How to Choose a Cybersecurity Partner: 8 Questions to Ask Before You Sign
Choosing a cybersecurity partner is one of the more consequential decisions a business makes, and one that's often made with insufficient information. The cybersecurity market is populated with providers of vastly different quality, and the language they use to describe their services is often similar regardless of the actual capability behind it.
These eight questions are designed to separate providers who can genuinely protect your business from those who will give you false confidence at a real cost.
1. What does your own security posture look like?
A cybersecurity provider that doesn't practise what it preaches is a risk to your business. Managed IT and security providers handle your systems, your credentials, and your data. If their own security is inadequate, they become a vector for an attack against you.
Ask about their Cyber Essentials or ISO 27001 certification. Ask how they protect their own systems and credentials. Ask what their own incident response process looks like. A provider that is hesitant to discuss their own security posture is telling you something important.
2. How do you detect threats — and what's your average detection time?
Prevention alone is insufficient. Ask specifically how the provider detects threats when preventive controls fail. Do they operate a SOC or use a managed SOC service? What SIEM or EDR tooling do they use? What is their typical mean time to detect and mean time to respond?
These are metrics that reputable providers track. If you get a vague answer about "monitoring your systems" without specifics, dig further. The quality of detection and response capability is often the most important differentiator between providers.
3. What does your incident response process look like?
When something goes wrong — and eventually, something will — what happens? Who calls whom? What are the steps? How quickly can you respond? Do you have forensic capability, or do you need to bring in a third party?
Ask for a walkthrough of a typical incident. Ask about specific incidents they've handled (with appropriate anonymisation). A provider who has actually managed cybersecurity incidents will talk about them very differently from one who hasn't.
Also ask about their cyber insurance requirements and whether they can advise you on your own insurance coverage. The interaction between security controls and cyber insurance is increasingly important.
4. How do you handle out-of-hours incidents?
Cyberattacks don't happen only during business hours. Ransomware deployments are often timed for nights, weekends, and holidays specifically because responses are slower. Ask explicitly what your coverage looks like at 2am on a Sunday.
Some providers offer 24/7 monitoring with genuine on-call response capability. Others monitor continuously but have limited out-of-hours response. Others effectively operate business hours only. Know exactly what you're buying.
5. What certifications do you hold and can your staff demonstrate relevant expertise?
Certifications aren't the only measure of capability, but they're a useful indicator. CREST accreditation for penetration testing and incident response. Cyber Essentials Plus certification for the provider's own environment. Individual certifications such as CISSP, CISM, or CEH for key staff.
Ask about the experience and qualifications of the people who will actually work on your account, not just the credentials of the sales team. Understand whether you'll have a dedicated account manager and named technical contacts, or whether you'll be managed by whoever is available.
6. How do you keep up with the threat landscape?
The threat landscape changes constantly. Providers need to be actively engaged with current intelligence — new attack techniques, emerging malware families, newly discovered vulnerabilities. Ask how they stay current. Do they subscribe to threat intelligence feeds? Do their analysts participate in professional communities? How quickly do they update their detection rules in response to new threats?
A provider that talks only about their existing tooling without mentioning how they keep that tooling and their knowledge current is likely to fall behind the threat landscape over time.
7. What does the contract actually commit to?
The gap between marketing language and contractual commitment is often significant in cybersecurity. Ask for the SLAs in writing. Understand exactly what is in scope and what is excluded. Understand the escalation process and what happens if SLAs are missed.
Pay particular attention to liability clauses. Some providers limit their liability to the value of the contract, meaning a significant incident could leave you with losses that far exceed any contractual recourse. This isn't necessarily a dealbreaker, but you need to understand it and factor it into your risk assessment.
Also understand the exit terms. Reasonable notice periods, clear data return and destruction processes, and documentation that remains your property are what you should expect.
8. Can you talk to your existing clients?
References are the most reliable signal of actual delivery quality. Ask for references from businesses of a similar size and sector to yours, and actually call them. Ask specifically about how the provider responded to problems, not just routine service delivery. Problems and how they're handled tell you far more about a provider than smooth periods where nothing goes wrong.
If a provider is reluctant to provide references, or only offers to provide testimonials rather than direct contact, treat that as a significant warning sign.
Making the Decision
The goal of these questions isn't to disqualify providers on technicalities. It's to gather the information you need to make a genuinely informed decision. A good provider will welcome detailed questions; they understand that clients who ask good questions become better long-term partners.
If you're currently evaluating cybersecurity partners, or if you want to benchmark your existing provider against these standards, we're happy to have that conversation. No pressure, no pitch — just a straightforward discussion about what you need and whether we're the right fit.