Seven Questions Every Business Leader Should Ask Their IT Provider About Cyber Security

Seven practical questions to help business leaders test cyber security controls, challenge assumptions and gain clearer evidence from their IT provider.

KANJ Advisory Team
Explore
Seven Questions Every Business Leader Should Ask Their IT Provider About Cyber Security

As organisations evolve, responsibility for technology often moves away from the leadership team.

An internal IT department or Managed Service Provider takes responsibility for systems, users, devices, cloud services and cyber security. Technology becomes more sophisticated, specialist expertise becomes essential and business leaders become less involved in its day-to-day management.

The danger is that organisations sometimes outsource their curiosity along with the technology.

Directors who would never accept an unclear answer from an accountant, solicitor or auditor can receive surprisingly little evidence about one of the organisation’s most significant operational risks. Revenue, cash flow and commercial performance may be examined closely at board meetings, while an entire discussion about cyber security is reduced to the reassuring statement that everything is working properly.

That may be true, but it does not tell the board whether the business is adequately protected.

Business leaders do not need to become cyber security specialists. They should, however, be able to ask informed questions, understand the answers and receive evidence that appropriate controls are working.

The seven questions are:

1. How do we know our cyber security controls are working today?
2. Who has access to our systems and sensitive information?
3. How quickly would we detect and respond to a cyber attack?
4. Could we recover our essential operations if our systems were compromised?
5. Which known security weaknesses remain unresolved?
6. What should the board learn from our cyber security reporting?
7. When was our cyber security last independently assessed?

The purpose of these questions is not to catch an IT provider out. It is to establish whether the organisation understands its risks, whether responsibilities are clear and whether confidence is supported by evidence.

1. How do we know our cyber security controls are working today?

Installing antivirus software, enabling a firewall and purchasing Microsoft 365 security licences do not, by themselves, demonstrate an effective security environment. The important question is whether those controls have been configured properly, deployed consistently and monitored over time.

A considered answer may refer to Microsoft Secure Score, Multi-Factor Authentication coverage, endpoint protection, patch compliance, vulnerability management, privileged access, backup testing and security monitoring. The provider should also explain what this evidence means for the business.

A board does not need a collection of technical statistics. It needs to understand whether the organisation’s exposure is increasing or reducing, where important weaknesses remain and what decisions may be required.

No credible provider can guarantee that a business is secure. A strong answer will acknowledge that reality while demonstrating how risks are identified, prioritised and managed. A weak answer will rely on product names, general reassurance or the fact that nothing serious has happened recently.

The absence of a known incident is not evidence that an attack has not occurred. Nor does it demonstrate that the business is prepared for one.

2. Who has access to our systems and sensitive information?

Many cyber incidents begin with a legitimate account that has been compromised, misused or left active for too long.

Access tends to accumulate as an organisation grows. Employees move between roles, contractors complete projects, suppliers receive temporary permissions and administrator rights are granted to solve immediate problems. Unless those permissions are reviewed, temporary access can quietly become permanent.

The provider should be able to show who has access to the organisation’s systems, who holds elevated privileges and how permissions change when someone joins, moves within or leaves the business. External supplier accounts, shared credentials and dormant users should all be included.

This is particularly important in Microsoft 365. A single compromised identity may provide access to email, SharePoint, Teams, OneDrive and a substantial amount of commercially sensitive information.

An accurate user and administrator report is a useful starting point, but process matters as much as the report. The leadership team should understand who authorises access, who informs the IT provider when circumstances change and who checks that the instruction has been completed.

If a former employee retains access because nobody notified the provider, the weakness is not solely technical. It is a gap between HR, management and IT. A mature answer will therefore explain both the controls and the responsibilities supporting them.

3. How quickly would we detect and respond to a cyber attack?

Preventing every attack is unrealistic. The time taken to detect and contain suspicious activity is therefore an important measure of cyber resilience.

Traditional IT support is usually reactive. Someone reports that a device is not working, an email account is behaving strangely or files can no longer be opened. Effective security monitoring aims to identify suspicious behaviour before the resulting disruption becomes obvious.

