There are two ways to buy security for a business of this size, and the difference is not technical. One is to have the firm that already runs your IT do it, because it already holds the credentials, knows the estate and is accountable for the machines. The other is to buy it separately from a specialist, which brings expertise and adds a seam. Most of the waste in this market lives in that seam, where two suppliers each assume the other is doing something.
One supplier or two, and what each costs you
One supplier is simpler, cheaper and has a conflict: the firm assessing whether your IT is secure is the firm that built it. Two suppliers give independence and create a seam, where patching belongs to one and vulnerability reporting to the other, and neither owns the fix. If you use two, insist that the contract names who remediates what and within how long. If you use one, buy the assessment from somebody else even if you buy everything else from them.
What the cloud line changes
When the estate moves to cloud services, security stops being about the network and becomes about identity and configuration. The questions change accordingly: who has administrative rights, is multi-factor enforced everywhere or only recommended, what is the conditional access policy, how are the tenant settings monitored for drift, and who reviews sharing on the file store. A provider quoting cloud security in terms of appliances and perimeter is describing an estate you no longer have.
What a risk assessment should produce
An inventory of what you have, an honest list of the ways in, a prioritised set of fixes with costs, and a statement of what is being accepted rather than fixed. That last item is the one most reports omit and the one a board actually needs. Ask for the deliverable format before commissioning, and ask whether the firm producing it also sells the remediation, so the conflict is at least priced in.
The advisory line, and when it is worth a retainer
Advice sold as a retainer is worth buying when somebody has to own security as a job and nobody in the business can: a named person who attends a quarterly review, owns the risk register, answers customer security questionnaires and is on the call when something happens. It is not worth buying as a document subscription. Ask what days are included, what is delivered each quarter, and who specifically holds the role, by name.
Questions people ask about it security solutions
Should our IT provider also do security?
It can do most of it, and it has an obvious conflict on assessment. A common compromise is to buy everything from them except the assessment.
What changes when we move to the cloud?
Security becomes about identity and configuration rather than the network. Administrative rights, multi-factor coverage and tenant configuration drift are the questions.
What should a risk assessment deliver?
An inventory, the ways in, prioritised fixes with costs, and a written list of what is being accepted rather than fixed.
Is a security retainer worth it?
When somebody has to own security as a job and nobody internally can. Ask for named days, named people and a defined quarterly deliverable.