Analyst monitoring network and security dashboards in a small network operations room
Articles

Managed IT and Cybersecurity: How to Audit What's Actually Included

Every managed IT proposal claims strong security. The phrasing barely varies — enterprise-grade, multi-layered, proactive, 24/7. Three proposals will make the same claim in nearly the same words, and none of them gives you a way to check it.

There is a way to check it, and it doesn't involve trusting anyone's marketing. Two organizations publish concrete, public baselines of what a security program should contain. Neither sells managed IT. You can hold any provider's scope against them, line by line, and see what's missing.

Here's how to do that.

The two yardsticks

NIST Cybersecurity Framework 2.0 gives you the structure. Published February 26, 2024, it organizes security into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is new in 2.0 — NIST added it to cover the part that isn't technical at all: who is accountable, what the policy is, and how risk decisions get made.

That's the useful shape for evaluating a proposal, because provider scopes tend to be heavy on Protect and Detect and much thinner on Govern, Respond, and Recover. Those three are where an incident actually costs you money.

CIS Critical Security Controls, Implementation Group 1 gives you the content. CIS publishes 18 Controls broken into three implementation groups, and IG1 is the entry tier: 56 safeguards that CIS itself describes as "an emerging minimum standard of information security for all enterprises."

IG1's target profile is worth quoting, because it describes CTC's typical client almost exactly. CIS says the safeguards selected for IG1 "should be implementable with limited cybersecurity expertise and aimed to thwart general, non-targeted attacks."

Fifty-six safeguards is a real number, published by a body with nothing to sell you, aimed at organizations your size. That's a far better basis for a conversation than "enterprise-grade."

What to ask for, by function

Take any proposal and sort its contents into the six Functions. The gaps show up fast.

Govern

The one most often missing entirely. Ask:

  • Who is accountable for security decisions — named, on both sides
  • How risk gets assessed and how often
  • What policies exist in writing, and who maintains them
  • How third-party and vendor risk is handled

That last item has grown teeth. Verizon's 2026 Data Breach Investigations Report found breaches with third-party involvement rose sharply year over year, reaching 48% of total breaches. In the manufacturing sector specifically, third-party involvement appeared in 61% of breaches. (Verizon sells security services, so treat the framing accordingly — but the DBIR publishes its sample sizes, methodology and contributor list, and it is the most methodologically transparent report in the category. The 2026 edition covers more than 31,000 incidents including over 22,000 confirmed breaches across 145 countries, from November 2024 through October 2025.)

Identify

You cannot protect what nobody has counted, and this is the deliverable that most often doesn't exist before an engagement starts.

  • Asset inventory — hardware, software, and who owns each
  • What's past end of support
  • Network diagrams that reflect the building as it is now
  • Data classification: what you hold and where it lives

For plants and processing facilities this extends onto the floor. CISA and eight partner agencies published Foundations for OT Cybersecurity: Asset Inventory Guidance in August 2025, and its central claim is blunt:

"An OT asset inventory—an organized, regularly updated list of an organization's OT systems, hardware, and software—is foundational to designing a modern defensible architecture because without an inventory, organizations do not know what they have and what should be secured and protected."
Technician using a rugged tablet to catalogue the contents of an open industrial control cabinet

Ask whether the provider's inventory stops at the business network or continues to the PLCs, HMIs, historians and machine-attached PCs. It's worth asking explicitly, because a scope that says "all endpoints" rarely means the ones bolted to a machine.