The provider should explain what is monitored, when monitoring operates and who is responsible for reviewing alerts. If that responsibility sits with a separate security provider or an internal team, this should be equally clear.

The important issue is not whether a particular security product has been installed. It is whether a defined response follows when that product identifies suspicious activity.

The leadership team should understand who can isolate a compromised account or device, how an incident is escalated, when senior management would be informed and whether the response process has been exercised.

A serious incident may also require input from cyber insurers, lawyers, communications advisers, regulators or forensic investigators. Those relationships and escalation routes are better established before an attack than during one.

A useful follow-up question is: When did we last test our response, and what did we learn?

A written incident plan has value. An exercised plan provides considerably more assurance.

4. Could we recover our essential operations if our systems were compromised?

Most organisations know that backups are important. Fewer know whether their backup arrangements would support the recovery the business actually needs.

A successful backup notification confirms that data was copied. It does not prove that the data is complete, protected from attackers or capable of being restored within an acceptable timescale.

This has become increasingly important as ransomware attacks have evolved. Attackers may attempt to compromise backups alongside live systems, removing the organisation’s quickest route to recovery.

Cloud services can also create misplaced confidence. Microsoft 365, Azure, Amazon Web Services and other providers operate resilient infrastructure, but their resilience does not automatically provide every customer with a complete backup or business continuity strategy.

The IT provider should be able to explain what is backed up, where those backups are held, how they are protected and when a meaningful restoration test was last completed. It should also be clear which systems would be restored first and how long recovery is expected to take.

The order should reflect what the business needs to continue operating. A manufacturer may prioritise production schedules and machine configurations. A professional services firm may need access to case files and communications. A logistics business may depend first on transport planning, warehouse or tracking systems.

If the provider does not know which activities matter most, it cannot confidently design recovery around them.

The most useful evidence is not simply a successful backup report, but a recovery test showing what was restored, how long it took, what failed and what changed as a result.

5. Which known security weaknesses remain unresolved?

Every technology environment contains vulnerabilities. The relevant governance question is whether those weaknesses are known, prioritised and being addressed.

Providers should be able to identify missing security updates, unsupported software, unmanaged devices, excessive privileges, exposed services and poorly configured cloud systems. They should also distinguish between routine recommendations and issues that create a material business risk.

Not every finding can or should be resolved immediately. Some changes may interrupt operations, require investment or depend on the replacement of a wider system. In other cases, the cost of remediation may be disproportionate to the risk.

Those may be legitimate business considerations, but the decision should be visible and deliberate.

For each significant weakness, the leadership team should know what the risk is, which part of the business it could affect, what action has been recommended, who owns that action and when it is expected to be completed. Any decision to accept the remaining risk should also be recorded.

This is more valuable than expecting a report with no adverse findings. An apparently perfect security report may offer less assurance than one that identifies weaknesses honestly and shows how they are being managed.

The provider’s role is not to create the impression that risk has disappeared. It is to help the organisation understand where risk exists and make informed decisions about it.

6. What should the board learn from our cyber security reporting?

Many organisations receive monthly reports from their IT provider, but these often resemble service desk summaries rather than management information.

The number of support tickets opened and closed may indicate responsiveness and workload. It says relatively little about whether the organisation’s cyber risk is increasing or reducing.

A useful cyber security report should explain what has changed, which controls have improved, whether important actions were completed and where decisions are required. Relevant measures might include patch compliance, endpoint coverage, Multi-Factor Authentication adoption, privileged accounts, backup restoration results, unresolved vulnerabilities and significant security incidents.

Metrics require context. A Microsoft Secure Score of 70 per cent, for example, is neither inherently good nor bad. The board needs to understand which recommendations remain outstanding, whether they are relevant and what practical risk they represent.

The same applies to patching. Reporting that 95 per cent of devices are compliant sounds encouraging, but the remaining 5 per cent may include the organisation’s most important server or several laptops holding sensitive information.

Good reporting should allow directors to answer three straightforward questions:

  • Are we becoming more or less secure?
  • Where are our most significant outstanding risks?
  • What action or decision is required from us?

