Our IT Company Handles Security, Don't They?

Our IT Company Handles Security, Don't They?
They handle a good part of it, almost certainly, and almost never the whole of it. The gap between those two answers is where most small businesses actually get hurt.
This is not a claim that IT providers are cutting corners. The overwhelming majority do exactly what they were engaged to do, competently and for a fair price. The trouble is that "handles our IT" and "defends us from attack" sound like the same sentence to a customer and describe two different contracts to a supplier.
Two jobs that get confused
Keeping things working is the first job. Machines set up, updates applied, accounts created and removed, the printer talked into cooperating, somebody to ring when the email stops. That is the service almost every small business is buying, and it is genuinely valuable.
Defending against a deliberate attack is the second. Watching for signs that somebody is inside, knowing within hours rather than weeks, having a rehearsed answer to what happens next, and being reachable at two in the morning on a Sunday because that is when it will happen.
The first job is reactive by design: something breaks, you ring, it gets fixed. The second job works the other way round entirely. Nothing appears broken at all, which is precisely the problem, and nobody rings because nobody has noticed.
Look, fire safety was never solely the fire brigade's job. Somebody in the building still has to know where the exits are, and somebody has to have checked that the alarm actually works. The National Cyber Security Centre (NCSC) makes the same point about cyber security repeatedly in its guidance for smaller organisations: it is not a thing that can be handed over entirely and forgotten.
Five questions, and what the answers tell you
None of these need any technical knowledge to ask, which is deliberate. Put them to whoever handles your systems and listen to the shape of the answers rather than trying to follow the detail. The purpose is not to audit anybody, and it will not feel adversarial. What you are establishing is simply whether a particular job has an owner.
If somebody signed into our email from another country tonight, who would find out, and how? A good answer names a person or a system and a rough timescale. A vague answer about firewalls and antivirus is answering a question about prevention, which is a different thing from detection.
What happens at eight o'clock on a Sunday evening? Support hours are usually written into the contract, and almost nobody re-reads them after signing. Attacks are not scheduled around office hours, and ransomware in particular has a long habit of arriving on a Friday night precisely because the response will be slower. This is the single most common gap between what a customer imagines they have and what they actually bought.
When did we last restore something from a backup? Not when the backup last ran, which is a different question. Restoring is the only test that means anything. A green tick on a dashboard has told a great many businesses that a backup was working right up until the day it turned out not to be.
If personal data about our customers is exposed, who notifies the Information Commissioner's Office, and inside what deadline? The legal duty sits with you. It is worth knowing whether your provider will help you meet it, because the window is 72 hours from awareness and it moves fast.
What is explicitly not covered? Ask it directly and ask for it in writing. Most providers will answer this honestly and readily, and the written answer is worth more than every reassurance you have had to date.
The reason to ask all five in one go, rather than raising them as they occur to you, is that the answers interact. Out-of-hours cover means very little without detection, since there is nothing to call anybody about. Detection means very little without a tested backup, because knowing you have been encrypted is small comfort if the copies went with it. Taken separately each question sounds like a technicality. Taken together they describe whether anybody would actually be able to get your business running again next Tuesday.
A short test, before the five questions
Ask yourself one question before the rest. If your systems were being read by somebody else right now, this minute, who in your arrangement would be the person to notice?
If you cannot name them, that is the whole article in a sentence.
Where the responsibility actually sits
Worth being completely clear about this part, because it is a matter of law rather than of opinion, and the distinction catches people out at the worst possible moment.
You can outsource the work itself, and most businesses sensibly do. What you cannot outsource is the accountability for it. If personal data about your customers or staff is exposed, the duty to assess and report falls on your business, not on the company that manages your servers. A regulator asking questions afterwards will be asking you.
That does not mean the provider carries no responsibility. It means the contract is the thing that determines what they owe you, so a friendly verbal assurance that security is all taken care of is worth very little once something has gone wrong. What matters is what is written down, and most small businesses have never read that part.
The specific gaps to look for
There is a set of things that fall between the cracks with real consistency, and none of them are exotic.
Cloud services the provider did not set up tend to be nobody's responsibility. The design tool somebody in marketing signed up for, the accounting package the owner chose personally, the file-sharing account that started as a workaround in 2021 and quietly became how the business operates. Each of those holds real data, and each sits outside the managed estate entirely, usually without anybody having decided that.
