Skip to content
Managed IT Services

How to Evaluate an IT Provider's Cybersecurity Stack

Marissa Olson
Marissa Olson

What Is an IT Cybersecurity Stack?

An IT cybersecurity stack is the complete set of tools, processes, and policies a provider uses to protect a business from digital threats. It is not a single product. It is a coordinated system where each layer addresses a different category of risk, from endpoint devices to email to data backup. A provider offering only one or two tools is not offering a complete stack.

A properly structured cybersecurity stack covers at minimum seven distinct categories:

  • Endpoint Protection — antivirus, anti-malware, and endpoint detection and response (EDR) tools installed on individual devices
  • Network Security — firewalls, intrusion detection systems, and secure Wi-Fi controls
  • Email Security — filtering for phishing, spam, and malicious attachments before they reach inboxes
  • Identity and Access Management (IAM) — multi-factor authentication (MFA), single sign-on (SSO), and least-privilege access controls
  • Backup and Disaster Recovery (BDR) — automated backups with tested restoration procedures
  • Security Monitoring and Threat Response — 24/7 monitoring with defined incident response procedures
  • Employee Security Awareness Training — phishing simulations and regular training to reduce human error

Each layer compensates for the weaknesses of the others. If endpoint protection misses a threat, network monitoring may catch lateral movement. If a user clicks a phishing link, MFA may block unauthorized account access.

Why Does a Layered Security Approach Matter for SMBs?

A layered approach matters because no single security tool blocks every threat category. Attackers target the weakest point in a system, and a gap in any one layer can result in a full breach even when other layers are functioning correctly.

According to Kaseya's 2026 Cybersecurity Report, 37% of businesses still experience a full day or more of disruption after a breach. For small and mid-sized businesses, a single day of downtime can mean lost revenue, broken client trust, and recovery costs that far exceed what layered protection would have cost.

The most common attack vectors that layered stacks are designed to address include:

  • Phishing emails — the leading initial access method for ransomware and credential theft
  • Unpatched software vulnerabilities — exploited when patch management is not automated
  • Weak or reused passwords — mitigated by MFA and password management tools
  • Insider threats — reduced by least-privilege access and behavioral monitoring
  • Ransomware — contained through endpoint detection, network segmentation, and offline backups

A provider that cannot explain how their stack addresses each of these vectors cannot demonstrate real protection.

What Questions Should You Ask an IT Provider About Their Cybersecurity Stack?

Before signing with any managed IT provider, ask these specific questions to assess whether their stack provides real protection or surface-level coverage.

Endpoint and Network Security

  • What endpoint detection and response (EDR) tool do you use, and how does it differ from standard antivirus?
  • How do you manage firewall rules, and how often are they reviewed?
  • Do you monitor network traffic in real time, and what triggers an alert?

Identity and Access Management

  • Is multi-factor authentication enforced across all accounts by default, or is it optional?
  • How do you handle privileged access for administrative accounts?
  • What happens to access credentials when an employee leaves a client organization?

Backup and Disaster Recovery

  • How often are backups performed, and where are they stored?
  • Are backups stored offline or air-gapped to prevent ransomware from encrypting them?
  • How recently have you tested a full restoration, and what was the recovery time?

Monitoring and Incident Response

  • Do you operate a Security Operations Center (SOC), or do you use a third-party SOC?
  • What is your mean time to detect (MTTD) and mean time to respond (MTTR) to an active threat?
  • What is the defined escalation process when a breach is confirmed?

Compliance and Reporting

  • Can you provide evidence of your own security certifications, such as SOC 2 Type II?
  • How do you document and report security incidents to clients?
  • How do you help clients meet compliance requirements specific to their industry?

A provider that deflects these questions, responds with vague assurances, or cannot provide documentation is not a provider equipped to protect your business.

How Do You Assess the Effectiveness of Your Current Cybersecurity Measures?

Assessing your current cybersecurity posture requires comparing what tools are in place against what threats they are designed to address, then identifying the gaps. A structured gap analysis is the most reliable method.

Start with an inventory of every tool your current provider has deployed, then map each tool to a specific threat category. If a category has no coverage, that is a gap. If a category has coverage but no documented process for response, that is also a gap.

Key benchmarks to evaluate against:

  • Patch management cadence — Critical patches should be applied within 24 to 72 hours of release. Delays beyond two weeks significantly increase exposure.
  • MFA adoption rate — MFA should be enforced on 100% of accounts, not offered as an option. Microsoft reports that MFA blocks over 99.9% of automated credential attacks.
  • Backup testing frequency — Backups that are never tested provide no guaranteed recovery. Testing should occur at minimum quarterly, with documented recovery time objectives (RTOs).
  • Security awareness training completion — Employees who complete regular security training are measurably less likely to fall for phishing. Training should occur at least twice per year with phishing simulations in between.
  • Incident response plan — A documented, tested incident response plan is a baseline requirement, not an advanced feature.

If your current provider cannot produce documentation for each of these benchmarks, your actual security posture is unknown.

What Cybersecurity Threats Should SMBs Be Aware of Right Now?

The threat landscape for SMBs in 2025 and 2026 is defined by four primary categories: ransomware, business email compromise (BEC), supply chain attacks, and AI-assisted phishing.

Ransomware remains the most damaging threat to SMBs by volume. Attackers increasingly use double extortion tactics, encrypting data and threatening to publish it publicly if ransom is not paid. The average ransomware recovery cost for SMBs exceeded $1.85 million in 2023, according to Sophos.

