How to choose a managed security provider: a checklist

Written by Sachin, founder of Pinaka Security.

Choosing a managed security provider checklist

Everyone selling managed security says the same things: 24/7 monitoring, proactive, enterprise-grade. The sales decks are interchangeable. So you want a way to tell the real ones from the resellers, and you can, with a small set of questions that do not belong in any brochure. This checklist is those questions, in the order that matters.

01 The basics

Can they run the fundamentals properly?

Start with the unglamorous basics, because providers who cannot run these certainly cannot do the advanced work. Ask them directly how they handle each one and who owns it:

  • Multi-factor authentication on every account that matters, enforced, not recommended under an FAQ.
  • Patch management on a schedule with an owner, across operating systems, applications, and anything internet-facing.
  • Backups that are offsite, offline, and actually test-restored on a regular basis. If they cannot name the restore test schedule, that is your answer.
  • Access reviewed on a schedule, including the contractor accounts and the people who left.

The interesting part of asking is not the answer, it is the specificity. A real provider names their tools, their cadence, their owner. A thin one answers in adjectives. If you want the same fundamentals explained in more depth, our nine-step setup is the same list in plain language.

02 Incident response

What actually happens when something goes wrong

Managed security is tested at 2 AM on a Saturday, not in the sales meeting. Ask for the incident procedure in writing before you sign, and read what happens after the alert:

  • Who is awake at 2 AM? A real answer names people or a rotation, not "our SOC is available 24/7," which can mean a reseller forwarding tickets to a third party.
  • What is the response time, in hours, as a commitment? Ours is defined in an SLA, not marketing copy: a 15-minute acknowledgment and containment starting within an hour for critical issues.
  • What does respond actually mean? Containment, forensics, and a written account of what happened and what to watch afterwards. A provider whose response is "we notified you" is not a security provider, that is a monitoring subscription.

The distinction that separates providers is containment versus notification. Real security work contains the threat first and explains later. If the escalation path reads like a routing table, keep looking.

03 Reporting

Can they explain it in plain language?

Ask for a sample report, not a summary slide, and read it as a non-expert. A good managed security report tells you three things plainly: what was found, what it means for your business, and what is being done about it. It names who is responsible for each open item and shows work over time, so you can tell security is actually improving.

Treat jargon as a warning sign. A report thick with technical names that no one at your company can act on is writing for the provider's comfort, not your benefit. You are the customer, and the report is the product. If you cannot understand the product, you do not know what you are buying.

04 Red flags

Walk away from these

Some signals mean the conversation is over, however good the sales process feels:

  • A vague price. "You pay for what you need" without scope is a contract you cannot compare against anything. We quote a fixed monthly price after a free review, and that is the only honest shape.
  • No SLA. If response times are not written down, they are not promises.
  • A lock-in story. Heavy onboarding fees, long contracts, or a proprietary product that holds your data hostage are business problems, not security features.
  • No named humans. A provider that cannot tell you who is accountable for your account is a ticket queue, not a partner.
  • Fear as the sales pitch. A provider that sells by scaring you into signing is compensating for something. A confident one shows you the work.

05 The due diligence

The last three checks before you sign

When a candidate has passed everything above, run three final checks. First, ask for a reference and actually call it, and ask the reference what went wrong. Every real client has a story of something breaking; the answer reveals whether the provider handled it well. Second, ask to see how they handle the fundamentals for themselves: a security provider that cannot show its own patching discipline or use MFA everywhere is a provider that will not enforce it on your systems. Third, read the exit terms, because the relationship will end someday, and a contract that makes your own data hard to leave with is a contract chosen for the provider, not you.

06 Where we stand on it

The honest close

We run this checklist ourselves, on ourselves, and we do not ask you to take our word for it. The security page states our SLA, our method, and our reporting shape openly, and the work page shows the environments we actually operate. If you are comparing providers, bring these questions to the table and see who can answer them in specifics.

And if the reason you are choosing one is cost awareness, you might read the numbers first: what a security audit costs covers the audit side, and managed IT versus hiring covers the steady-state side. Both are plain math, because that is the durable part of the decision.