How to Tell If Your Managed Cybersecurity Provider Will Actually Respond During an Attack
September 2, 2026
It’s two in the morning. Your provider says one of your endpoints is compromised. No one on your team picks up the phone.
What happens next? That depends on one thing. Did anyone plan for this ahead of time?
Ask This Instead
Don’t ask a vendor if they respond to attacks. Every credible vendor in this category will say yes.
Ask this instead:
What are you allowed to do without me?
That question is harder to dodge. It tells you what you’re really buying.
The Answer Changes Depending On What Got Hit
Here’s the part that trips people up. The answer is not the same for every system.
A provider might isolate a standard employee laptop right away. No approval needed. But that same provider may need your OK first for a system that can’t go down. Or for an executive’s laptop.
Both of those rules can exist in the same contract, with the same vendor.
The real question is this. Was that plan made ahead of time? Or will it get made live, during your real incident, by whoever happens to answer the phone?
A good provider already knows which systems need special rules. They know how fast they escalate. They know exactly who to call. A provider who makes up the answer on a sales call might still do good work. But if none of it is written down, you’re trusting a story, not a plan.
Run This Test With Any Provider
Ask these four things. Get the answers in writing. Don’t just take their word on a call.
A standard employee laptop gets compromised.
Can they isolate it without calling you first? If yes, what happens next? Do they call you, email you, or just log it somewhere you have to go check? If no, what do they need from you first?
The compromised device belongs to an executive, or it’s a system that can’t go offline.
Do they already have a plan for this? Or would they figure it out live, during your incident? How fast do they escalate? Who do they call first? If no one answers, what do they do next?
The problem is a user account, not a device.
Can they lock the account without waiting on you? Can they force a password reset on their own? Or does your team have to do it first?
After the immediate threat is contained.
Isolating a device or locking an account may stop the immediate spread. It does not mean the threat is gone or the system is ready to use again.
Who investigates what happened? Who removes the threat? Who restores the system and approves bringing it back online, the provider or your team?
Define that handoff now, not during an incident.
What This Actually Prevents
This test exposes the gap between what your team believes it bought and what the provider is actually prepared and allowed to deliver.
Both sides may use the word “response” while meaning different things. The buyer may expect the provider to contain the attack. The provider may mean it will investigate the alert, recommend an action, and help the buyer carry it out.
Neither model is automatically wrong. The problem is buying one while expecting the other.
With someone on your side, you map this out before you pick a vendor. You do not discover it for the first time during a breach call.
ITBroker built this test from a conversation on this episode of Signed, where a managed cybersecurity provider explained how response can change across systems, users, and incidents, even under the same industry label.
Are you evaluating a managed cybersecurity provider now? Or did you sign one over a year ago without ever asking this question? Run the test before an incident answers it for you.
Choosing between managed cybersecurity providers? This is where independent representation changes the outcome. We’ll show you what real world fit looks like across 967 providers. Get Started.
No pitch. No prep. Just answers.


