How to Know If Your Current IT Provider Is Leaving You Exposed
Your provider's remote access is now one of the easiest ways for someone to get into your network. Here are nine questions you should ask them, and the answers that should make you concerned.
Tickets get resolved quickly. The monthly reports look good. There haven't been any outages since spring. By most owners' standards, this looks like a good provider.
But none of that tells you the most important thing: would your systems hold up if someone really tried to break in? That's a different question, and only one of them shows up on a service report.
Before you read on, know that Emry Networks is a managed IT, cybersecurity, and compliance provider. Of course we want you to question whether your current provider is good enough. So read this as if you were a competitor, and ask us the same questions too. If a provider can't answer these about their own business, they aren't worth switching to.
Start with the uncomfortable part: your provider is a way in
The 2026 Verizon Data Breach Investigations Report found that 48% of breaches involved a third party, nearly double the 30% recorded the year before, and roughly triple the figure from the year before that. Among small and midsize business breaches specifically, third parties featured in 55%. More than half.
For most small and midsize businesses, the IT provider is the most trusted third party in the system. That's not a mistake. It's how the arrangement works. You gave them ongoing administrative access so they can fix problems at any hour. Their remote monitoring and management tools are built to hold a strong, always-on connection to your network.
Which means their security practices are now part of yours, and chances are you've never checked how secure they actually are.
What this looks like when it goes wrong
Look at a recent, well-documented example. It's more useful than any general warning.
On 6 February 2026, BeyondTrust issued fixes for a critical vulnerability, CVE-2026-1731, in its Bomgar remote support product. The flaw let an unauthenticated attacker execute code remotely. Huntress reported an initial spike in exploitation starting 12 February, affecting at least ten organizations, followed by a second wave in early April.
On 14 April, attackers used a compromised Bomgar instance belonging to a dental software company to deploy ransomware, hitting three downstream companies. The next day, 15 April, they compromised a high-privilege Bomgar account belonging to an MSP and used it to push remote access tooling onto a domain controller. That single account produced the mass isolation of 78 businesses, with confirmed follow-on exploitation at four downstream customers.
Inside the victim environments, Huntress observed the pattern you'd expect: create a local account, escalate it into Local Administrators, then into Domain Admins, install a second and third remote access tool for persistence, run network enumeration, turn off endpoint protection using a vulnerable driver, then encrypt. The affected systems were running outdated Bomgar versions, one at 21.1.3, against a patched release of 25.3.2.
So a fix was available on 6 February. The MSP was compromised on 15 April. That's ten weeks in which a provider whose main job is to patch systems didn't update the tool they use to reach clients.
You didn't sign up to share security risk with your provider's other clients. You signed up for support. It came as part of the same agreement.
This isn't one company's problem. Both Verizon and Huntress have reported large increases in attacks that abuse legitimate remote management tools. Huntress said these attacks jumped 277% in 2025, according to its 2026 Cyber Threat Report. Attackers worked out that the quickest way to reach many small businesses is through one provider, and remote management traffic looks normal until it isn't.
The problem is common enough that CISA, the NSA, the FBI, and cybersecurity agencies from the UK, Australia, Canada, and New Zealand released a joint advisory on protecting MSPs and their customers. Their main recommendation isn't technical. It's to have a clear, written agreement about who is responsible for what. Most gaps happen when each side assumes the other is handling something.
Nine questions, and what the answers tell you
You don't need to understand the technology for these. You need your provider to give specific answers. What matters isn't the detail of the answer, but whether they can answer right now, without a week to prepare.