Protect

The part every proposal covers. What's worth checking is specificity rather than presence:

  • Multi-factor authentication — and which kind. Microsoft Research published a 2023 study (arXiv:2305.00945) using a benchmark-multiplier method across Azure AD accounts, finding MFA "reduces the risk of compromise by 99.22% across the entire population and by 98.56% in cases of leaked credentials." Microsoft sells identity products, so note the authorship — but the paper states its method and reports lower numbers than the company's own marketing has, which is worth something. The sharper practical point comes from insurance claims data: Marsh McLennan found phishing-resistant MFA correlated with a 9% lower breach likelihood than MFA that isn't. The kind matters, not just the presence.
  • Endpoint detection and response, and what share of devices it's actually deployed on. Marsh found each 25% increase in EDR coverage correlated with roughly a 10% decrease in breach likelihood.
  • Patch management on a defined cycle — including what happens to systems that can't take one
  • Email and DNS filtering
  • Network segmentation, especially between business and production networks
  • Security awareness training, run as a program rather than an annual video

Detect

  • 24/7 monitoring, and who is watching at 3am — staff, or an alert nobody reads until Monday
  • Log collection and retention, and for how long
  • Vulnerability scanning on a schedule
  • Alert triage: what actually happens when something fires

Respond

Ask for the plan as a document, not a description. Then ask when it was last exercised.

Marsh McLennan's analysis of controls against claims outcomes, published August 2025, found organizations running regular tabletop exercises and scenario drills were 13% less likely to experience a material cyber event — and ranked incident response planning among the five most effective controls overall, alongside network hardening, EDR, logging and monitoring, and awareness training with phishing testing. Marsh describes its base only as "thousands of organizations" without giving a precise sample size, so treat the percentages as directional; the ranking is the durable part.

CTC's existing article on building a cybersecurity contingency plan goes further into the planning side.

Recover

  • Backups, retention, and — the actual question — when someone last performed a test restore
  • Documented recovery time objectives, agreed with operations rather than assumed by IT
  • Who declares an incident over, and how you verify the environment is clean

The number that reframes the whole conversation

Here is the figure most security content gets exactly backwards.

The FBI's Internet Crime Complaint Center recorded 3,611 ransomware complaints in 2025, with reported losses of $32.3 million — against $20.877 billion in total reported losses across all crime types that year. Ransomware looks almost trivial in that comparison.

It isn't. IC3 explains why in its own words:

"Regarding ransomware adjusted losses, this number does not include estimates of lost business, time, wages, files, or equipment, or any third-party remediation services acquired by an entity."

The ransom is the smallest line on the invoice.

Insurance claims data shows what the rest looks like. NetDiligence's 2025 Cyber Claims Study analyzed over 800 manufacturing claims drawn from a dataset of roughly 10,500 claims covering 2020–2024. Among the 51 small and mid-sized manufacturers whose claims broke out business interruption separately, BI averaged $2.5 million against a $3 million average total incident cost.

Read that again. In the claims where someone actually measured the downtime, the downtime was the loss — the rest of the incident was a rounding error next to it.

Stopped and empty production line in a factory with the overhead lights on and no workers present

That's why this belongs in an operations conversation and not only an IT one. It's also why the Recover function matters more than the Protect function in a plant, and why a proposal that's strong on firewalls and vague on restore testing is solving the cheaper half of the problem.

(Two notes: NetDiligence is a claims-data firm serving insurers, not a security vendor selling controls, which is a cleaner commercial position than most sources in this category. And 51 claims is a small sample drawn from a more severe population than the dataset as a whole — it tells you what a bad one looks like, not what an average one costs.)

What this looks like on a plant floor

Three things change in industrial environments, and a provider's answers on these tell you quickly whether they've worked in one.

Systems that can't be patched on a normal cycle. Every plant has them, and a provider who says they patch everything on a standard schedule is telling you they haven't worked in one. The answer is segmentation, compensating controls and monitoring — ask which, for which systems, and who decided. CTC's article on bridging the IT/OT gap covers the architecture side.

Edge devices past support. CISA, the FBI and the UK's NCSC published joint guidance in February 2026 stating that "nation-state threat actors exploit end-of-support (EOS) edge devices—including, but not limited to, load balancers, firewalls, routers, and virtual private network (VPN) gateways—to gain network access, maintain presence, and compromise sensitive data." Ask your provider for the end-of-support date on every edge device you own. If they can't produce the list, the Identify function isn't being done.

