Five Security Questions to Ask Your IT Provider This Week
Most Oklahoma businesses that get breached this year will not be beaten by a genius with a zero-day. They will be beaten by a setting somebody left wrong.
That sounds bleak. It is actually the best news in cybersecurity. Nation-state tradecraft is somebody else's problem to solve. Configuration is yours, and it is fixable this quarter without a bigger budget.
The Open Worldwide Application Security Project — the closest thing the industry has to a scoreboard — moved security misconfiguration from #6 on its Top 10 list in 2017 to #2 in 2025. SonicWall's 2026 Cyber Protect Report reaches the same conclusion from the incident-response chair: the organizations that suffer most are not failing because of exotic attacks. They fail because of exposed services, unmonitored access, and inconsistent policy — gaps that grew quietly while everyone was busy running the business.
The problem usually isn't your IT provider
I want to be careful here, because this is where most articles turn into a pitch against whoever you're currently paying. That is not the point.
In a small or mid-sized business, the people who implement your security controls and the people who report on them are the same people. That is not a conspiracy. It is how a lean organization is staffed, and it describes good providers as well as bad ones. But it means nobody outside the technical layer is checking the work, and no owner should have to accept "we're good" on faith for a risk that can end the company.
When I ask owners why they don't push harder, the answer is almost always the same: they wouldn't understand the response. That's fair, and it's fixable. The five questions below don't require you to understand the technology. They require specifics — and you can evaluate a specific answer whether or not you can read a firewall rule.
The five questions
Send these in writing. Ask for artifacts, not assurances.
- 1. List every account that does not have multi-factor authentication. Not "do we have MFA" — almost everyone says yes. You want the exceptions: the service account nobody wanted to break, the shared shop-floor login, the executive who found it annoying. The exceptions are where intrusions start.
- 2. What is reachable from the internet right now? Remote desktop, VPN appliances, remote-access tools, that on-premises server running your ERP. Every item on that list is a door. You are entitled to know how many doors your building has.
- 3. Who holds administrator rights, and when did someone last review that list? Admin creep is the most common finding in any assessment I run. Former employees, a vendor from a 2019 project, a technician who needed it once. The review date matters as much as the list.
- 4. When did we last complete a full test restore, and how many hours did it take? Not "are backups running." Backups run beautifully right up until you need them. A real test restore of a critical system typically takes 60 to 120 minutes when it is working properly. If the answer is "we've never tested it," you don't have a backup — you have a backup product.
- 5. What are we still running that is past its end-of-support date? Unsupported software stops receiving security patches entirely. This is the question that most often surfaces a line item nobody budgeted for, which is exactly why it should surface now instead of during an incident.
How to read what comes back
Speed is the first signal. A provider who has this under control produces all five answers within about a week — most of it already exists in their documentation and tooling. Longer than that isn't an accusation of negligence. It is information you did not have before, and it usually means the answers are being assembled for the first time rather than retrieved.
Completeness is the second signal. Watch for answers that restate the question. "We have MFA enabled" is not a list. "Backups are monitored daily" is not a restore time. A good provider will give you the uncomfortable version, because they would rather you hear it from them.
The third signal is what happens next. Every answer above either confirms something is handled or produces a task with an owner and a date. If a gap gets identified and nothing gets scheduled, the exercise was theater.
Consider a 40-person construction company in Norman running project management on an on-premises server, with a field crew connecting over VPN. Question two surfaces the VPN appliance. Question five reveals it stopped receiving vendor patches fourteen months ago. That is now a scheduled replacement with a cost and a date attached — not a surprise discovered by somebody else at 2 a.m.
Why this matters beyond security
These five questions are not only a security exercise. They are the same ground your cyber insurance renewal covers. A current questionnaire runs 40 or more control attestations, and somebody signs it on your behalf. If nobody has verified the answers against reality, you may be carrying a policy that pays less than you think at the exact moment you need it.
The same goes for HIPAA risk assessments, CMMC self-assessments for anyone in the Tinker Air Force Base supply chain, and the security questionnaires your own customers increasingly send before signing. In every case someone attests on your behalf. Verification is the cheap part. Discovering the gap during a claim is the expensive part.
The seat nobody is sitting in
None of this requires a larger IT budget. It requires somebody at the leadership table whose job is to ask the questions and evaluate the answers — someone who is not also the person being evaluated. In a large company that person is the CIO. Most businesses across the Oklahoma City metro don't have one, and don't need one full time.
That gap is why fractional CIO work exists, and it's the seat I sit in for a small number of businesses around OKC. I am not the help desk and I don't replace your MSP or your internal IT staff. I am the independent set of eyes that reads the answers, tells you what they mean in business terms, and makes sure something gets scheduled.
Start with the five questions. Send them this week. Whatever comes back, you will know more about your own risk on Friday than you did on Monday — and that is real progress for the price of one email.
If nobody can answer these five questions inside a week, that's not a technology problem — it's a governance gap, and it's worth an independent look. The discovery call is free and there's no pitch, just whether there's a fit — for businesses across the Oklahoma City metro.
Book a free discovery call