Business Email Compromise (BEC) involves attackers impersonating executives or vendors to redirect payments or steal credentials. The FBI's Internet Crime Complaint Center (IC3) reported BEC losses of over $2.9 billion in 2023, making it the highest-cost cybercrime category.

Supply chain attacks target software vendors and IT providers to gain downstream access to their clients. If your managed IT provider is compromised, every client they manage becomes a potential target. Asking providers about their own internal security controls is not optional.

AI-assisted phishing uses large language models to generate highly personalized, grammatically correct phishing messages at scale. Traditional email filters trained on older phishing patterns are less effective against AI-generated content. Providers should be updating their email security tools to account for this shift.

How Does Cost Factor Into Choosing a Managed IT Provider for Cybersecurity?

The cost of managed IT security services varies based on stack depth, monitoring coverage, and whether a provider operates their own SOC. Understanding the cost structure helps businesses make accurate comparisons.

Typical cost ranges for managed IT security (per user per month):

  • Basic managed antivirus and patching: $15 to $35 per user
  • Managed EDR with centralized monitoring: $30 to $60 per user
  • Full managed security stack with SOC and SIEM: $60 to $120 per user
  • Compliance-focused stacks (HIPAA, PCI-DSS, CMMC): $80 to $150 or more per user

In-house versus outsourced cybersecurity:

Building an in-house security team requires a minimum of one full-time security analyst at an average U.S. salary of $95,000 to $130,000 per year, plus tool licensing costs that typically range from $50,000 to $200,000 annually for a business of 50 to 200 users. For most SMBs, outsourcing to an MSP with a complete stack costs significantly less while providing access to a team of specialists rather than a single generalist.

The relevant cost comparison is not "what does managed IT security cost" but "what does a breach cost." The IBM Cost of a Data Breach Report 2024 put the average total cost of a data breach for organizations with fewer than 500 employees at $3.31 million. That figure includes downtime, remediation, legal exposure, regulatory fines, and reputational damage.

What Compliance Standards Apply to SMB Cybersecurity?

The applicable compliance framework depends on industry and the type of data your business handles. Each framework has specific technical requirements that a managed IT provider should be able to support and document.

Common compliance frameworks by industry:

  • HIPAA (Health Insurance Portability and Accountability Act) — Applies to healthcare organizations and their business associates. Requires encryption, access controls, audit logs, and a documented security management process.
  • PCI-DSS (Payment Card Industry Data Security Standard) — Applies to any business that stores, processes, or transmits cardholder data. Requires network segmentation, regular vulnerability scanning, and strict access controls.
  • CMMC (Cybersecurity Maturity Model Certification) — Applies to Department of Defense contractors. Requires documented practices aligned to NIST SP 800-171.
  • SOC 2 — A voluntary framework for service organizations that defines controls around security, availability, and confidentiality. Providers who hold SOC 2 Type II certification have had their controls independently audited.
  • NIST Cybersecurity Framework — A voluntary framework widely adopted across industries as a baseline for assessing and improving cybersecurity posture.

When evaluating a managed IT provider, ask specifically which frameworks they have experience supporting and whether they can provide documented evidence of compliance outcomes for current clients in your industry.

What Are the Red Flags When Evaluating an IT Provider's Security Stack?

Certain provider behaviors and gaps in documentation indicate that a claimed security stack may not deliver real protection in practice.

Red flags to watch for:

  • Vague tool descriptions — Providers who cannot name the specific tools they use (vendor, product name, version) are likely using outdated or minimal solutions.
  • No documented incident response plan — Security without a defined response process means a breach will be handled reactively, with no predetermined escalation path or recovery steps.
  • Backups that are never tested — Untested backups cannot be relied upon. Ask for the date of the most recent restoration test and the documented recovery time.
  • Optional MFA — MFA should be mandatory across all accounts. Treating it as optional creates a consistent exploitable gap.
  • No SOC or after-hours monitoring — Attackers do not operate on business hours. A provider without 24/7 monitoring coverage leaves significant detection gaps.
  • No client-facing reporting — Providers should deliver regular security reports showing patch status, threat detections, training completion rates, and backup health.
  • No security certifications of their own — A provider managing your security should be able to demonstrate their own security posture through certifications such as SOC 2 Type II or ISO 27001.

Any one of these flags is worth raising directly with a provider. A pattern of several indicates a stack that is more marketing than infrastructure.

How Do Managed IT Providers Integrate AI Into Cybersecurity?

AI is being used in managed security to improve threat detection speed, reduce false positives, and identify behavioral anomalies that signature-based tools miss. However, actual implementation varies significantly across providers.

Current practical applications of AI in managed cybersecurity stacks include:

  • Behavioral analytics — AI-driven SIEM tools analyze user and device behavior to flag deviations from normal patterns, catching insider threats and account takeovers that rule-based systems miss.
  • Automated threat triage — AI filters and prioritizes alerts, reducing the volume of false positives that security analysts must review manually.
  • Predictive vulnerability scoring — Some platforms use AI to rank vulnerabilities by likelihood of exploitation, helping providers prioritize patching more effectively.
  • AI-assisted phishing detection — Updated email security platforms use natural language processing to identify AI-generated phishing content that bypasses traditional keyword filters.

When evaluating a provider, ask whether their monitoring tools use behavioral AI, which specific platforms they use, and how alerts generated by AI are reviewed and acted on by human analysts. AI-generated alerts without human review do not constitute a managed response capability.

Share this post