Questions to Ask an MSP After a Security Scare
The alert came in on a Tuesday. Something moved through the network that had no business being there. It got caught and contained before it reached anything that mattered, and by Wednesday, the environment was quiet again.
Then the questions started: What if it had reached the file server? What if it had been ransomware instead of a probe? Are we set up to catch the next one, or did we get lucky this time?
That last question is usually where the search for a new provider begins.
Do you know the risks posed to your business? You might be surprised: The Security Gaps Most Businesses Don’t Know They Have

A Mature Incident Process
Before you can judge a provider, you need a picture of what “good incident response” is. A capable incident process moves through clear stages, and each one has an owner and a record.
- Detection and triage: An event is noticed, verified as real, and ranked by how much damage it could do. This is supposed to happen within minutes, and it does not depend on someone noticing a problem the next morning.
- Containment: Someone with authority isolates the affected systems and stops the spread. The roles and responsibilities are confirmed ahead of time, so no one is figuring out who does what while the clock runs.
- Investigation and forensics: The team preserves evidence, maps how far the event reached, and builds a timeline of what happened. This record is what insurers and regulators will later ask for.
- Recovery and restoration: Systems come back cleanly, and the team confirms the threat is gone before declaring the event closed. Rushing this step is how reinfection happens.
- Post-incident response: The gap that allowed the event gets identified and closed. Something in the environment changes as a result, and there is a written account of what and why.
The thread running through all five stages is documentation. A mature incident response process is repeatable, and it leaves behind a record that holds up when someone outside the company reads it.
Why “Price” and “Speed” are the Wrong First Filters
Cost and start date are easy to compare. Two providers give you two numbers, and the cheaper, faster one wins. That is exactly why buyers reach for these filters first after a scare, when the pressure to act is high.
The trouble is that both measure reaction time. Neither tells you whether the provider will reduce the odds of the next event, whether their paperwork will support a claim, or whether they carry any responsibility for your risk once the immediate crisis passes. Those are the things that decide whether a near-miss becomes a pattern.
So these next questions are built to surface that.
Spin a potential threat on its head and use it to assess your security measures: What Your Last Blocked Cyber Attack Reveals About Your Security
The Questions to Ask
How Active Incidents are Handled
Who makes containment decisions during an event, and how fast can that person be reached?
You want a named role and a guaranteed path to it. A vague answer about “the team” means no one is accountable when minutes count.
What are your response times, and are they written into the agreement?
Listen for numbers that live in the contract. Aspirational targets that appear only in a sales conversation tend to slip under real pressure.
Walk me through the last security breach you handled. What did the timeline look like?
A strong provider can talk you through a real event, start to finish. Hesitation here usually means less hands-on experience than the pitch suggests.
What Happens Post-Incident
Do you deliver a written post-incident review, and what goes in it?
The report should cover how the event was detected, contained, investigated, and closed. This document is also what your insurer will want to see.
How do your findings turn into changes in our environment, and who owns that follow-through?
The value of a review is the fix that follows it. If no one owns the follow-through, the same gap stays open for the next attacker.
How do you measure whether our risk went down after a cybersecurity incident?
A provider who thinks in terms of risk can answer this. One who thinks in terms of tickets will change the subject to response volume.
Cyber Insurance Alignment
Does your incident documentation meet what our insurer requires for a claim?
Most policies require professional, documented incident response plans to validate a claim. Ask to see the format they use, and confirm it matches your policy’s terms.
Can you help us prepare for a renewal or a risk assessment, and have you done it before?
Renewals and assessments ask hard questions about your controls. You want a provider who has sat on your side of that table more than once.
Which of our current controls would an underwriter expect to see, and where are we short?
A capable partner can name the gaps before the underwriter does. That is the difference between passing your risk assessment and scrambling through it.
Ownership Between Incidents
Who is accountable for our security posture when there’s no active incident?
Security is mostly the quiet work that happens between events. Find out who does that work and how you will know it is being done.
Do we get a strategic contact who understands our business, or a support queue?
A named strategic voice can translate risk into terms your leadership will act on. A queue can only answer the question you already knew to ask.
How do you keep our leadership informed about risk?
You want reporting that a non-technical executive can read and use for a budget decision. Raw alert counts do not clear that bar.
The Tech Stack and the Security Team
Is your support team in-house, or is it outsourced or on-call?
An in-house team answers to the same company you are paying. Outsourced coverage adds a layer between you and the people doing the work during an event.
What security tooling do you standardize on, and why those choices?
A clear answer shows a deliberate security approach. A list of logos with no reasoning behind it does not.
How do you stay current on the threats that reach organizations like ours?
You are looking for specifics tied to your size and industry, not a general reassurance that they keep up.
Successful cyberattacks must be reported, but many businesses aren’t aware that near-misses need to be explained as well: Reporting Cyber Incidents: When a Near-Miss Still Counts
How to Assess the Answers
No single reply should be your decision. Weigh the pattern across the whole conversation.
A provider who owns risk tends to document by habit, follow through on their own findings, and describe their work in terms of the risk they took off your plate. They can point to the change that followed the last incident they handled.
A reactive provider leans on speed and price, counts their value in tickets closed, and goes quiet when you ask what happens after recovery. The gap between the two will show up in these answers.
Turning the Answers Into a Decision
The near-miss was a warning, and the provider you partner with next decides what that warning turns into.
Pick one who treats the event as a one-time job, and you have bought yourself a faster response to the next scare. Pick one who owns the risk between events, and you have changed the odds of there being a next scare at all. That second choice is the one leadership can report upward and sleep on.
Louisville Geek was built around the kind of process these questions test for. Security is included in our managed model, and support comes from an in-house, all-W2 team instead of an outsourced queue.
If a recent close call has you weighing your options, a security-led assessment is a straightforward place to see where you stand.




