An audit is a snapshot; managed security is the movie
A security audit tells you how things stand today. Managed cybersecurity is someone keeping them that way, because settings drift, staff changes, new laptops appear, and attackers don't check your calendar. Both are real services; confusing them is how businesses end up paying for an annual PDF and calling themselves protected.
The honest split: an audit is a one-time project with findings and a fix list. Managed security is a monthly service with monitoring, maintenance, and a human who answers when something looks wrong. This article is about the second one: what should be in it, what it costs, and where its limits are.
The five areas a managed service should cover
For a small business, managed security should cover five areas. If a proposal skips one, ask why.
- Identity. Your accounts are the front door. The service should enforce multi-factor authentication, the second confirmation step beyond a password, on every account, review who has admin rights quarterly, and disable departed staff the day they leave.
- Email. Most small-business attacks arrive as email. That means filtering, plus the DNS records called SPF, DKIM, and DMARC that stop criminals from sending mail that appears to come from your domain, plus a way for staff to report suspicious messages and get an answer.
- Endpoints. Every company computer runs monitored protection software and gets its updates applied on a schedule you can verify, not whenever the user clicks OK.
- Website. If your site takes payments or leads, it needs uptime monitoring, software patching, and someone watching for defacement or injected spam. Websites are the most publicly embarrassing thing to lose.
- Backups. Automatic, offsite, and test-restored on a schedule, with the restore results reported to you. Backups are a security control because ransomware, malicious software that encrypts your files and demands payment, is defeated primarily by having clean copies elsewhere.
Alerts and monitoring: who is actually watching?
Around-the-clock monitoring appears in every brochure, so ask what it means mechanically. Software generates alerts; the question is who reads them and what they're empowered to do.
Reasonable questions for any provider:
- When an alert fires at 2am Saturday, does a human see it before Monday?
- What actions will you take without calling me first, like isolating an infected laptop or blocking a sign-in from another country, and what requires my approval?
- Roughly how many alerts do your clients generate in a month, and how many turn out to be real?
That last one isn't a gotcha. A provider who tunes their tools will happily tell you most alerts are noise and explain how they filter it. A provider who just forwards raw alerts to your inbox has sold you anxiety, not monitoring.
Reporting and incident roles: decide who does what before it matters
Two documents separate a mature service from a logo page.
The monthly report should be plain-English and specific: what was patched, what alerts fired and what came of them, who joined or left your staff accounts, when backups last restored successfully, and what the provider recommends next. If you can't understand the report, the report is the problem, not you.
The incident plan should fit on one page and name names: who declares an incident, who gets called and in what order, who talks to customers, who has authority to shut things down, and where the cyber-insurance policy number lives. You do not want to be inventing this list during the incident. A good provider drafts it with you in the first month.
Realistic boundaries: what no provider can promise
Boundaries matter, and honest providers state them.
No provider can promise you won't be breached; anyone who does is telling you they haven't been tested. What a good service promises is that the common attacks fail, the uncommon ones are noticed fast, and recovery is measured in hours, not weeks.
Managed security also isn't compliance certification, it isn't insurance, and it can't fix a business rule like letting anyone in accounting wire money on an emailed request. That fix is yours to make, though a good provider will flag it.
On price: for a small business, managed security typically runs 30 to 100 dollars per user per month on top of, or bundled with, general IT support. The range is driven by how much of the five areas is included and whether compliance requirements apply. Cheaper than that usually means software licenses with no humans attached.
What to do next
How to move on this without a big project:
- Ask your current IT provider, or yourself if you are the IT provider, which of the five areas are covered today: identity, email, endpoints, website, backups. Write the honest yes/no list.
- For every yes, ask for one piece of recent evidence: the last patch report, the last test restore, the MFA enforcement screenshot. A yes without evidence is a maybe.
- Close the identity gaps first: MFA everywhere, admin cleanup, same-day offboarding. They're the highest risk and mostly cost effort, not money.
- Then get quotes for the rest as a monthly service, and compare against the five-area list, not against brochures.
I'm Security+ certified and this is core work at HashWhales for businesses across the DMV. The five-area gap conversation is a free phone call, and you'll know your exposure by the end of it.
