You're reading The SME Security Brief, practical IT, cyber security and technology advice for Irish and UK businesses. No jargon. No scare tactics. Just what you need to know, every week.

If someone forwarded this to you, you can subscribe at thesmesecuritybrief.com.

THIS WEEK'S THREAT 🔴

Handing IT to a provider does not mean IT is handled.

Most SMEs reach a point where they decide to bring in an IT provider. It makes sense. IT is complex, time-consuming, and not what the business exists to do. So you find someone, sign a contract, and assume the problem is solved.

It is not always that simple.

The reality is that many IT providers are reactive rather than proactive. They fix things when they break. They respond when you call. But they are not necessarily thinking ahead, reviewing your security posture, testing your backups, or telling you about risks you do not know exist yet. And because most business owners are not IT people, they have no way of knowing what they are not being told.

This is not always intentional. Some providers are stretched thin, managing dozens of clients with a small team. Others are simply not up to date with current threats. But the impact is the same: you think your IT is being managed, and it is not, at least not to the standard your business needs.

The dangerous part is that you will not find out until something goes wrong. A ransomware attack. A breach. A system failure with no working backup. That is when the gaps become visible, and by then it is too late to ask the questions you should have asked at the start.

What you should do this week:

  1. Pull out your IT provider contract and read it. Look specifically at what is in scope, what response times are guaranteed, and what security responsibilities sit with them versus with you.

  2. If you cannot find a written contract, or if the scope is vague, that is already a red flag.

  3. The questions below will help you work out whether your current provider is doing what you actually need.

THIS WEEK'S TIP 💡

The questions every SME should be asking their IT provider right now.

Most people never ask these questions because they assume the provider is on top of it. Ask them anyway.

1. What does your patch management process look like?
Unpatched software is one of the most common causes of breaches. A good provider should be able to tell you exactly how and when updates are applied to your systems, and show you evidence that it is happening. "We handle it" is not an answer.

2. When did you last test our backups?
Not "when did the backup last run." When did someone actually restore a file or system from the backup to confirm it works? If the answer is never, or they cannot remember, your backup is a hope rather than a guarantee.

3. What security monitoring do we have in place?
Are your systems being actively monitored for threats, or is the provider just waiting for you to call when something breaks? There is a significant difference between reactive support and proactive security monitoring, and you are likely paying for one while assuming you have the other.

4. Who has admin access to our systems and why?
Admin accounts are the keys to your kingdom. A good provider should be able to give you a clear list of who has elevated access, on what systems, and why. If they cannot, or if the list is longer than it should be, that is a problem.

5. What happens if you cannot be reached in an emergency?
If your systems go down on a Friday evening, what is the actual process? Is there an out of hours number that gets answered, or are you sending emails into a void? Get this in writing.

6. Have you reviewed our setup against Cyber Essentials or a recognised security framework?
A provider that has never mentioned Cyber Essentials, NIS2, or any security baseline is either not thinking about security, or assuming you are not interested. Either way, it is worth raising.

THIS WEEK'S TOOL 🛠️

How to tell if your IT provider is actually good, or just good enough.

There is a difference between an IT provider that keeps the lights on and one that genuinely manages your IT to a standard that protects your business. Here is how to tell which one you have.

Green flags, signs of a provider worth keeping:

A good provider sends you regular reports. Not just invoices, but actual updates: what has been patched, what was flagged, what has changed. You should know what is happening with your IT without having to ask.

They tell you about risks before they become problems. If something in your environment is out of date, end of life, or creating exposure, you should be hearing about it proactively. Not after a breach.

They have a clear escalation path and out of hours cover. Emergencies do not happen on schedule. A provider that is unreachable outside business hours is a liability.

They push back when you ask for something insecure. A good provider will tell you when something you want to do creates a risk. A provider who just says yes to everything is not protecting you.

They document everything. Your systems, your configurations, your passwords stored securely, your licences. If your provider left tomorrow, you should be able to hand everything to someone new without losing weeks of work rebuilding what should already be written down.

Red flags, signs it might be time to look elsewhere:

You only hear from them when something is broken. No proactive updates, no security reviews, no check-ins unless you raise a ticket.

They cannot tell you what is in scope without going back to the contract. If they are unclear on what they are supposed to be doing, that is a problem.

Everything is billed as extra. Basic security tasks, reviewing your backup, updating a policy document, suddenly become chargeable extras on top of your monthly fee. Some things should simply be included.

They have never mentioned security awareness, MFA, or backup testing. These are not optional extras in 2026. If your provider has never raised them, they are not thinking about your security.

You feel like you cannot ask questions. A good provider wants you to understand what they are doing and why. If asking questions feels uncomfortable, or if answers are vague and defensive, trust that instinct.

QUICK COMPLIANCE CHECKLIST

Five questions to put to your IT provider this week:

  1. Can you show me evidence that our patches and updates are being applied regularly?

  2. When was the last time our backup was actually tested with a full restore?

  3. What security monitoring do we have in place and what does it cover?

  4. Who has admin access to our systems and can you give me a full list?

  5. What is the out of hours emergency process if our systems go down?

BEFORE YOU GO

A good IT provider is one of the most valuable assets a small business can have. They free you up to run the business, they keep things running, and when something goes wrong, they are the ones who fix it fast.

But "good enough" is not good enough when it comes to IT security. Too many SMEs are paying monthly fees for a provider who is keeping the lights on while leaving the doors unlocked.

You do not need to be an IT expert to ask the right questions. You just need to ask them. And if the answers do not add up, it might be time to find someone who can do better.

See you next week.

  • The SME Security Brief

You're receiving this because you subscribed at thesmesecuritybrief.com. To unsubscribe, click here.

If you find this newsletter useful and want to show your support, you can buy me a coffee. It genuinely means a lot and keeps this going. No pressure at all.