
Every managed IT proposal claims strong security. The phrasing barely varies — enterprise-grade, multi-layered, proactive, 24/7. Three proposals will make the same claim in nearly the same words, and none of them gives you a way to check it.
There is a way to check it, and it doesn't involve trusting anyone's marketing. Two organizations publish concrete, public baselines of what a security program should contain. Neither sells managed IT. You can hold any provider's scope against them, line by line, and see what's missing.
Here's how to do that.
NIST Cybersecurity Framework 2.0 gives you the structure. Published February 26, 2024, it organizes security into six Functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is new in 2.0 — NIST added it to cover the part that isn't technical at all: who is accountable, what the policy is, and how risk decisions get made.
That's the useful shape for evaluating a proposal, because provider scopes tend to be heavy on Protect and Detect and much thinner on Govern, Respond, and Recover. Those three are where an incident actually costs you money.
CIS Critical Security Controls, Implementation Group 1 gives you the content. CIS publishes 18 Controls broken into three implementation groups, and IG1 is the entry tier: 56 safeguards that CIS itself describes as "an emerging minimum standard of information security for all enterprises."
IG1's target profile is worth quoting, because it describes CTC's typical client almost exactly. CIS says the safeguards selected for IG1 "should be implementable with limited cybersecurity expertise and aimed to thwart general, non-targeted attacks."
Fifty-six safeguards is a real number, published by a body with nothing to sell you, aimed at organizations your size. That's a far better basis for a conversation than "enterprise-grade."
Take any proposal and sort its contents into the six Functions. The gaps show up fast.
The one most often missing entirely. Ask:
That last item has grown teeth. Verizon's 2026 Data Breach Investigations Report found breaches with third-party involvement rose sharply year over year, reaching 48% of total breaches. In the manufacturing sector specifically, third-party involvement appeared in 61% of breaches. (Verizon sells security services, so treat the framing accordingly — but the DBIR publishes its sample sizes, methodology and contributor list, and it is the most methodologically transparent report in the category. The 2026 edition covers more than 31,000 incidents including over 22,000 confirmed breaches across 145 countries, from November 2024 through October 2025.)
You cannot protect what nobody has counted, and this is the deliverable that most often doesn't exist before an engagement starts.
For plants and processing facilities this extends onto the floor. CISA and eight partner agencies published Foundations for OT Cybersecurity: Asset Inventory Guidance in August 2025, and its central claim is blunt:
"An OT asset inventory—an organized, regularly updated list of an organization's OT systems, hardware, and software—is foundational to designing a modern defensible architecture because without an inventory, organizations do not know what they have and what should be secured and protected."

Ask whether the provider's inventory stops at the business network or continues to the PLCs, HMIs, historians and machine-attached PCs. It's worth asking explicitly, because a scope that says "all endpoints" rarely means the ones bolted to a machine.
The part every proposal covers. What's worth checking is specificity rather than presence:
Ask for the plan as a document, not a description. Then ask when it was last exercised.
Marsh McLennan's analysis of controls against claims outcomes, published August 2025, found organizations running regular tabletop exercises and scenario drills were 13% less likely to experience a material cyber event — and ranked incident response planning among the five most effective controls overall, alongside network hardening, EDR, logging and monitoring, and awareness training with phishing testing. Marsh describes its base only as "thousands of organizations" without giving a precise sample size, so treat the percentages as directional; the ranking is the durable part.
CTC's existing article on building a cybersecurity contingency plan goes further into the planning side.
Here is the figure most security content gets exactly backwards.
The FBI's Internet Crime Complaint Center recorded 3,611 ransomware complaints in 2025, with reported losses of $32.3 million — against $20.877 billion in total reported losses across all crime types that year. Ransomware looks almost trivial in that comparison.
It isn't. IC3 explains why in its own words:
"Regarding ransomware adjusted losses, this number does not include estimates of lost business, time, wages, files, or equipment, or any third-party remediation services acquired by an entity."
The ransom is the smallest line on the invoice.
Insurance claims data shows what the rest looks like. NetDiligence's 2025 Cyber Claims Study analyzed over 800 manufacturing claims drawn from a dataset of roughly 10,500 claims covering 2020–2024. Among the 51 small and mid-sized manufacturers whose claims broke out business interruption separately, BI averaged $2.5 million against a $3 million average total incident cost.
Read that again. In the claims where someone actually measured the downtime, the downtime was the loss — the rest of the incident was a rounding error next to it.

