What cyber security should your IT provider include?
Most managed IT contracts say "security included" somewhere. Here is what that phrase should actually mean, mapped to the five Cyber Essentials controls, plus the extras a small business needs and the ones that are fair to charge for.

Just over four in 10 UK businesses (43%) were hit by a cyber attack or breach in the past year, according to the government's Cyber Security Breaches Survey 2025/2026. In the same survey, fewer than half (47%) use two-factor authentication. Most of the gap between those two numbers is an IT provider's job.
What should be included as standard?
Start with the five technical controls behind the NCSC's Cyber Essentials scheme. They exist because most attacks are basic, the digital version of trying the front door. If your provider is not doing all five, you are paying for IT support without the security part.
Firewalls. Every office connection and every laptop behind a firewall that has been configured, with default passwords changed and remote access through controlled routes only. 74% of businesses have one, so a quarter do not.
Secure configuration. New devices arrive set up for convenience. Your provider should strip unnecessary software, enforce screen locks and apply the Cyber Essentials password standard of at least 12 characters, or eight with common passwords blocked.
User access control. Nobody does day-to-day work as an administrator. Leavers lose access the day they leave, and admin accounts are separate and named. 73% of businesses restrict admin rights. Ask to see the list.
Malware protection. Managed protection on every device, centrally reported, with someone reading the reports. 81% of businesses say they have it, which makes it the control most often assumed rather than checked.
Security update management. The Cyber Essentials requirements say critical and high-risk updates must be applied within 14 days of release. Your provider should be able to tell you, for any month, what percentage of your devices met that deadline. If they cannot, patching is being hoped for.
Only 24% of businesses have all five controls in place. That is the clearest single measure of whether an IT provider is doing its job.
What else should a small business expect?
Cyber Essentials is a floor. For a business of 10 to 100 people, we think the following also belong inside the monthly fee.
- Two-factor authentication on every account. Email, file storage, accounting, the lot. Cyber Essentials requires it for cloud services, and it stops most account takeovers before they start.
- Backups with tested restores. 74% of businesses back up to the cloud. Far fewer have ever restored from it. Expect a restore test at least quarterly, with a note confirming what came back and how long it took.
- Email filtering. Phishing is the most common attack by a long way, reported by 38% of businesses. A filtering layer in front of your mailboxes should be standard, with the settings reviewed rather than left on defaults.
- Monitoring and alerting. The tooling your provider uses to patch your devices can also tell them something is wrong before you ring. If the first they hear of a problem is from you, that is break-fix with a monthly invoice.
- A written incident response plan. Only 25% of businesses have one. Yours should fit on two pages: who to call, who decides whether to pay a ransom, how staff are told, and when the ICO is notified. Your provider writes the first draft with you.
- Basic staff awareness. A short briefing for new starters and a reminder when a convincing phishing email does the rounds. Only 19% of businesses ran any staff training last year, so 20 minutes puts you ahead of most.
What is fair to charge extra for?
Quite a lot. A provider that bundles everything below into a fixed fee is either charging a premium or quietly not doing it.
- Cyber Essentials certification itself. The controls should be included. The assessment and certificate fee (from £320 plus VAT) are a project. We have covered what Cyber Essentials actually involves separately.
- Simulated phishing campaigns. Fake phishing emails sent to your own staff, with training for the people who click. Useful and measurable.
- 24/7 detection and response. A human watching alerts overnight with authority to isolate a device at 3am. Most 20-person firms do not need it. A firm handling client funds or patient data probably does.
- Penetration testing. Paying a specialist to try to break in. Worth doing before a big tender or a compliance audit, not every month.
- Compliance frameworks. ISO 27001, SOC 2 and the NHS Data Security and Protection Toolkit are months of work. We took a care provider through its first DSPT submission, and it was priced as consultancy.
If the standard list is missing from your contract and the add-ons are being sold to you instead, read what should be in an IT support contract before you sign.
Does your IT provider's own security matter?
More than almost anything else here. Your provider holds administrator access to everything you own. If they are compromised, so are you, and the attacker arrives with valid credentials.
The NCSC guidance on choosing an MSP gives you four things to ask for.
- Named accounts. Every engineer works under their own identity, so you know who did what.
- Multi-factor authentication on their access to you. Including the remote support tools, where it is most often missing.
- Least privilege. Engineers get the permissions the job needs, reviewed when their staff change.
- Logs you can see. How long are records of their activity on your systems kept, and can you get them?
The NCSC also suggests looking for a provider with Cyber Essentials Plus or equivalent, so ask yours where it stands and when it was last assessed.
How do you check what you are actually getting?
Four requests, none needing a technical background.
- The patching report. One month, every device, how many met the 14-day window. A provider doing the work has it in minutes.
- The list of people without two-factor authentication. The right answer is "nobody", or a short list with reasons.
- The date of the last restore test. Not the last backup. The last time something was recovered from it.
- The incident plan. If it does not exist, that is your first project together.
A law firm came to us needing Cyber Essentials Plus for a tender. Because the five controls were already in place and documented, certification took a month. For how security weighs against response times and contract terms, see our guide to choosing an IT support provider.
What we do
Systemwork has supported businesses across Leeds and Yorkshire since 2005. Our managed IT support is a fixed monthly price per user, with a service desk staffed by engineers and proactive monitoring included. Site visits are included too, except for project work.
We guide clients through Cyber Essentials, ISO 27001, SOC 2 and NHS DSPT when the business case is there, and say so when it is not. How security fits with the rest of what an MSP does, and what the fee typically costs in the UK, is covered elsewhere.
Book a free IT audit. We will check your setup against the five controls and the extras above, and tell you plainly what we find. Call 0113 898 0565 or use the button below.
Frequently asked questions
Is cyber security normally included in managed IT support?
The basics should be, and most contracts say they are, but "security included" rarely defines what that means. Ask for the five Cyber Essentials controls, two-factor authentication everywhere, tested backups, email filtering, monitoring and an incident plan to be named in the contract. Treat anything less as a gap.
What is the difference between Cyber Essentials and having the Cyber Essentials controls?
The controls are the technical work: firewalls, secure configuration, access control, malware protection and 14-day patching. Certification is an assessed check that they are in place, with a certificate you can show customers and insurers. Your IT provider should be doing the controls regardless, and certification becomes a separate project when someone asks for it.
Do small businesses really need 24/7 security monitoring?
Most do not, and a provider pushing it on a 15-person firm without a specific reason is upselling. Automated alerting in business hours with a clear out-of-hours escalation route covers most small businesses. Firms handling client money or health data, or answering to a regulator, are the usual exceptions.
How do I know if my IT provider's own security is good enough?
Ask four questions. Does every engineer use a named account on your systems? Is multi-factor authentication enforced on their access to you? Are their admin permissions limited to what the job needs? Can you see logs of what they did? A provider with good answers will be pleased you asked, and one without them is a risk you are paying for.
