Cybersecurity is a trust purchase — you’re buying something you hope never to see working. That makes it easy to sell badly and hard to buy well. These questions cut through.
The eight questions
- 1. "When an alert fires at 2am Saturday, what happens in the first 30 minutes — and who does it?" Vague answers mean nobody is actually watching.
- 2. "What exactly will you do in our first 30 days?" Good providers lead with basics: MFA, patching, backups. Beware anyone leading with their dashboard.
- 3. "How do you report to us, and can we see a sample?" You want plain-English monthly reporting a non-technical owner can read.
- 4. "What’s included in the price, and what triggers extra charges?" Incident response included, or billed hourly at crisis rates? Get it in writing.
- 5. "Will you work alongside our existing IT provider?" The right answer is yes, with a clear split of duties.
- 6. "How do you map your work to the Essential Eight?" If they can’t, they can’t support your insurance or tender story either.
- 7. "What happens if we leave?" Data, credentials and tooling should hand over cleanly. Lock-in by obscurity is a red flag.
- 8. "Can you give us a reference from a business our size?" Enterprise logos are nice; a 20-person client who renewed twice is proof.
Red flags worth walking away from
Fear-first selling ("you’re probably already breached"), guarantees of 100% protection (nobody honest offers one), pricing that only appears after a "free audit", and contracts where every incident costs extra. Security providers should reduce your anxiety with clarity, not farm it.
And one more signal: how they explain things. If the sales conversation is jargon soup, the incident call at 2am will be too. Pick the provider who can make complexity plain — that skill is the product.
Want help with this in your business?
Book a free security check with our Sydney team — plain-English advice, no obligation.
Get a Free Security Check