The nine questions, and how to read the answers
| Ask this | Answer that should worry you | Answer you want |
|---|---|---|
| 1. Show me every account in our environment with administrative privilege, as of today. | "I'd have to look into that." | A current list, each account tied to a named human, service accounts identified, and a date for the last review. |
| 2. How do you connect to our systems, and what protects that connection? | "Through our RMM. It's secure." | The tool named, MFA enforced on their side, credentials unique to you rather than shared across clients, sessions logged, and a stated process for cutting off a departing technician. |
| 3. When did we last restore from backup, and how long did it take? | "Backups are running green." | A date, a recovery time, what was restored, and a written record of the test. |
| 4. What is our patch target, and what is the actual measured number? | "We patch monthly." | Two numbers, the target and the measured time to remediate, plus the exceptions named and owned. |
| 5. What is in scope for logging, how long is it kept, and who reads it? | "Everything's logged." | Which systems, the retention window, where logs go, who reviews them, and whether twelve months could be produced on request. |
| 6. Which framework are we being managed against? | "We follow industry best practices." | The framework named, and a split of which controls they own versus which are yours. |
| 7. Are you a business associate, and is our agreement current, including your subcontractors? | "We signed something at onboarding." | A clear yes or no with reasoning, a current agreement describing the data movement that actually happens, and agreements flowing down to their subcontractors. |
| 8. If we ended the contract tomorrow, what would we walk away with? | "We'd hand over the passwords." | Documentation, configuration records, log archives and evidence, in a usable format, within a stated timeframe. |
| 9. What did you find last quarter that we did not ask you to look for? | Silence, or "nothing to report." | Specific findings, what was done about each, and what is still open. |
Four of those deserve more than a table row.
Question 2 is the one almost nobody asks
It's also the crux of the Bomgar incidents. You're asking your provider to explain how they secure the tool that gives them access to your network. A good provider will get specific: MFA on their console, your account on its own credentials rather than a shared technician password, sessions recorded, access reviewed when staff leave. If a provider treats the question as a formality, that's your answer.
Ask a follow-up: what version is it running, and when was it last updated? If no one can say, you've just learned exactly how those ten-week gaps happen.
Question 3 separates a backup from a recovery
A backup job that reports success only means the job ran. It doesn't tell you whether the data is safe, whether you can actually restore it, or how long recovery would take. Those are three different things, and only one shows up on a dashboard.
The cyber insurer At-Bay, drawing on its own claims data, has reported that more than one in four businesses hit by ransomware fail to recover their data from backup. These were organizations that had a backup solution. They'd bought the product, and it was running.
If your provider can't tell you when the last restore test happened, it probably hasn't happened.
Question 7 has legal consequences most owners have never been walked through
If you're a healthcare or dental practice and your IT provider has remote access to systems holding protected health information, that provider is almost certainly a business associate under HIPAA. That isn't a matter of opinion or contract preference. It follows from what they do. A business associate agreement is required, it has to reflect the data movement that genuinely happens rather than a template, and if your provider uses subcontractors who can reach that data, the obligations flow down to them too.
OCR can and does pursue business associates directly. But in practice you're the regulated business, and you're the one who has to prove the arrangement was properly managed.
Question 9 is the best in this article
Everything else asks your provider to report on work you already assigned. This one asks whether anybody is looking without being told to.
A reactive provider won't have anything to say here, because nothing comes up until a user reports it. A proactive provider will have a list: an old employee's account still active in a cloud app, a firewall rule left open after a project, a laptop that stopped reporting in March. These small, boring details are exactly what turn into incidents.
How to read a quiet quarter
"Nothing to report" for a whole quarter doesn't mean everything is fine. It just means nobody checked.
Three warning signs that never show up on a checklist
You only hear from them when something is broken
Look at your interactions over the last six months. How many times did you reach out first, and how many times did they? If their only outbound contact is invoices and a quarterly report, they're reactive, whatever the contract says. Reactive support isn't a service level. It means there isn't one.
The knowledge lives in one technician's head
There's usually one person who knows your environment. Everyone likes them. When they're on holiday, response quality drops noticeably, and everyone has quietly accepted that. It isn't a staffing quirk. It means your environment is undocumented, and you'll find out exactly how undocumented on the day that person leaves. Question 8 exists to surface this before it happens.
