Cybersecurity
We Are 22 People. We Cannot Hire a Security Expert, and Honestly We Would Not Know What to Ask One to Do.
The owner of an independent insurance agency in New Castle spent twenty years selling other people protection against the things that go wrong. Then his own carrier sent over a renewal packet, and inside it was a twelve-page cyber liability questionnaire. Do you enforce multi-factor authentication on company email? Do you have endpoint detection deployed on every workstation? Do you run security awareness training at least annually? Do you keep backups that an attacker cannot reach? He read the thing twice, got to the last page, and realized he could not honestly answer yes to most of it. He also realized he had no idea who in his 22-person office was supposed to fix that. He was not going to hire a full-time security specialist (he could not justify the salary, and one person cannot watch a network at two in the morning on a Saturday anyway). That gap, between what a small business is now expected to have in place and what it can realistically staff, is exactly what outsourcing cyber security exists to close, and it is where most small and mid-sized businesses in Western Pennsylvania are quietly sitting right now.
If that sounds familiar, the good news is that the answer is not a hire and it is not a shopping spree on security software. It is a program someone else runs for you. Below is what that actually looks like in practice, how to tell whether the IT company you already pay is doing any of it, why the insurance questionnaire is a bigger deal than it appears, and the specific questions to ask before you sign with anyone.
Why can't a company our size just hire someone to handle security?
Because the math does not work, and it does not work for reasons that have nothing to do with being cheap.
Start with the salary. A qualified security professional (someone who can actually investigate an alert at midnight, not just install antivirus) commands a market rate that competes with Pittsburgh and Cleveland employers, not with what a 22-person agency in Lawrence County budgeted for its next hire. Even a business willing to stretch for that number runs into the second problem immediately.
Attacks do not keep office hours. The ransomware that encrypts a server almost always lands on a Friday night, over a holiday weekend, or at three in the morning, precisely because that is when nobody is watching. Covering a network around the clock genuinely takes four or five people working in rotation. You cannot buy round-the-clock coverage by hiring one person, no matter how good they are. You buy one person's weekdays and a pager they will eventually resent.
Then there is the loneliness problem, which owners underestimate. A single in-house security person has no peer to check their work, no second opinion when something looks odd, and no visibility into what attacks are hitting other businesses this week. They are guessing in isolation. Meanwhile the tools that make the job possible (detection platforms, log collection, threat intelligence feeds) are priced and licensed for organizations far larger than yours, so the individual hire arrives without the equipment to do the work.
And in most small offices, the job has already quietly landed on someone who never asked for it. The operations manager who is good with computers. The owner's nephew. The one employee who set up the WiFi once, so now everything technology-related is theirs. That person is not a security program. They are a single point of failure with a full-time job somewhere else in your business.
What does outsourcing cyber security actually include?
This is where the term gets vague, so it is worth being specific. A real outsourced security program is not a product you install. It is a set of ongoing functions, run by a team, on a schedule, with someone accountable for each one.
A genuine program covers:
- Continuous monitoring and detection. Software watches your systems constantly, and (this is the part that matters) trained people review what it flags. An alert nobody reads is not security. It is a log file.
- Endpoint protection on every machine. Modern endpoint protection does not just match known viruses. It watches for the behavior of an attack in progress, like a process suddenly encrypting hundreds of files, and stops it mid-act.
- Email security. The overwhelming majority of successful attacks on small businesses arrive by email, dressed as an invoice, a shipping notice, or a message from the boss. Filtering, link inspection, and impersonation protection block most of it before a human ever has to make a judgment call.
- Patching on a schedule. Every operating system, browser, and business application gets its security updates on a defined cadence, so you are never the company breached through a hole that was publicly fixed eight months ago.
- Identity and access control. Multi-factor authentication on email and remote access, sensible password policy, and prompt removal of accounts when people leave. This single category closes more real-world attacks than any other.
- Device coverage beyond the desktop. Company data lives on phones and tablets now, which is its own exposure. If you have never had a way to lock or wipe a device that walks out the door, that is a gap worth reading about separately in what happens when an employee leaves with a phone full of company data.
- Employee training that is actually run. Short, regular, human training plus simulated phishing so people learn on a harmless fake instead of a real wire transfer. Your staff is either your weakest layer or your best sensor, and what a real awareness program contains is what decides which.
- Backup verification. Not "we have backups," but proof that the backups exist, are separated from the network an attacker would reach, and have been test-restored recently.
