The Questions I'd Ask Before Hiring Any Cybersecurity Company
The Questions I'd Ask Before Hiring Any Cybersecurity Company
I get asked fairly often how a business owner with no technical background is supposed to tell a genuinely good cybersecurity provider from one that's mostly good at selling. It's a fair question, because the marketing on both sides tends to look identical, confident language, impressive-sounding certifications, a slide with a padlock on it. What actually separates a provider worth paying from one that isn't shows up in how they answer a handful of specific questions, not in how polished their pitch is. These are the five I'd ask before signing anything.
Do They Explain Things in Plain English or Just Sell Fear
The first thing I pay attention to isn't what a provider says, it's how they say it. A good one can explain your actual exposure in terms you'd understand without a technical background, this is the risk, here's roughly what it would cost you if it happened, here's what we'd do about it. A provider leaning on fear alone, vague warnings about hackers, scary statistics with no context, urgency to sign today, is usually selling a feeling rather than a service. I've sat in enough of these conversations to notice that the providers who are actually good at the work tend to be the calmest in the room, because they don't need drama to make their case. If a pitch leaves you more frightened than informed, that's telling you something about the provider, not about your actual risk level.
What Happens After the Contract Is Signed
This is the question that separates a genuine ongoing partner from a one-off vendor, and it's the one people forget to ask until it's too late. Some providers do a single audit, hand you a report, and disappear until renewal time. Others treat the relationship as continuous, monitoring, regular check-ins, updates as your business and the threat landscape both change. Neither model is automatically wrong, but you need to know which one you're buying before you sign, because a business that assumed ongoing support and got a one-time report is going to be badly caught out the first time something goes wrong six months later. I ask providers directly to walk me through what a normal month looks like after onboarding, not just what the initial engagement includes.
Can They Show Me Real Client Outcomes, Not Just Logos
Almost every provider's website has a row of client logos, and almost none of them tell you anything useful. What I actually want to hear is a specific, if necessarily anonymised, example, we caught this kind of attempt for a client in your sector, here's roughly what we found in an audit, here's how we responded when something did get through. A provider who can only speak in generalities about their own track record, "we help businesses stay secure", without ever getting concrete, hasn't necessarily done anything wrong, but it makes it much harder to judge whether their experience actually matches your situation. I'd rather hear one detailed, honest example of something that didn't go perfectly than a wall of logos and five-star testimonials that could belong to any provider in the industry.

Do They Push One Product or Actually Assess My Risk First
This is the one I consider closest to a genuine red flag. A provider who recommends a specific product or package before they've properly understood your business, what data you hold, how your team actually works, what your existing setup looks like, is selling you something off a shelf rather than solving your actual problem. The better ones start with an assessment, sometimes a paid one, before recommending anything specific, because a ten-person accountancy firm and a fifty-person logistics company have almost nothing in common in terms of what they actually need protecting. If a sales call moves straight to pricing tiers without any real questions about your business first, that's usually the pattern repeating itself, and it's worth being cautious about what you're actually being sold.
What's Included When Something Goes Wrong
No provider can promise nothing will ever happen, and I'm always slightly more wary of one that implies otherwise. What matters more is what's actually included in your contract if something does get through, incident response, who you can call and how quickly, what the escalation process looks like, and whether that's part of your existing fee or a separate cost you'll be quoted for under pressure at the worst possible moment. I ask this question directly and expect a direct answer, not a vague reassurance that they'll "be there for you." A provider who's thought this through in advance, and can tell you plainly what's covered, is showing you they've actually planned for the scenario they're being hired to prevent.
None of these five questions require any technical knowledge to ask, and the answers you get back tell you far more than any brochure or sales pitch will. How they explain risk, what ongoing support actually looks like, whether they can speak concretely about real outcomes, whether they assess before they sell, and what's covered when something goes wrong, that's the real picture of what you're buying, well before you get anywhere near a contract. I've written separately about the five security fixes I'd make first regardless of which provider you end up choosing, and about the antivirus software I've actually ended up trusting on my own devices if you're comparing options at the product level too. If you want a second, independent source on vetting a provider, the NCSC publishes its own guidance for small businesses, and my free Safety Toolkit covers the rest of what I'd recommend if you want to get your own basics in order first.