Every security conversation ends in a quote
Some things genuinely cost extra, and a provider who never suggests upgrades isn't being generous. They're being passive. The real problem is when nothing is included. If enabling MFA, testing restores, reviewing admin rights, and checking logging are all separate charges, security is being treated as an add-on rather than a core part of your IT. That's the real issue, and buying more upgrades won't solve it.
What "audit-ready" means when you're buying it
There's no certification that makes a provider audit-ready, and anyone implying otherwise is describing a badge rather than a capability. What the phrase should mean is narrower and easier to check.
There should be a specific framework named, not just "best practices." Whether it's HIPAA, SOC 2, ISO 27001, NIST, PCI DSS, CMMC, or HITRUST, it has to fit your obligations. If no one can name the framework, no one is managing it.
There should be a written agreement about who is responsible for what. Which controls do they handle, which do you handle, which are shared? That's the core recommendation from the joint advisory, and it's the easiest gap to fix.
Controls should be checked where they actually run. Don't settle for a report describing the control. See the control working, with a date to prove it.
Evidence should be produced as part of normal work. If getting ready for a review means a two-week scramble, the evidence wasn't being collected. It's being recreated after the fact.
And you should get findings before you ask for them. See question 9.
Those last points are what separate an IT provider who happens to serve regulated clients from one that's built for them. For the full model, we've written a longer piece on standard IT vs. defensible IT.
What to do with the answers
Ask the nine questions and read the answers honestly.
If most answers are specific, with dates, numbers, or named people, you have a good provider and a few gaps to fix. Close the gaps. Don't switch unless you have to. Changing is disruptive, and a provider who gives clear answers is worth more than one who sells well.
If most answers are vague, don't assume the people are bad at their jobs. Usually they aren't. They're following a model built to keep systems running, not to answer these questions. The problem is the model, and hiring another provider with the same model won't fix it.
This is the gap Emry Networks was built to close. Our managed IT service treats security and compliance as core parts of the job, not extras. We start with Regulatory Discovery, scanning your environment against the frameworks that apply and giving you a plain-English Risk Status Report that shows every gap between your documentation and your actual systems. Security Hardening then stands up our managed stack: detection and response, advanced endpoint protection, managed encryption, tested backups, and round-the-clock monitoring. Continuous Management keeps it on track with ongoing monitoring, staff phishing training, backup checks, and regular compliance reviews.
Question 9 is the tell, and what it points to is whether anyone is actively looking. When a mid-sized financial advisory firm was hit by ransomware, we focused first on containing it, then restoring operations, then fixing what let it happen. The full story is in our ransomware containment case study. The compliance side of this approach is on our IT compliance page.
And ask us question 2 as well. Ask how we reach your systems and what protects that access. If we can't give you specific answers, nothing else in this article matters.
See which of the nine questions your setup can actually answer
Request an assessment and we'll walk through your live environment, then tell you where the specific answers are and where the silences are.
Request an assessmentFrequently asked questions
How do I evaluate an IT provider without a technical background?
Ask questions that require specifics rather than reassurance, and judge the answer on whether it contains a date, a number, or a name. "Are we secure?" invites a yes. "When did we last restore from backup and how long did it take?" cannot be answered without facts. A provider who can produce current, specific answers on access, patching, logging, backups, and framework alignment is showing that someone is measuring those things. A provider who needs a week to find out is showing that nobody is.
Is my IT provider really a cybersecurity risk to my business?
They are a privileged path into your environment, which makes their security posture part of yours. The 2026 Verizon Data Breach Investigations Report found third parties involved in 48% of all breaches and 55% of breaches at small and midsize businesses. Attacks abusing remote monitoring and management tools, the software providers use to reach client systems, rose sharply through 2025 and 2026, because compromising one provider can reach every client it manages. This isn't a reason to avoid outsourcing IT. It's a reason to ask your provider how they secure their own access.
What is an RMM, and why does it matter to me?