- Incident response. A written plan and a phone number that gets answered when something happens, so the first hour of a breach is executed instead of improvised.
- Reporting you can hand to someone. Documentation of what is in place, which is what your insurer, your auditor, or your largest customer is going to ask for.
Notice how much of that is process rather than product. That is the real reason outsourcing cyber security works at this size: you are not renting software, you are renting the discipline to run it every week without fail.
Does my IT company already do this, or do they just fix things when they break?
This is the uncomfortable question, and a lot of owners assume the answer is yes when it is not.
Plenty of small IT providers are genuinely good at support. They answer the phone, they get the printer working, they rebuild the laptop that died. That is help desk work, and it is valuable. It is also reactive by design, and security is the opposite of reactive. A provider can be excellent at fixing what broke and still have nobody monitoring anything at eleven at night.
There is a simple test. Ask your current provider to show you last month's security reporting: what was detected, what was blocked, which machines were missing patches and when they were brought current, and who reviewed it. A provider running a real program produces that in a day, because it already exists. A provider doing support with security bolted on will tell you they will "put something together," which is your answer.
This gap also explains something owners run into constantly when comparing proposals. Two IT quotes can be far apart in price while looking like the same service, and the difference is almost always sitting in this exact category. We wrote about why three IT companies can quote three wildly different numbers for what appears to be the same thing, and security is the most common thing missing from the cheap one. It is also worth knowing that service quality can quietly change hands without the sign on the door changing, which is a familiar story for anyone whose provider was bought by a larger company.
What does this have to do with the cyber insurance questionnaire on my desk?
More than most owners realize, and this is the part worth reading twice.
Cyber liability carriers have spent the last several years paying out on small-business ransomware claims, and they have responded by turning the application into a technical audit. Multi-factor authentication, endpoint detection, tested offline backups, and documented employee training are no longer bonus points. On many policies they are conditions of coverage.
That creates a risk that has nothing to do with hackers. If you answer yes to a control you do not actually have, and you later file a claim, the carrier reviews those answers. A misstatement on the application can reduce a payout or void the policy outright, which means the business that thought it was insured discovers at the worst possible moment that it was not. Answering the questionnaire truthfully, and then closing the gaps, is the only version of this that protects you.
The regulatory layer sits right on top of it, and it varies by what you do. An insurance agency or accounting firm holds Social Security numbers, bank details, and financial records, and Pennsylvania's breach notification law puts real obligations on you if that data gets out. A medical or dental practice is HIPAA-bound, where a single lost unencrypted device can become a reportable breach with federal reporting and patient notification attached. A restaurant or retailer taking card payments answers to PCI requirements. In each case, security stops being an IT preference and becomes a line item someone outside your business can hold you to.
That is the useful reframe. The money you spend here is not really buying software. It is buying the ability to answer yes, truthfully, to the questions your insurer, your regulator, and your biggest customers are already asking.
What should I ask before outsourcing cyber security to anyone?
Ask these, and ask every provider the same set so the answers can be compared side by side:
- Who is watching my systems outside of business hours, and where are those people? Is it a real rotation or a phone that rings at someone's house?
- What exactly is included in the monthly price, and which of these functions are add-ons? Get monitoring, endpoint protection, email security, patching, and training accounted for individually.
- What will you actually do in the first hour of a ransomware event, and is that written down?
- Will you help me complete my cyber insurance questionnaire honestly, and can you back up every yes?
- What reporting do I receive, how often, and can I see a real sample from a current client?
- Are you securing my backups against an attacker who already has access to the network?
- How do you handle a departing employee's accounts and devices, and how quickly?
A provider running a real program answers all of that comfortably, with specifics. One selling security as a checkbox will get vague around the third question. That difference is the whole decision.
If you do not know where you currently stand, the honest starting point is not a proposal but a look at what you actually have. A cybersecurity assessment inventories your real exposure (which machines are unprotected, where multi-factor is missing, whether your backups would survive an attack) so that any spending afterward is aimed at something specific rather than guessed at. That is the same idea behind what a proper IT assessment covers, applied to the security side.
If you have a questionnaire on your desk that you cannot answer, or you simply want to know how exposed your business is before someone else finds out for you, we can help. We work with small and mid-sized businesses across Mercer, Lawrence, Butler, Crawford, and the surrounding Western PA counties (from New Castle to Hermitage to Meadville), and we will walk you through it in plain English with no scare tactics and no jargon. Call us at 833-859-9021 or Request an IT assessment through our contact page, and we will show you exactly where you stand.