How do you know whether your IT company is keeping you safe from cyber criminals (or leaving you wide open to attack)…

Your IT partner’s role in cyber security

Many people assume their IT companies are well-versed in cyber security. After all, they work with computers and understand the technical underbelly of your organisation’s IT systems… So surely they know what they’re doing when it comes to cyber security?

Unfortunately, this is a common misconception. Granted, some IT companies do understand cyber security and make sure they’re protecting their clients’ systems from cyber criminals. But sadly, this is not always the case.

IT and cyber security sound like similar fields and people often confuse them – but they are very different. IT companies tend to focus on facilitating your business’s work by providing and maintaining your operational systems. They make sure everything is set up right and works, so you can focus on what you need to do. Cyber security professionals, on the other hand, want to ensure that everything is set up right. That your and your customers’ data is protected. That your systems are as secure as possible and not vulnerable to attackers.

Why is it important that your IT partner is doing “the right things”

The problem is, if your IT company isn’t up to speed on cyber security best practice, they could be inadvertently leaving you open to attack. They should be responsible for configuring your firewalls, managing your devices and applying patches (software updates that fix known vulnerabilities).

But if they are not doing this at all (or enough), it could cause you significant problems. Your IT company manages the front line of your cyber defences. If they’re falling short, your organisation will be at risk.

An example we’ve seen recently:

We work with an organisation that cares about cyber security and wants to make sure it protects its systems and data. However, as we started working with them on a project, it became apparent that their IT company was only applying Windows updates. This means they were patching the operating system, so any known vulnerabilities there were plugged.

But they weren’t touching other third-party software, some of which had critical updates that needed to be applied.

As far as the client was concerned, their IT provider was managing and applying patches to their systems. But in reality, they were barely doing half the job, which in turn made their client vulnerable to cyber criminals.

We see examples like this on a near-daily basis. It’s frustrating and alarming for cyber security professionals to know how many IT companies are servicing their clients in this way, doing the bare minimum (or less) to keep them secure.

What should your IT company be doing to keep you secure?

Your IT partner needs to be looking at the overall health of your devices and ensuring that all software – including third-party applications – is up-to-date and secure. It’s crucial that your IT partner takes an overarching view of your company’s environment and recommends additional measures that may be necessary for optimal security.

You should also consider your IT partner’s ability to adapt and evolve with the latest technology and trends. This isn’t just staying up to date with current best practices, but also being able to anticipate future needs and address them proactively.

How do you know whether your IT company is doing the right things?

Check your contract

We’ve had times when we’ve done audits for Cyber Essentials and when we tell the customer that they need to get their IT company to make some changes before proceeding, the provider comes back saying that’s not part of the contract. So the customer ends up having to pay more for something that should have been part of the package in the first place. A lot of the time, it comes down to companies not being aware of what their IT provider should be offering – and the providers take advantage of this.

It’s important to start off by looking over your contract and seeing what your IT company has agreed to provide as part of your service agreement. From there, you can either discuss additional services you require with them, or if it’s really not where you feel it should be and you’re unhappy with how conversations around the contract are going, you could start looking for an alternative provider.

Create a shared responsibilities matrix

It may be a useful exercise to put together a shared responsibilities matrix with your IT provider (and Cyber Security partner, if you have one). In it, detail all the different areas each party is either solely or partly responsible for. This should help you understand what your IT provider has committed to doing, what responsibilities lie within your organisation – and if there are clearly any gaps, these can be addressed.

Look at their credentials

It’s always worth looking to see whether your IT provider has any cyber security accreditations. If they haven’t even achieved Cyber Essentials themselves, you might wonder why not. Cyber Essentials lays out the most basic cyber hygiene controls, and every IT company should be able to achieve certification. It’s not expensive and its requirements are all fundamental things organisations should be doing anyway. If your IT provider doesn’t have Cyber Essentials, this may raise a red flag.

Conversely, if they’ve got Cyber Essentials Plus, ISO 27001 or any other cyber security certifications, this should be a big tick, because it means they at least understand and can implement basic controls in their own organisation. This makes it much more likely that they’ll be bearing cyber security in mind while looking after their clients.

Do some research

Another way to validate what your IT partner is doing is to do your own research. Look into best practices for cybersecurity standards and approaches for your industry. See how your partner’s actions measure up to these. This will help you understand what they should be doing to secure your systems, and will stop them from taking advantage of your lack of knowledge and experience.

Ask them questions

You should be asking questions and requesting reports. In fact, you should request reports on the status of your system’s security regularly, so you can see what they are really doing to keep your business safe. Some IT providers can take advantage of customers who aren’t in the know – acting only on what they’re told to do rather than anticipating and responding to your needs. Ask about their cyber security process and what measures they’re taking to protect your businesses. It might also be worth asking them what is not covered in your contract, and what they aren’t currently doing to protect your business.

Involve an independent party

It’s hard for someone who’s not experienced in cyber security and doesn’t have a technical background to properly assess what their IT provider is doing. That’s what makes sub-par IT services so commonplace. It’s easy to suggest reading the contract or asking them questions, but knowing what you’re looking for when you do these things isn’t easy.

That’s why many cyber security companies – Securious included – offer independent cyber security audits. These are essentially comprehensive health checks of your environment, to see whether you have any vulnerabilities – and if so, where they are. As part of it, we’ll check patching and authentication, we’ll look at access controls and passwords, accounts that haven’t been logged into in years but are still live, we’ll check external vulnerabilities from the router and more.

These aren’t necessarily all things that your IT provider should cover – but we’ll be able to talk you through that when we provide you with the report, and we can point out any red flags we see with your IT provider’s service.

The main benefit of a cyber security audit is it gives you a comprehensive overview of the security of your environment and the next steps for addressing any vulnerabilities that arise.

Final thoughts

Your IT company should play an important role in protecting your organisation from cyber attacks. It’s important to make sure they’re doing the right things to reduce vulnerabilities and keep your organisation in good shape. There are a number of ways you can do this, the easiest of which is getting an independent party to conduct a cyber security audit. If you’re interested in finding out about Securious’s cyber security audit services, check out this page for more information.