Older firewall appliance and switch mounted in a dusty wall cabinet in a back utility closet

Change windows that belong to operations. A patch schedule set without reference to the production calendar isn't a security program, it's a scheduling conflict waiting to be discovered by whoever loses a shift to it. Ask who at your company has to sign off before a change goes in, and check that the provider's proposal names that person rather than assuming IT decides.

On the threat picture specifically, Verizon's 2026 manufacturing snapshot recorded 3,627 incidents with 2,713 confirmed data disclosures in the sector, with ransomware present in 61% of breaches involving malware, and exploitation of vulnerabilities the leading initial access vector at 38%. Both of those point at the same unglamorous conclusion: patching and asset inventory, not exotic threats.

CTC's existing piece on cybersecurity challenges in manufacturing covers the threat landscape in more depth.

How to actually use this

Print the six Functions. Put any proposal beside them and mark which ones it addresses with a specific, named deliverable rather than an adjective.

Then ask three questions that are hard to bluff:

  1. Which of the 56 CIS IG1 safeguards does this scope cover, and which does it not? A provider who has done this before will have an answer. One who hasn't will change the subject to their platform.
  2. What happens to systems that can't be patched on your standard cycle? There's no generic answer, which is exactly why it sorts people.
  3. When did you last participate in a tested restore for a client of our size? Not "do you offer backup." A tested restore, recently, with a date.

If you're earlier in the process and still comparing providers generally, these ten questions cover the broader evaluation.

Frequently Asked Questions

Is cybersecurity included in managed IT services?

Some is always included and the rest varies enormously, which is why two proposals at the same price can cover materially different amounts of security. The way to compare them is against a published baseline — CIS Implementation Group 1 is 56 safeguards aimed specifically at organizations with limited in-house IT expertise.

What is CIS IG1?

The entry tier of the CIS Critical Security Controls: 56 safeguards that CIS describes as an emerging minimum standard for all enterprises, implementable with limited cybersecurity expertise and aimed at thwarting general, non-targeted attacks. It's a useful checklist precisely because CIS doesn't sell managed services.

What are the six NIST Cybersecurity Framework functions?

Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in CSF 2.0, published February 2024, and covers accountability, policy, and how risk decisions get made. Most provider proposals are strong on Protect and Detect and thin on the other four.

Does managed IT include incident response?

Sometimes, sometimes at additional cost, and sometimes only as an hourly engagement after an incident starts. Ask for the plan as a document and ask when it was last exercised. Marsh McLennan's claims analysis ranked incident response planning among the five most effective controls.

How much does the security portion of managed IT cost?

Security scope is one of the largest sources of variance between two quotes — which is the argument for pricing it as a line item you can see rather than a bundled adjective. The benchmark data is here.

What's the real cost of a ransomware incident?

Far more than the ransom. The FBI's IC3 states plainly that its reported ransomware loss figures exclude lost business, time, wages, equipment, and third-party remediation. In NetDiligence's manufacturing claims data, among the 51 small and mid-sized manufacturers who broke out business interruption separately, BI averaged $2.5 million against a $3 million average total incident cost.

Audit Us Against This Too

CTC Technologies supports Michigan businesses from an Ann Arbor headquarters. We'd rather be evaluated against a published baseline than a brochure.

If you want a concrete starting point, take the Identify function first — nothing in the other five works without it. What you're running, what's past end of support, and how the business network and the production network actually connect. Then hold the rest of the checklist against whoever you're considering, us included.

Request an IT assessment or call 734-408-0200. Managed IT and network security across Michigan, including Detroit, Warren, Sterling Heights, Kalamazoo, Battle Creek, and Ann Arbor.

We Have The Proof

We Solve Complex IT and Networking Problems.

Contact Us Today