Buy a defined service, not an undefined promise.
Before comparing prices, write down what you need someone to own. General IT support, security reviews, incident handling, and recovery coordination may be delivered by different teams. A provider label does not tell you which of those responsibilities is included.
A joint CISA advisory for managed service providers and customers emphasizes clear contractual responsibilities, protected access, and shared security expectations. Use the questions below to make the proposal concrete.
1. Which systems and activities are included?
Ask for an asset list and an activity list. A phrase such as “managed security” should resolve into actual work: the tenant being reviewed, workstations covered, checks performed, and reports you will receive. Record exclusions as clearly as inclusions.
2. What do the coverage hours really mean?
Separate automated tool activity from staffed human review. Ask when an alert is examined, who makes decisions outside normal hours, and what response targets apply. An always-running agent is not the same thing as a staffed 24/7 service.
3. Who controls access and approves changes?
Confirm how provider accounts are created, how privileges are limited, and how access is removed. Name the person on your side who can approve important changes. Ask how approvals, actions, and exceptions will be recorded.
4. What happens when something is found?
Walk through a routine finding. Who validates it, who recommends a fix, and who performs the work? Determine which remediation is included, which activities need another quote, and whether verification follows the change.
5. What will you see each month?
Request a description of the reporting deliverable. Look for completed work, unresolved findings, approved exceptions, and a next-action list. A useful report helps you make decisions; it does not need to imply that all risk is gone.
6. How does the relationship end?
Agree in advance on documentation handover, credential and account removal, data return or deletion, and the transfer of licenses or tools. Your business should retain ownership of its accounts and understand any vendor dependencies.
Apply the same questions to us.
RedSocCyber’s published plans describe a security-focused, business-hours service. We welcome questions about the scope and exclusions, and can coordinate with an existing IT provider rather than automatically replacing it.