If a lengthy report cannot answer those questions, the information may be accurate but it is not yet useful.

The report should also reflect the provider’s agreed scope. A support provider cannot report on controls it has neither been contracted nor given access to manage. Where gaps exist between suppliers, internal teams or contracts, ownership should be established rather than assumed.

7. When was our cyber security last independently assessed?

Independent scrutiny should not be seen as a threat to the relationship between an organisation and its IT provider.

Accountants expect financial records to be audited, and professional advisers expect important decisions to be reviewed. Cyber security should be approached with similar maturity, particularly where an organisation holds sensitive information, operates within a regulated sector or depends heavily on technology.

An independent assessment might examine security configurations, external vulnerabilities, access controls, patch compliance, backup restoration, incident response and evidence supporting Cyber Essentials or ISO 27001.

Its purpose is not necessarily to prove that the existing provider has failed. It is to test assumptions, identify overlooked weaknesses and confirm that current arrangements remain appropriate as the organisation changes.

This matters because an IT provider may be reviewing decisions and configurations it originally helped to create. That does not make its assessment unreliable, but an independent perspective can uncover assumptions that have become embedded over time.

The provider’s response to scrutiny can itself be informative. A professional partner should be willing to explain its decisions, acknowledge limitations and engage constructively with sensible recommendations.

There may be legitimate reasons why every piece of evidence cannot be supplied immediately. The concern is not an imperfect environment or a missing document. It is resistance to scrutiny, unclear responsibilities or an inability to provide evidence for controls believed to be in place.

The questions may reveal a wider governance issue

Business leaders sometimes worry that they lack the technical knowledge required to recognise a poor answer. In practice, clarity, evidence and ownership often reveal more than technical vocabulary.

A provider should know what sits within its responsibility and be honest about what does not. The organisation must then establish who owns anything outside that scope.

Appointing an IT provider does not transfer every aspect of cyber security responsibility to that provider. Leadership still determines risk appetite, approves investment, sets business priorities and ensures that responsibilities across employees, internal teams and suppliers are understood.

The seven questions may identify problems with the provider, but they may also expose gaps in contracts, internal processes or management oversight.

Warning signs that deserve further examination include:

  • Answers that depend on reassurance rather than evidence
  • No accurate record of privileged users
  • Backup restoration that has not been tested
  • Unclear monitoring and incident response responsibilities
  • Known risks with no owner or completion date
  • Reports that provide statistics without explaining their significance
  • Important controls assumed to belong to another supplier
  • Independent assessment discouraged without a credible reason

None of these automatically demonstrates that a provider is incapable. They do indicate uncertainty around an important area of business risk.

Better questions create more valuable IT relationships

The strongest Managed Service Providers do more than maintain systems and respond quickly to support requests.

They help leadership teams understand risk, make informed decisions and improve resilience over time. They understand the systems the organisation uses, the information it must protect and the operational consequences if technology becomes unavailable.

The purpose of these seven questions is not to create confrontation. It is to replace assumed responsibility with clear responsibility and general reassurance with evidence.

No technology environment is perfect. What matters is whether the risks are understood, communicated honestly and supported by a credible plan for improvement.

That creates a better conversation between the leadership team and its technology provider. More importantly, it gives the organisation a clearer understanding of whether it is genuinely prepared for the incidents it has not yet encountered.

How Kanj Technologies helps

Many organisations already have an established Managed Service Provider or experienced internal IT team. They may not need to replace those arrangements, but still want independent confirmation that their cyber security controls remain appropriate for the business they have become.

Kanj Technologies provides independent technology assurance, Microsoft 365 security reviews, cyber security assessments and support with standards including Cyber Essentials and ISO 27001.

Our role is not automatically to recommend more technology or replace an existing provider. It is to understand the organisation, examine the available evidence and help its leadership team identify material risks, unclear responsibilities and practical priorities for improvement.

The strongest technology partnerships are built on informed challenge, clear evidence and shared accountability for protecting the business.

 

Keep exploring

Related blogs

let's collaborate

Need IT That Reduces Risk and Stands Up to Regulation?

Let's strengthen reliability and optimise your IT for efficiency.