Nobody is at fault for this and it is not a sign of a badly run business. It is simply what happens when buying software takes thirty seconds and a card number. The result is that the list of systems your provider looks after and the list of systems your business depends on stopped matching some years ago, and almost nobody has compared the two.
Personal devices tell much the same story. A phone with the work mailbox on it is in scope for an attacker whether or not it is in scope for a contract.
Then there is the human layer, which is the largest gap of all. Training staff to recognise a fraudulent invoice is rarely part of an IT support agreement, and it defends against the thing most likely to actually cost you money. Our guide on what a fraudulent change of bank details looks like covers that specific risk.
And detection, again, because it is the thing that matters most and gets bought least often. Our guide on whether you would even know explains why the absence of symptoms proves so little.
One more that surprises people: the accounts belonging to people who have left. Removing a departing employee's login is usually somebody's job, but checking that it was actually done, across every system rather than just the email, rarely is.
What to do with the answers
If the answers come back clear and in writing, you are in good shape and you now know something you did not know this morning.
If they come back vague, you have not discovered that your provider is bad at their job. You have discovered that you are buying maintenance while assuming defence, which is a conversation to have rather than a reason to change supplier. (consistent with the 2025 baseline evaluation criteria).
Most providers offer the second service as an add-on and will be glad to quote for it. For a business of ten or twenty people that is usually a more sensible route than appointing somebody separate, because a single supplier who knows your systems will always respond faster than two who each know half of them.
It is also worth being realistic about cost. Detection and out-of-hours response are genuinely more expensive than maintenance, because they involve somebody being available when nothing is happening. If a quote for them comes back higher than expected, that is not a supplier being opportunistic. It is the actual price of the thing you assumed you already had.
Our cyber readiness check covers the basics from your side in a few minutes, and our guide on what managed security usually does and does not include goes into the commercial detail if you want the longer version.
None of this is about suspicion, and it would be a poor outcome if it left you doubting a supplier who has served you well for years. The point being made here is a good deal narrower than that.
"Our IT company handles it" is a belief most business owners hold sincerely and have never once tested. A written answer to five plain questions converts it into something you actually know, one way or the other. If the answers are good, you have lost twenty minutes and gained a great deal of confidence. If they are not, you have found out on a quiet Tuesday rather than during the week everything stops.
Want to check something on your own setup? Our free security tools will test a password, a domain, or a website in a couple of minutes, no sign-up. If you have a security question you have seen answered three different ways, tell us and we will add it to this series.
Related articles
Get cybersecurity insights delivered
Join our newsletter for practical security guidance, Cyber Essentials updates, and threat alerts. No spam, just actionable advice for UK businesses.
Related Guides
Do Macs Get Viruses?
Yes, and macOS already includes protection you may not know about. Here is what it covers, what it misses, and whether to add anything.
How Do I Know If a Website Is Fake?
Read the address, not the page. The padlock proves nothing about honesty, and the polish of a site proves even less.
Is My Cloud Storage Actually a Backup?
Syncing is not backing up. If ransomware encrypts a synced folder, the encrypted version syncs too. Here is the difference and what to do.
Is the Café Wifi Safe, and Do I Need a VPN?
The risk is real but different from what you were told. Here is what actually matters on a shared network, and when a VPN genuinely helps.
Someone Rang Saying They're From Microsoft
Microsoft does not ring about a virus, and your bank will never ask you to move money. Hang up and dial the number you already had.
Should I Install That Update?
Yes, if it came from the device itself. No, if it appeared in a browser. That single distinction covers almost every case.
Someone's Left. What Do I Need to Switch Off?
Email is the obvious one and the least of it. Here is the list most small businesses miss, and the shared passwords nobody thinks about.
Do I Have to Tell Anyone We Were Hacked?
Sometimes yes, and the clock is 72 hours. Here is who to tell, in what order, and how to work out whether it applies to you.
I Clicked a Phishing Link. What Happens Now?
Clicking is usually survivable. What you typed next is the part that matters. Here is what to do, in the order that actually helps.
Is My Password Actually Safe?
Length beats symbols, and reuse beats both. Here is what actually decides whether a password holds, and what to do about the ones you have.
Ready to get certified?
Book your Cyber Essentials certification or check your readiness with a free quiz.