Five questions to ask your IT provider this quarter
A useful security conversation ends with a record of what is covered, what remains uncertain, and who will act next. Bring these five questions to your next provider meeting.
1. Who responds outside business hours?
If a serious alert arrives on Saturday night, who reviews it, who can contain the problem, and who contacts your organization? Ask for the agreed response hours, escalation route, and authority to act. Automated alert generation, human investigation, and incident response may be separate services.
Write down the first contact and a fallback. A named contact alone does not establish a response commitment; check the service agreement as well.
2. What did the last recovery test demonstrate?
Ask when a restore was last tested, which systems were included, and whether the restored application was usable. Compare the recorded recovery time and data age with what your business can tolerate. A successful file restore supports a narrower conclusion than a successful recovery of a complete business service.
Our guide to reading a backup report explains the evidence to request.
3. How is access to business email controlled?
Ask which accounts must use multi-factor authentication, what exceptions exist, and how access from personal devices is governed. Request the current policy and evidence that it applies to the intended accounts. Ask your administrator to explain how phishing-resistant authentication fits your environment.
The useful answer identifies coverage and exceptions. A claim that a feature is available does not establish that it is enforced.
4. Where does your responsibility end and ours begin?
Ask for a current list of security responsibilities, including work assigned to other providers. For shared tasks, identify who starts the work, who approves it, and who confirms completion. Use a concrete example such as removing a departing employee’s access.
Our provider responsibility guide shows how to examine those handoffs.
5. How do we verify a change to payment instructions?
Ask the people who approve payments to explain the process, then check whether it works independently of the email making the request. For example, an organization might confirm a change using a previously verified contact number and require a second approval. Agree on exceptions before an urgent request arrives.
This question belongs to finance and operations as well as IT. Technical access controls and business approval processes need to work together.
Turn the answers into decisions
Record the evidence reviewed, any unresolved question, an owner, and a due date.
Published by Security Reality Check LLC.
Want to apply this to your situation?
Tell us the question this article raised, the providers or processes involved, and what you need to decide next.
You do not need to send confidential documents to start the conversation.
Contact us about a review