Managed IT security services: what they cover and how to assess what you need

Managed IT security services are the outsourced operation of an organization’s security controls: monitoring, detection, response, patching and reporting, run by an external team on a fixed monthly fee. The assessment that tells you which parts you need is short. Take the thirteen baseline controls published by the Canadian Centre for Cyber Security, mark which ones your organization can operate at 2 a.m. on a Saturday, and hand the rest to a provider.

Most organizations that do this exercise honestly find the same thing. They own tools for eight or nine of the controls. They can operate three or four of them outside business hours.

Why the assessment matters before the shopping

Security spending goes wrong in a predictable way. Something frightening happens in the news, a budget appears, and it gets spent on a product. The product generates alerts. Nobody is assigned to read them, so the alerts accumulate in a console that gets opened during audits.

That is not a tooling failure. It is an operating failure, and no additional product fixes it.

The numbers behind the urgency are less dramatic than vendor marketing suggests, which is useful. Statistics Canada found that 18% of Canadian businesses were impacted by a cyber security incident in 2021, rising with size: 16% of small businesses, 25% of medium, 37% of large. About 40% of those affected experienced downtime, and the average outage ran 36 hours.

Thirty-six hours is the figure worth planning around. It is a day and a half of a stopped organization, and it lands on whoever is on call.

Bar chart showing the share of Canadian businesses impacted by a cyber security incident in 2021: 16% of small businesses, 25% of medium, 37% of large.
The incident rate climbs with headcount, but the 36-hour average outage does not. A small organization loses the same day and a half.

Use a published control set, not a vendor’s checklist

A vendor’s assessment will find gaps that the vendor sells products for. That is not dishonesty, it is scope. Run the exercise against a neutral standard first and you will know which parts of the resulting quote are real.

The Canadian Centre for Cyber Security’s baseline controls for small and medium organizations covers organizations under 500 employees and lists thirteen. Score each one twice: do we have it, and can we operate it continuously.

Baseline control Typical answer to “do we have it” Typical answer to “can we run it at 2 a.m.”
Incident response plan Rarely No
Automatic patching Partly No, patching drifts
Security software enabled Yes Alerts unread
Secure device configuration Inconsistent No
Strong user authentication Partly, with exceptions Yes, once enforced
Employee awareness training Annually Not applicable
Backup and encryption Yes Restores untested
Secure mobility Partly No
Perimeter defences Yes Rules unreviewed
Secure cloud and outsourced IT Assumed No
Website security Yes No
Access control and authorization Partly Reviews skipped
Portable media Policy exists Unenforced

The right-hand column is the one that decides whether you need a service or a purchase. Anything scoring “no” there is work that only exists if somebody is being paid to be awake for it.

Two-by-two matrix scoring a security control on whether the organization has it and whether it can be operated at 2 a.m. Quadrants are labelled Ad hoc effort, Covered, Not started and Tooling only.
Most security budgets are spent moving controls into the lower-right box, which is the one quadrant that does not improve the outcome of an incident.

The three questions that separate providers

Once you know which controls you are outsourcing, the shortlist gets short quickly.

Who is on shift, and where. Some providers run their own security operations centre with named analysts. Others resell monitoring from a partner several time zones away who has no context on your environment. Both are legitimate business models and they behave very differently at 3 a.m. Ask which one you are buying.

What happens without a human decision. If a workstation starts encrypting files, can the platform isolate that machine from the network automatically? Containment that waits for a person to read an email is not containment.

What the response commitment is, in writing. A stated target such as a 30-minute response on critical incidents is a contractual object you can hold someone to. “We aim to respond promptly” is not. An organization in Calgary or Kelowna comparing managed security services in Alberta should ask each provider to put the critical-incident number in the agreement rather than the brochure.

What sits outside the monitoring conversation

Two items get left off assessments repeatedly and both cause disproportionate damage.

The first is the backup platform’s own authentication. Organizations enforce multi-factor authentication on email and leave the backup console reachable with a shared password, which is precisely where an intruder goes first. Backups get deleted before encryption starts, because a target with clean backups does not pay.

The second is the restore test. A backup job that reports success is a hypothesis. Pick a file from three months ago, restore it somewhere harmless, and write down how long it took. If nobody in your organization has done that in the past year, the honest entry on the assessment is “unverified”.

Scoring the result

Add up the controls where the answer to continuous operation was no. Under three, you probably need help with specific gaps rather than a full service. Between four and eight, a managed service is usually cheaper than the internal hiring that would otherwise be required, because one qualified person cannot cover nights, weekends, illness and vacation. Above eight, the gap is structural and the sequencing matters more than the vendor choice: authentication first, then backup integrity, then monitoring.

None of this requires a consultant. It requires an afternoon, a printed control list, and a willingness to write “no” in a column where writing “partly” would feel better.

The part nobody enjoys

The assessment produces a document that says your organization is less protected than it assumed. That document is the useful output, not the embarrassment it feels like. It is also the thing an insurer, a regulator or a large client will ask for, and having one dated last month rather than never puts you ahead of most organizations your size.

Start with the column that asks whether you can operate the control at 2 a.m. Everything else in the assessment follows from it.

Post Author: Rae Schwan