Every cyber security managed service provider can show you a dashboard. The harder question is what happens when something serious appears on it.
For CIOs and CISOs, choosing a managed security partner is ultimately a risk decision. You are giving a third party access to systems, data and potentially privileged accounts. The provider needs to go beyond threat detection and respond quickly, communicate clearly and work within an operating model that complements your internal team.
That scrutiny is justified. The UK Government's 2025/26 Cyber Security Breaches Survey found that 43% of UK businesses experienced a cyber security breach or attack in the previous 12 months. For large businesses, the figure rose to 69%. Yet only 25% of businesses had a formal incident response plan, compared with 76% of large businesses.
The right provider can add specialist capability and 24/7 coverage. The wrong one can add another layer of complexity. Here are 12 questions to ask before you sign.
1. What exactly are you taking responsibility for?
Start with the scope. "Managed security" can mean very different things between providers. One may monitor alerts and escalate them to your team. Another may investigate, contain and respond to threats. Some may also manage vulnerabilities, endpoints, identity controls or incident response.
Ask for a clear definition of:
- Systems and environments covered
- Security services included
- Monitoring and response responsibilities
- Out-of-hours coverage
- Escalation processes
- Activities that remain with your internal team
- Services or incidents that incur additional charges
The NCSC recommends that MSP contracts clearly define responsibilities, response times and liability, including the responsibilities of any third parties involved in delivering the service. If you cannot establish who owns a decision before signing, expect confusion when an incident occurs.
2. Do you provide genuine 24/7 security operations?
A service described as "24/7" needs scrutiny. Does that mean systems generate alerts around the clock, or are analysts actually monitoring and responding 24/7?
Ask:
- Where is the security operations centre?
- Who monitors alerts outside UK business hours?
- Are analysts involved overnight or is activity simply queued?
- What happens when a high-severity incident is detected?
- Who contacts your team?
- What happens if your own team cannot respond?
The point isn't that every organisation needs a particular operating model. It is that your coverage should match your risk. If an incident at 2am could cause material disruption, waiting until the next working day isn't a viable response model.
3. How quickly do you detect and respond to threats?
"Fast response" is not a useful SLA. Instead, ask for measurable targets. That could include:
- Mean time to detect (MTTD)
- Mean time to respond (MTTR)
- Time to triage
- Time to containment
- Escalation thresholds
- Customer notification times
The NCSC recommends using SLAs to establish clear expectations around response and resolution times. More importantly, ask how those numbers are measured.
A provider claiming a 15-minute response time needs to explain whether that means an automated acknowledgement, an analyst beginning an investigation or actual containment. Those are very different outcomes.
4. What happens when an alert is generated?
This is one of the most useful questions you can ask. A security platform can generate an alert. That does not mean the threat has been investigated.
Ask the provider to walk you through a real example:
Alert → triage → investigation → severity assessment → containment → escalation → resolution.
Who makes the decision at each stage? What evidence is collected? When does the provider contact your team? Can it isolate an endpoint, disable an account or block malicious activity without waiting for approval? And what happens when the provider gets it wrong?
You want to understand the operating model behind the technology, not just the technology itself.
5. How much of the service is automated?
Automation can reduce workload, improve response times and help analysts focus on significant events, but "AI-powered" is not an operating model.
Ask which parts of the service are automated:
- Alert correlation
- Detection
- Investigation
- Threat intelligence enrichment
- Endpoint isolation
- Account suspension
- Ticket creation
- Reporting
Then ask where human analysts remain involved. The best model is usually not automation instead of expertise. It is automation handling predictable activity while experienced analysts investigate the events that require judgement.
For a stretched internal team, that distinction matters. You want the provider to reduce noise, not simply send more of it to a different inbox.
6. How do you protect your own access to our environment?
Your security provider is part of your attack surface. It may have privileged access to systems, endpoints, cloud platforms or security tools. That access needs to be protected to the same standard you would expect internally.
Ask about:
- Multi-factor authentication
- Privileged access management
- Least-privilege access
- Administrative accounts
- Access reviews
- Session logging
- Credential management
- Remote access controls
- What happens when an employee leaves the provider
The NCSC specifically recommends that organisations check how an MSP secures its access to customer systems, including the use of two-step verification and least privilege.
The question is simple: If the provider's credentials were compromised, how much access would an attacker gain?
7. What visibility will we have?
A managed service should not be a black box. Your team needs enough visibility to understand what is happening, what has been detected and what actions have been taken.
Ask what reporting includes:
- Security incidents
- Threat activity
- Vulnerability trends
- Detection and response performance
- Security alerts
- Open and closed incidents
- Recommendations
- Service-level performance
The NCSC recommends regular reviews and reporting from MSPs, including information on security alerts, patch compliance, backup performance and infrastructure health. The reporting should also work at different levels.
