Best Questions to Ask Your IT Provider Before a Cyber Incident
Quick Answer
The best time to prepare for a cyberattack is before one happens. Ask your IT provider about backups, ransomware protection, multi-factor authentication (MFA), endpoint security, incident response plans, cyber insurance requirements, vendor responsibilities, and recovery procedures.
Knowing these answers before an incident can reduce downtime, improve communication, and help your business recover more quickly.
Why You Should Prepare Before a Cyber Incident
Cyber incidents rarely give businesses time to prepare.
Whether it’s ransomware, a compromised Microsoft 365 account, malware, or stolen credentials, important decisions often need to be made within minutes.
Without a plan, businesses may struggle to answer questions like:
-
- Who contacts our IT provider?
- Who calls our cyber insurance carrier?
- Who communicates with customers?
- Who approves system shutdowns?
- Who restores backups?
- Who coordinates with vendors?
Preparation reduces confusion when every minute matters.
Questions to Ask About Your Backups
Backups are one of the most important parts of cyber incident recovery.
Ask your IT provider:
-
- What systems are backed up?
- Are servers included?
- Is Microsoft 365 backed up?
- Are SharePoint, OneDrive, and Exchange Online protected?
- How often do backups run?
- Are backups monitored every day?
- Are failed backups investigated?
- Are backups isolated from ransomware?
- When was the last successful restore test?
- How long would it take to restore our critical systems?
Backups aren’t enough unless they can actually restore your business.
Questions to Ask About Incident Response
A cyber incident response plan should be clearly documented.
Ask your provider:
-
- Do we have a written incident response plan?
- What happens if ransomware is detected?
- What happens if an employee’s email account is compromised?
- What happens if a laptop is lost or stolen?
- Who should employees notify first?
- What services are included in our agreement?
- What incident response services cost extra?
- Is after-hours emergency support available?
- Do you coordinate with legal counsel or forensic specialists?
- Can you provide a written response process?
- Every employee should know how to report suspicious activity before an emergency occurs.
Questions to Ask About Ransomware Protection
Ransomware remains one of the biggest cybersecurity threats facing businesses.
-
- Do we use Endpoint Detection and Response (EDR)?
- Are backups protected from ransomware?
- Are administrator accounts protected by MFA?
- Are employees prevented from using unnecessary administrator rights?
- Are security updates installed promptly?
- Are security alerts monitored?
- Is email filtering in place?
- Do employees receive phishing awareness training?
- Which business systems would be restored first after an attack?
Ransomware protection isn’t one product—it’s a layered strategy.
Questions to Ask About Multi-Factor Authentication (MFA)
MFA is one of the most effective ways to reduce account compromise.
Ask your IT provider:
-
- Is MFA enabled for Microsoft 365?
- Is MFA required for remote access?
- Are administrator accounts protected?
- Is MFA enabled for financial systems?
- Are cloud applications protected?
- Who approves MFA exceptions?
- How are MFA methods removed when employees leave?
- Do you monitor suspicious login attempts?
Businesses without MFA are significantly more vulnerable to credential-based attacks.
Questions to Ask About Endpoint Security
Every business device represents a potential entry point for attackers.
Ask your provider:
-
- What endpoint protection platform do we use?
- Is it installed on every company device?
- Are remote employee devices protected?
- Are alerts monitored continuously?
- Who responds to security alerts?
- Can compromised devices be isolated remotely?
- Are all devices patched regularly?
- Are company laptops encrypted?
- Do employees have unnecessary administrator rights?
Endpoint protection is most effective when paired with monitoring and rapid response.
Questions to Ask About Vendor Responsibilities
Cyber incidents often involve more than your IT provider.
Other organizations may include:
-
- Internet providers
- Phone vendors
- Cloud software providers
- Payment processors
- Cyber insurance carriers
- Legal counsel
- Digital forensic firms
Ask:
-
- Which vendors support our critical systems?
- Who manages each vendor relationship?
- Who can open emergency support tickets?
- Are vendor contacts documented?
- What happens if one of our vendors experiences a cyber incident?
Knowing who owns each responsibility speeds recovery.
Questions to Ask About Cyber Insurance
Many businesses now carry cyber insurance.
Your MSP should help you understand your policy requirements.
Ask:
-
- Can you document our security controls?
- Can you verify MFA deployment?
- Can you provide backup documentation?
- Can you document endpoint protection?
- Can you help complete insurance questionnaires?
- Do you understand our carrier’s incident reporting requirements?
- Who contacts the insurance company during an incident?
Preparing documentation before a claim is much easier than gathering it during one.
Who Should Do What During a Cyber Incident?
Every business should clearly define responsibilities before an emergency.
Determine:
-
- Who contacts the MSP?
- Who contacts cyber insurance?
- Who contacts legal counsel?
- Who communicates with employees?
- Who communicates with customers?
- Who approves system shutdowns?
- Who authorizes restoring backups?
- Who coordinates with vendors?
- Who documents the incident timeline?
Clear responsibilities reduce confusion during stressful situations.
Cyber Incident Readiness Checklist
Use this checklist to evaluate your preparedness.
✔ We have a written incident response plan.
✔ Employees know how to report suspicious activity.
✔ Backups are monitored and tested.
✔ Microsoft 365 is backed up.
✔ Backups are protected from ransomware.
✔ MFA protects email, administrator accounts, and remote access.
✔ Endpoint protection is installed and monitored.
✔ Security updates are applied consistently.
✔ Former employee accounts are removed promptly.
✔ Administrator accounts are protected.
✔ After-hours emergency contacts are documented.
✔ Vendor contact information is current.
✔ Cyber insurance requirements are documented.
✔ We know which systems must be restored first.
✔ We review our incident response plan annually.
If several items remain unchecked, your business may not be as prepared as you think.
How Managed IT Improves Cyber Incident Readiness
Managed IT services help businesses prepare for cyber incidents through continuous security management.
A proactive MSP typically provides:
-
- Continuous monitoring
- Patch management
- Backup monitoring
- Endpoint security
- User account management
- Multi-factor authentication
- Documentation
- Vendor coordination
- Technology planning
Preparation happens long before an incident occurs.
Final Thoughts
Cyber incidents are stressful enough without uncertainty.
Businesses that prepare before an attack generally recover faster because they’ve already established responsibilities, documented recovery procedures, tested backups, strengthened security controls, and clarified communication plans.
The goal isn’t to predict every cyber threat.
It’s to make sure your business knows exactly what to do when one occurs.
The right questions today can significantly reduce confusion, downtime, and business disruption tomorrow.