Choosing a Security Partner Is a Risk Decision
Handing security responsibilities to an outside firm means giving them deep access to your systems and trusting their judgement when something goes wrong at three in the morning. It deserves more scrutiny than most procurement processes apply.
Decide What You Are Actually Buying
“Security services” covers very different things. Monitoring and detection is a continuous operational service. Penetration testing is a point-in-time assessment. Compliance readiness is advisory. Incident response is an emergency capability you hope not to use.
Firms tend to be genuinely strong in one or two of these and adequate in the rest. Being clear about which you need prevents buying a bundle where the part you care about is the weakest component.
Ask Who Actually Does the Work
The team in the pitch is frequently not the team on your account. Ask who will be assigned, what their experience is, and whether any of the work is subcontracted. Ask about analyst turnover — high churn in a monitoring service means the people watching your environment are permanently new to it.
Test Their Detection Claims
Every provider claims comprehensive coverage. Make it concrete: which log sources do they ingest, what detections run against them, how are those tuned to your environment, and how are false positives handled? A provider that cannot answer specifically is selling a dashboard.
Ask for a redacted example of a real alert they escalated, and what the customer was told to do.
Response Times Need Definitions, Not Numbers
A fifteen-minute response commitment means nothing until you know what is being measured. Time to acknowledge? To triage? To contain? Get the definitions, the measurement method, the reporting, and what happens when the target is missed.
Confirm They Can Act, Not Just Alert
There is a large difference between a provider who tells you something is wrong and one who can contain it. Can they isolate a host, disable an account, block traffic — and under what authority? Agree those boundaries in advance, because the incident is the wrong time to discover nobody is empowered to act.
Compliance and Jurisdiction
If you operate under specific frameworks, confirm the provider has worked within them rather than merely read about them. Establish where your data is stored and processed, who can access it, and what their own certifications cover — the scope of a certificate often excludes the service you are buying.
Exit Before Entry
Ask how you leave. Do you keep your log history? In what format? How long does transition take, and what does it cost? A provider who has not thought about this has designed a relationship that is hard to leave, which is not the same as one worth staying in.
References From Bad Days
Reference calls about smooth engagements tell you little. Ask for a customer who had a real incident, and ask them how the provider behaved: communication, escalation, honesty about what was missed. That is the behaviour you are buying.
Conclusion
Define the service precisely, verify the people and the detections, and agree authority and exit terms before signing.
Serigor Inc advises on security programmes and staffing for commercial and government environments. Get in touch.
