Managed IT security services are the outsourced operation of an organization’s security controls: monitoring, detection, response, patching and reporting, run by an external team on a fixed monthly fee. The assessment that tells you which parts you need is short. Take the thirteen baseline controls published by the Canadian Centre for Cyber Security, mark which ones your organization can operate at 2 a.m. on a Saturday, and hand the rest to a provider.
Most organizations that do this exercise honestly find the same thing. They own tools for eight or nine of the controls. They can operate three or four of them outside business hours.
Why the assessment matters before the shopping
Security spending goes wrong in a predictable way. Something frightening happens in the news, a budget appears, and it gets spent on a product. The product generates alerts. Nobody is assigned to read them, so the alerts accumulate in a console that gets opened during audits.
That is not a tooling failure. It is an operating failure, and no additional product fixes it.
The numbers behind the urgency are less dramatic than vendor marketing suggests, which is useful. Statistics Canada found that 18% of Canadian businesses were impacted by a cyber security incident in 2021, rising with size: 16% of small businesses, 25% of medium, 37% of large. About 40% of those affected experienced downtime, and the average outage ran 36 hours.
Thirty-six hours is the figure worth planning around. It is a day and a half of a stopped organization, and it lands on whoever is on call.

Use a published control set, not a vendor’s checklist
A vendor’s assessment will find gaps that the vendor sells products for. That is not dishonesty, it is scope. Run the exercise against a neutral standard first and you will know which parts of the resulting quote are real.
The Canadian Centre for Cyber Security’s baseline controls for small and medium organizations covers organizations under 500 employees and lists thirteen. Score each one twice: do we have it, and can we operate it continuously.
| Baseline control | Typical answer to “do we have it” | Typical answer to “can we run it at 2 a.m.” |
|---|---|---|
| Incident response plan | Rarely | No |
| Automatic patching | Partly | No, patching drifts |
| Security software enabled | Yes | Alerts unread |
| Secure device configuration | Inconsistent | No |
| Strong user authentication | Partly, with exceptions | Yes, once enforced |
| Employee awareness training | Annually | Not applicable |
| Backup and encryption | Yes | Restores untested |
| Secure mobility | Partly | No |
| Perimeter defences | Yes | Rules unreviewed |
| Secure cloud and outsourced IT | Assumed | No |
| Website security | Yes | No |
| Access control and authorization | Partly | Reviews skipped |
| Portable media | Policy exists | Unenforced |
The right-hand column is the one that decides whether you need a service or a purchase. Anything scoring “no” there is work that only exists if somebody is being paid to be awake for it.

The three questions that separate providers
Once you know which controls you are outsourcing, the shortlist gets short quickly.
Who is on shift, and where. Some providers run their own security operations centre with named analysts. Others resell monitoring from a partner several time zones away who has no context on your environment. Both are legitimate business models and they behave very differently at 3 a.m. Ask which one you are buying.
What happens without a human decision. If a workstation starts encrypting files, can the platform isolate that machine from the network automatically? Containment that waits for a person to read an email is not containment.
What the response commitment is, in writing. A stated target such as a 30-minute response on critical incidents is a contractual object you can hold someone to. “We aim to respond promptly” is not. An organization in Calgary or Kelowna comparing managed security services in Alberta should ask each provider to put the critical-incident number in the agreement rather than the brochure.
What sits outside the monitoring conversation
Two items get left off assessments repeatedly and both cause disproportionate damage.
The first is the backup platform’s own authentication. Organizations enforce multi-factor authentication on email and leave the backup console reachable with a shared password, which is precisely where an intruder goes first. Backups get deleted before encryption starts, because a target with clean backups does not pay.
The second is the restore test. A backup job that reports success is a hypothesis. Pick a file from three months ago, restore it somewhere harmless, and write down how long it took. If nobody in your organization has done that in the past year, the honest entry on the assessment is “unverified”.
Scoring the result
Add up the controls where the answer to continuous operation was no. Under three, you probably need help with specific gaps rather than a full service. Between four and eight, a managed service is usually cheaper than the internal hiring that would otherwise be required, because one qualified person cannot cover nights, weekends, illness and vacation. Above eight, the gap is structural and the sequencing matters more than the vendor choice: authentication first, then backup integrity, then monitoring.
None of this requires a consultant. It requires an afternoon, a printed control list, and a willingness to write “no” in a column where writing “partly” would feel better.
The part nobody enjoys
The assessment produces a document that says your organization is less protected than it assumed. That document is the useful output, not the embarrassment it feels like. It is also the thing an insurer, a regulator or a large client will ask for, and having one dated last month rather than never puts you ahead of most organizations your size.
Start with the column that asks whether you can operate the control at 2 a.m. Everything else in the assessment follows from it.