That's why this belongs in an operations conversation and not only an IT one. It's also why the Recover function matters more than the Protect function in a plant, and why a proposal that's strong on firewalls and vague on restore testing is solving the cheaper half of the problem.
(Two notes: NetDiligence is a claims-data firm serving insurers, not a security vendor selling controls, which is a cleaner commercial position than most sources in this category. And 51 claims is a small sample drawn from a more severe population than the dataset as a whole — it tells you what a bad one looks like, not what an average one costs.)
Three things change in industrial environments, and a provider's answers on these tell you quickly whether they've worked in one.
Systems that can't be patched on a normal cycle. Every plant has them, and a provider who says they patch everything on a standard schedule is telling you they haven't worked in one. The answer is segmentation, compensating controls and monitoring — ask which, for which systems, and who decided. CTC's article on bridging the IT/OT gap covers the architecture side.
Edge devices past support. CISA, the FBI and the UK's NCSC published joint guidance in February 2026 stating that "nation-state threat actors exploit end-of-support (EOS) edge devices—including, but not limited to, load balancers, firewalls, routers, and virtual private network (VPN) gateways—to gain network access, maintain presence, and compromise sensitive data." Ask your provider for the end-of-support date on every edge device you own. If they can't produce the list, the Identify function isn't being done.

Change windows that belong to operations. A patch schedule set without reference to the production calendar isn't a security program, it's a scheduling conflict waiting to be discovered by whoever loses a shift to it. Ask who at your company has to sign off before a change goes in, and check that the provider's proposal names that person rather than assuming IT decides.
On the threat picture specifically, Verizon's 2026 manufacturing snapshot recorded 3,627 incidents with 2,713 confirmed data disclosures in the sector, with ransomware present in 61% of breaches involving malware, and exploitation of vulnerabilities the leading initial access vector at 38%. Both of those point at the same unglamorous conclusion: patching and asset inventory, not exotic threats.
CTC's existing piece on cybersecurity challenges in manufacturing covers the threat landscape in more depth.
Print the six Functions. Put any proposal beside them and mark which ones it addresses with a specific, named deliverable rather than an adjective.
Then ask three questions that are hard to bluff:
If you're earlier in the process and still comparing providers generally, these ten questions cover the broader evaluation.
Is cybersecurity included in managed IT services?
Some is always included and the rest varies enormously, which is why two proposals at the same price can cover materially different amounts of security. The way to compare them is against a published baseline — CIS Implementation Group 1 is 56 safeguards aimed specifically at organizations with limited in-house IT expertise.
What is CIS IG1?
The entry tier of the CIS Critical Security Controls: 56 safeguards that CIS describes as an emerging minimum standard for all enterprises, implementable with limited cybersecurity expertise and aimed at thwarting general, non-targeted attacks. It's a useful checklist precisely because CIS doesn't sell managed services.
What are the six NIST Cybersecurity Framework functions?
Govern, Identify, Protect, Detect, Respond, and Recover. Govern was added in CSF 2.0, published February 2024, and covers accountability, policy, and how risk decisions get made. Most provider proposals are strong on Protect and Detect and thin on the other four.
Does managed IT include incident response?
Sometimes, sometimes at additional cost, and sometimes only as an hourly engagement after an incident starts. Ask for the plan as a document and ask when it was last exercised. Marsh McLennan's claims analysis ranked incident response planning among the five most effective controls.
How much does the security portion of managed IT cost?
Security scope is one of the largest sources of variance between two quotes — which is the argument for pricing it as a line item you can see rather than a bundled adjective. The benchmark data is here.
What's the real cost of a ransomware incident?
Far more than the ransom. The FBI's IC3 states plainly that its reported ransomware loss figures exclude lost business, time, wages, equipment, and third-party remediation. In NetDiligence's manufacturing claims data, among the 51 small and mid-sized manufacturers who broke out business interruption separately, BI averaged $2.5 million against a $3 million average total incident cost.
CTC Technologies supports Michigan businesses from an Ann Arbor headquarters. We'd rather be evaluated against a published baseline than a brochure.
If you want a concrete starting point, take the Identify function first — nothing in the other five works without it. What you're running, what's past end of support, and how the business network and the production network actually connect. Then hold the rest of the checklist against whoever you're considering, us included.
Request an IT assessment or call 734-408-0200. Managed IT and network security across Michigan, including Detroit, Warren, Sterling Heights, Kalamazoo, Battle Creek, and Ann Arbor.