// Blog / Guide

Questions to ask your IT provider about their own security

Share

You vet the software you buy, but the business with the deepest access to your systems is often the one you never audit: your IT provider. They hold administrator credentials, run remote-access tools across your machines, and store your passwords and backups. When their tools are attacked, and as recent RMM compromises show, they are, your business is exposed through no fault of your own. You do not need to be technical to check that your provider takes their own security seriously. You just need to ask, and know what a good answer sounds like.

How they protect their access to you

Start with the keys to your kingdom. Ask: do you use multi-factor authentication on every account that can reach our systems? Are your remote-management tools patched promptly, and do you monitor them for compromise? How are our administrator credentials and passwords stored and protected? A strong provider answers these confidently and specifically. Vagueness or discomfort here is the loudest possible red flag, because this is the exact door attackers use.

How they would handle an incident

Ask what happens if they are breached. Would you be told, and how quickly? Do they have an incident response plan that covers their clients? Have they ever had an incident, and how did they handle it? You are not looking for a spotless record, breaches happen to everyone, you are looking for honesty and a plan. A provider who cannot describe how they would tell you about their own bad day has not thought about yours.

Whether you would be in control

Ask the ownership questions: do we own our own domains, accounts, and data, or are they under your name? Could we get everything and leave cleanly if we needed to? A provider who holds your domain or your Microsoft 365 tenant under their own account has quiet power over you, and makes a breach of them far worse for you. You want to be a client, not a hostage.

What good sounds like

A provider worth trusting welcomes these questions rather than bristling at them, answers in plain language, and can point to real practices: MFA everywhere, prompt patching, monitored tools, tested backups they can restore, clear ownership in your name, and a straight commitment to tell you fast if something goes wrong. If asking makes them defensive, you have learned something important. Our guide on choosing a provider covers the rest of the evaluation.

Want an IT provider who secures their own tools, and proves it?

Talk to us

Related