← All resources

Is Your IT Company Doing Their Job? A Checklist for Houston Businesses

August 27, 2026 · Greg Brainerd

Is Your IT Company Doing Their Job? A Checklist for Houston Businesses — article illustration

One of the hardest questions I hear from Houston business owners is a quiet one: “Is my IT company actually doing their job, or am I just paying them and hoping?” It’s a fair thing to wonder. Most owners aren’t technical, so it’s tough to know whether the people protecting your network are genuinely on top of it, or coasting and counting on you not to ask hard questions.

So here’s a way to find out. This post is adapted from Chapter 11 of my book, Protecting Your Business Against Hackers, a checklist you can run against your current provider. If they don’t earn a confident “yes” on every point below, they are not adequately protecting you. Don’t let them talk you out of it, and don’t give them a free pass on any single item. You can download the full book here.

One rule before you start: get verification, not just answers. Asking “Do you have insurance to cover us if you make a mistake?” is good. Getting a copy of the actual policy is what counts: when push comes to shove, a provider can deny they ever told you anything.

The Checklist: What a Good IT Company Should Be Doing

Run down this list with your current provider in mind. Each one is a place I’ve personally seen businesses get burned.

Reviews, monitoring and reporting

  • Do they meet with you regularly? At a minimum, you should get a quarterly review and report on what they’ve done to protect you, plus a frank conversation about new threats and what to address next. If you haven’t sat down with them in the last three months, that’s a flag.
  • Do they proactively monitor, patch and update your network’s critical security settings? Daily? Weekly? At all? Are they reviewing your firewall’s event logs for suspicious activity, and can they prove it?
  • Have they recommended a comprehensive risk assessment every year? Many insurance policies require one. If you handle sensitive data (medical records, financial information, Social Security numbers), you may be legally required to.

Insurance and incident response

  • Have they ever urged you to talk to your own insurer about fraud or cyberliability coverage?
  • Do THEY carry adequate insurance to cover YOU if they make a mistake and your network is compromised? Ask for an Errors and Omissions (E&O) policy and a cyberliability policy, along with a copy of the current policy that names you for losses and damages.
  • Have they briefed you on what to do if you get compromised? You should have a written response plan in hand. If you don’t, ask why not.

Who’s actually touching your network

  • Are they outsourcing your support to a third party? Do you know who has access to your computers and network? If they’re outsourcing, have they shown you the controls that would stop a rogue technician in another country from abusing full access to your systems?
  • Are their technicians trained on current threats rather than winging it? Do they have someone experienced in conducting security risk assessments, and real partnerships with today’s major IT vendors?

Backups, devices and access

  • Do they have a ransomware-proof backup system? Part of what made WannaCry so devastating was that it hunted down and locked backup files too. Ask them to verify your backups would actually survive; don’t just take their word for it.
  • Is there a written mobile and remote device policy distributed to your team? Is data encrypted on those devices? Is there a remote “kill” switch to wipe a lost or stolen device, with backups so you can wipe it without losing files?
  • Do they enforce strong passwords and regular password updates in line with NIST guidance? When an employee quits or is fired, is there a process to change all passwords, and can you see it?
  • Have they implemented multi-factor authentication for access to sensitive data? (If you’re not sure whether you have it, you don’t.)
  • Do they still allow remote access through tools like GoToMyPC, LogMeIn or TeamViewer? That’s a reason to be concerned. Remote access should run strictly through a secure VPN.

Modern protection beyond antivirus

  • Have they talked about replacing old antivirus with advanced endpoint security? There’s broad agreement in the industry that traditional antivirus can’t stop today’s sophisticated attacks on its own.
  • Have they implemented web-filtering to keep employees off infected sites and content you don’t want on company equipment?
  • Have they configured your email to prevent confidential or protected data, like Social Security numbers, from being sent or received?
  • Do they offer dark web / deep web ID monitoring that watches cybercrime sites for your credentials being sold or traded, and alerts you so you can react fast?
  • Do they offer a Security Information and Event Management (SIEM) solution to catch unwanted traffic coming from inside your own network?

Your people: the front line

  • Have they given you and your team cyber security awareness training? Employees clicking a phishing email or downloading a malicious file is still the number-one way criminals get in. Have they helped you build an acceptable use policy (AUP)?
  • Do they run simulated phishing emails to test your staff? There’s no better teacher than a real-life scenario, and anyone who fails should get more training.

If you read that list and felt your stomach drop at how many you couldn’t answer, you’re not alone. A good IT partner welcomes every one of these questions. (For how we cover them under one roof, see our managed IT services page.)

The Only Way to Be Truly Sure: An Outside Assessment

Here’s the catch with grading your own provider: they’re the ones answering the questions. A real security assessment reviews, evaluates and stress-tests your network to uncover loopholes before a cyber event happens, like a cancer screening that catches problems while they’re small and cheap to fix.

It should always be done by a qualified third party, not your current IT team. Fresh eyes see what’s hidden in plain sight from the people staring at it every day. You get someone investigating on your behalf who isn’t trying to cover up gaps, just a clear, confidential report you can understand.

That’s what our risk assessment delivers: confidential verification on whether your provider is doing everything they should. We’ll show you whether your credentials are already for sale on the dark web, whether your systems are truly secured, whether your backup would actually survive ransomware, and whether your employees can spot a phishing email when we put them to the test. If we find problems, we’ll hand you an action plan, and you decide what to do with it.

Frequently Asked Questions

How do I know if I should switch IT companies?

Run the checklist above. If your provider can’t give you a confident, verifiable “yes” on the critical items (regular security reviews, proactive monitoring, ransomware-proof backups, MFA, employee training and proper insurance), they aren’t fully protecting you. One or two gaps may be a conversation; a wall of “no” answers is a reason to look elsewhere.

Should my current IT company run the security assessment?

No. It should be done by a qualified third party, not the team already managing your network. People looking at the same systems every day miss what they’ve grown used to, and they have an incentive not to surface their own shortcomings. Fresh, independent eyes give you an honest picture.

What’s the most important thing a good IT company does?

Real protection is layered, so there’s no single thing. But what separates a good provider from a coasting one is proactivity and accountability: meeting with you regularly, monitoring and patching without being asked, verifying your backups, training your people, and being able to prove all of it rather than just reassure you.

My IT guy says we’re covered. Isn’t that enough?

Not on its own. “We’ve got you covered” is exactly the reassurance that falls apart the day ransomware hits and you discover the backup never worked. Don’t take protection on faith. Get verification: copies of policies, proof of monitoring, and an independent assessment so you’re certain rather than hopeful.

Ready to Get the Facts?

You’ve spent years building your business. Don’t leave its safety to “hope” your IT guy has it handled. Get the facts and be certain.

If you want a clearer picture before you commit to anything, our IT Buyer’s Guide walks you through what to look for in a provider. When you’re ready to talk, book a discovery call or reach us in Houston at 281-367-8253. We’ll come in with no hard sell, just fact-based answers so you can make a smart, informed decision.

Schedule a Discovery Call

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.