Remote monitoring and management software is how your provider sees and controls your machines without being on site. It holds persistent, high-privilege access by design, and that is what makes it useful. It also means an attacker who compromises that tool inherits the same access, across every client the provider manages, while looking like routine administration. In April 2026, Huntress documented a single compromised provider account being used to reach a domain controller and trigger the isolation of 78 businesses. Ask your provider which RMM they use, whether MFA is enforced, and what version it is running.
Does my IT provider need to sign a business associate agreement?
If they create, receive, store, or transmit protected health information on your behalf, including remote access to systems containing it, then under HIPAA they are a business associate and an agreement is required. The agreement must commit them to Security Rule safeguards and breach notification, and it should describe the data movement that actually occurs rather than repeat a generic template. If your provider uses subcontractors who can reach that data, those subcontractors are business associates too and need agreements of their own. OCR can pursue business associates directly, but you remain the regulated entity.
My provider says our backups are fine. Is that enough?
No, because "fine" usually means the backup job completed. A completed job proves the job ran. It does not prove the data is recoverable, that the restore process works, or how long recovery would take. Insurer At-Bay has reported from its claims data that more than one in four businesses hit by ransomware fail to recover data from backup despite having a backup solution in place. The question to ask is when the last restore test happened, what was restored, and how long it took. If there is no date, there has been no test.
Should I switch providers if the answers are bad?
Not automatically. Sort the failures first. If a provider gives vague answers but responds well when you press, and can produce the information within a reasonable window, the gap may be that nobody ever asked them for it, and that is fixable inside the existing relationship and far less disruptive than a migration. Switch when the model itself is the problem: when security is only ever a quote, when documentation lives in one person's head, when nothing surfaces unless you report it. Those are structural and won't change because you complained.
Sources
- Verizon, 2026 Data Breach Investigations Report: third parties involved in 48% of all breaches (up from 30% the prior year and roughly 15% the year before) and in 55% of small and midsize business breaches.
- Huntress, "Threat Advisory: Uptick in Bomgar RMM Exploitation," 17 April 2026: exploitation waves from 12 February and early April 2026; 14 April ransomware deployed via a dental software company's Bomgar instance affecting three downstream companies; 15 April compromise of a high-privilege MSP Bomgar account used to reach a domain controller, resulting in mass isolation of 78 businesses and confirmed exploitation at four downstream customers; privilege escalation to Domain Admins, secondary RMM deployment (AnyDesk, ScreenConnect, Atera, SimpleHelp), network enumeration, a vulnerable driver used against endpoint protection, LockBit deployment; affected clients running outdated versions including 21.1.3.
- BeyondTrust, security advisory BT26-02: CVE-2026-1731, critical unauthenticated remote code execution in Bomgar / Remote Support; fixes issued 6 February 2026; fixed in Remote Support 25.3.2 and Privileged Remote Access 25.1.
- Huntress, 2026 Cyber Threat Report: 277% year-over-year increase in RMM abuse during 2025.
- CISA, NSA, FBI, NCSC-UK, ACSC, CCCS and NCSC-NZ, joint Cybersecurity Advisory AA22-131A, "Protecting Against Cyber Threats to Managed Service Providers and their Customers": recommends an explicit, transparent agreement between MSPs and customers on security responsibilities and supply-chain risk ownership.
- At-Bay claims-data research on ransomware recovery: more than one in four businesses hit by ransomware fail to recover data from backup.
- HIPAA business associate definition and BAA requirements, 45 CFR §160.103 and §164.308(b): an IT provider with access to systems containing ePHI is generally a business associate; subcontractors handling PHI are business associates of the business associate.
Exact figures above are attributed to the named primary sources. Any other number in this article is presented as reasoning or as an explicit estimate and should not be read as a measured value.
Read more from our team
Explore insights on compliance and security.
Ready to strengthen your compliance?
Get hands-on assessment and guidance from our compliance experts.