How do you know if your IT provider is actually secure?

Most businesses take their IT provider’s security on trust, then struggle to prove it when an insurer or auditor asks. Five questions that tell you what you need to know.

You have handed your IT provider the keys to your business. They run your email, hold your data, control who has access, and look after your backups. If they are not secure, neither are you. Yet most businesses pick a provider on service and price, then take the security on trust. That holds up right until someone asks you to prove it: a cyber insurer at renewal, an auditor mid-engagement, or a client running due diligence on their own supply chain. At that point, “they seemed to know what they were doing” is not an answer.

Why should you be asking this in the first place?

Your provider’s risk is your risk. If they are breached, it is your data that leaks and your operation that stops, and you are the one explaining it to customers and regulators. Supplier compromise has become one of the most common ways into UK businesses, because attackers worked out that breaking a single IT provider can reach dozens of their clients at once.

The questions are also arriving from more directions than they used to. Cyber insurers have tightened what they expect before they will offer cover, and a provider with weak security can affect your premium or your eligibility. Auditors and compliance frameworks increasingly ask about third-party risk. Larger clients send supplier due-diligence questionnaires before they sign. In every case, “we take security seriously” is a sentence, not evidence.

What does “secure” actually mean for an IT provider?

There is a difference between a provider who says they are secure and one who can prove it. The proof is independent certification: a standard set by someone other than the provider, tested by an external assessor, and renewed on a schedule.

Two are worth knowing by name. ISO 27001 is the international standard for information security management. It is not a one-off badge. It covers how an organisation manages risk across its people, processes and technology, it is audited by an external body, and it is renewed on a three-year cycle with annual surveillance audits in between. Cyber Essentials Plus is the hands-on, assessor-tested tier of the UK government’s Cyber Essentials scheme, where an independent assessor checks the controls are genuinely in place rather than taking the provider’s word for it.

The point is not the acronyms. It is the word independent. A standard the provider marks themselves against is marketing. A standard someone else audits is evidence.

What questions should you ask your provider?

You do not need to be technical to test this. Five direct questions will tell you most of what you need to know.

Are you independently audited, or self-declared? A serious provider is measured against an external standard, not its own opinion of itself. If the answer is a list of tools rather than a certification, press on it.

Do you hold ISO 27001 or Cyber Essentials Plus, and can you show the certificate and its scope? A real credential comes with a scope statement that says exactly what it covers. A logo on a website does not. Ask to see the certificate, and check the scope includes the services they actually deliver to you.

Do you use the security tools you sell to us? A provider that recommends a security platform to clients but does not run it in-house is worth a second look. If they will not eat their own cooking, ask why.

How do you manage your own people? Most breaches start with a person, not a server. Ask how they handle phishing, staff awareness, and access for their own team. Their internal discipline is a fair guide to the discipline you will get.

What happens when something goes wrong? Ask who you hear from, how quickly, and what the process is. A provider that can describe its incident response calmly has been there before. One that improvises is learning on your time.

What does a good answer look like?

A weak answer is vague and defensive. A good answer is specific and comes with evidence.

Take the question about using what you sell. At Highgate, our own inboxes run on Ironscales, the same email security platform we deploy for clients. The latest phishing simulation across our team came back with zero clicks, against 334 security incidents the platform handled in its first year. That is the kind of concrete answer to look for: a number, a result, something that actually happened.

On certification, we hold ISO 27001, externally audited and renewed annually, so the way we manage and protect client data is measured against an international benchmark rather than our own say-so.

And the best answer is one your own people can stand behind. Kings Chambers, a barristers’ set we support across three locations, put it plainly:

The difference in service with Highgate was clear from day one. They have quickly become a trusted partner and understand our business, support our goals, and ensure our IT is secure, efficient, and future-ready.”

Lewis Martin, Compliance Manager at Kings Chambers

For a regulated business, that assurance is the point. Mercer & Hole, an FCA-regulated accountancy firm with four offices, rely on Highgate for exactly the standard their own auditors and clients expect them to be able to demonstrate.

What if your provider cannot answer these?

If you ask these questions and get hesitation, deflection, or a sales brochure, treat that as the answer. It does not always mean a provider is negligent. It does mean you cannot evidence their security to anyone who asks, and that is a risk you are carrying on their behalf.

Switching provider feels like the harder road, which is why many businesses stay put longer than they should. In practice it is more straightforward than the fear suggests. A good incoming provider plans the move around continuity, and most of our clients came to us from a previous supplier who had stopped being able to answer questions like these. Managing that exposure properly is the whole of what we mean by reducing risk.

Where do you start?

The businesses that handle this well are rarely the ones with the biggest security budgets. They are the ones that decided what good looks like before they went looking, then held their provider to it. Start by putting the five questions above to your current provider. The answers will tell you whether you have a partner who can prove their security, or one who is hoping you never ask.

If you would like to talk it through, our cybersecurity team can take you through the full checklist and what a strong answer looks like for each question.