leave.
- What happens to our documentation and credentials if we change supplier? Ask now, while the relationship is good. The answer tells you whether you are a client or a hostage.
- Which of our systems are reachable from the internet? This should be a short, confident list. Uncertainty here is the single most useful finding you can get from the conversation.
What good answers sound like
You are not looking for perfection. You are looking for a supplier who knows the answer, or who says plainly that they do not and offers to find out. "I would need to check the firewall, give me a day" is a completely acceptable answer and a good sign.
What should concern you is confident vagueness. "Everything is secured", "we follow best practice", "that is all handled" are not answers. They are the shape of an answer, and they usually mean nobody has looked.
This is not an argument for replacing your supplier
We do infrastructure and security work, so read this with that in mind: in most cases the right outcome is not a new supplier. It is the existing one being asked questions nobody has asked them before, and being given the budget and the mandate to fix what surfaces.
Support suppliers frequently know exactly what is wrong. They have been carrying a list in their head for years and have never been asked. The businesses that get the best outcome are usually the ones that turn that list into a plan rather than starting again with someone new.
Where an outside pair of eyes helps is in producing the list independently, which is what a security assessment is for. Your supplier then has something concrete to work from, and you have something to measure progress against.
If you want a neutral yardstick
The CIS Critical Security Controls and the NIST Cybersecurity Framework both open with asset inventory and secure configuration, which is where most of the eight questions above land. The CIS Benchmarks carry the device-level detail. None of these require adopting a framework; they are simply a way of checking that what your supplier tells you lines up with what the rest of the industry considers baseline.
What to do this week
Send four of the questions by email: who holds the passwords, when the firewall was last reviewed, when a restore was last tested, and what is reachable from the internet. Email rather than a call, because you want the answers in writing and you want to see how long they take. The response tells you most of what you need to know.