A security analyst may need detailed event information. A CISO may need trends and risk. A CIO or board may need a clear view of material exposure and whether risk is improving.
8. Can you support our actual technology estate?
Don't choose a provider based on a list of logos. Ask whether it can actually monitor and respond across the technologies you run.
That could include:
- On-premises infrastructure
- IBM Power
- Microsoft environments
- AWS and Azure
- SaaS platforms
- Network infrastructure
- Endpoints
- Identity platforms
- Business-critical applications
This matters particularly in hybrid environments, where security responsibilities can be distributed across internal teams, cloud providers and third parties. Ask for evidence such as relevant case studies, certifications, customer references and technical expertise.
9. How do you handle incident response?
Detection is only the first stage of an incident. Find out what happens when an event becomes a confirmed security incident.
Ask:
- Who leads the response?
- Who makes containment decisions?
- How is evidence preserved?
- When does specialist incident response become involved?
- How are executives and other stakeholders notified?
- What happens if the provider itself is affected?
- How does the incident transition into recovery?
The NCSC recommends that MSPs have clear incident response procedures covering how they respond and how they engage with customers, including scenarios where the MSP itself is impacted.
If serious incidents are outside the provider's scope, establish who you call before you need them. For significant incidents, the NCSC recommends UK organisations use an NCSC-assured Cyber Incident Response provider.
10. How does cyber security connect to data resilience?
This question separates detection from business continuity. An attacker can be detected quickly and still cause significant disruption if critical systems cannot be recovered.
Ask how the provider works alongside your resilience strategy:
- Are backups monitored?
- Are backups isolated from production?
- Are immutable copies used?
- How often are restores tested?
- What are the agreed RPOs and RTOs?
- Who initiates recovery?
- How are dependencies between applications and infrastructure handled?
The NCSC calls regular backups and testing of data recovery an essential part of responding to ransomware, and recommends asking an MSP how it would recover services and data following an attack. For business-critical environments, recovery needs to be part of the conversation before an incident, not added afterwards.
11. How will you prove the service is reducing risk?
A monthly report showing how many alerts were closed is not enough. Ask how the provider measures outcomes.
Useful measures can include:
- MTTD and MTTR
- Time to contain incidents
- Critical vulnerability remediation
- Coverage across the estate
- Detection and response performance
- Recurring incident trends
- Security control effectiveness
- Recovery test performance
The aim is to understand whether your exposure is changing over time. A good managed service should give your team better visibility of risk, not simply more security data.
12. Can you prove the service works?
Finally, ask for evidence.
Look for:
- Relevant customer references
- Case studies
- Security certifications
- Independent assurance
- Incident response experience
- Technical certifications
- Service performance data
- Recovery testing
- Clear SLAs
The NCSC recommends checking an MSP's recognised security certifications, track record, references and transparency before appointment. Ask for examples that resemble your environment.
A provider supporting thousands of endpoints is not automatically the right choice for an organisation running complex IBM infrastructure. A provider with excellent cloud expertise may not have the specialist knowledge required for your most critical workloads. Evidence should be relevant to the risk you are trying to manage.
Don't compare providers on price alone
Price matters, but comparing providers on monthly cost alone can hide significant differences in scope. Before comparing the numbers, compare what you actually get.
Look at:
- Hours of coverage
- Systems monitored
- Response responsibilities
- Included incident response
- SLAs
- Reporting
- Technology integrations
- Vulnerability management
- Threat hunting
- Additional charges
- Contract and exit terms
The NCSC specifically recommends checking the potential cost implications of security features and making sure agreed responsibilities are included in the contract. The cheapest provider may be expensive if your internal team still has to perform most of the work.
The right provider should extend your team, not create more work
A managed cyber security provider should give your internal team more capacity and specialist capability without taking away the business context they need to make good decisions. Your CIO and CISO should retain ownership of risk appetite, strategy, governance and business priorities.
Your provider can add the operational capacity around that, such as continuous monitoring, detection, investigation, specialist response and technical expertise.
The NCSC makes clear that using an MSP does not remove an organisation's responsibility for managing its own cyber security risks. The provider is there to support that responsibility, not replace it.
Choosing a managed cyber security provider
The best cyber security managed service providers are not necessarily the ones with the longest service catalogue or the most impressive technology stack. They are the ones that can demonstrate how they will protect your environment, what happens when something is detected, who makes the decisions, how quickly they respond and how they support recovery when prevention fails.
For CIOs and CISOs, those are the questions worth asking before the contract is signed.
Looking for a managed cyber security partner that can extend your internal capability?
Speak to Celerity about managed cyber security services covering detection, response and ongoing security operations.