Network Essentials

5 Questions to Ask Your MSP After a Breach

Another breach just made national news. A hospital network, a big-box retailer, a SaaS platform your team might even use, the details change, but the pattern doesn’t. Employee data gets…

Another breach just made national news. A hospital network, a big-box retailer, a SaaS platform your team might even use, the details change, but the pattern doesn’t. Employee data gets stolen. Systems go down for days. Customers get notified their information is exposed.

If you’re a business owner in Charlotte or anywhere in the surrounding region, this is the moment to pick up the phone and call your managed service provider. Not out of panic. Out of good sense.

A headline breach is a free, real-world test case. It shows you exactly what kind of attack is working right now, against real companies, with real consequences. The question worth asking isn’t “could that happen to a company our size?” It’s “would that specific attack have worked on us?”

Here are the five questions to ask your MSP after a headline breach, and what a real answer should sound like.

Why a Headline Breach Should Trigger a Conversation With Your MSP

Most business owners read breach news and feel a flicker of concern, then move on. That’s understandable. You have a business to run, and cybersecurity isn’t your job.

But it’s your MSP’s job. A breach in the news is a natural trigger point to confirm they’re actually doing it, not just billing for it.

Think of it like a fire at a business down the street. You wouldn’t ignore it just because it wasn’t your building. You’d check your own exits, your own alarms, your own extinguishers. A headline breach deserves the same reflex, applied to your network instead of your building.

What Counts as a ‘Headline Breach’ and Why It Matters to You

A headline breach is any incident big enough to make the news: a hospital system knocked offline, a retailer’s customer database exposed, a software vendor your business relies on getting compromised.

These stories can feel distant. The company involved is bigger than yours, in a different industry, with a different budget. But the attack vector often isn’t distant at all.

When a major hospital system, retailer, or SaaS platform makes headlines for a breach, the attack vector, a phishing email, an unpatched VPN, a stolen credential, is often just as relevant to a 20-person Charlotte business as it is to the enterprise that got hit. Attackers don’t usually pick targets by size. They pick targets by which door is unlocked.

Question 1: How Would This Specific Attack Have Played Out on Our Network?

This is the question that separates a real conversation from a reassuring pat on the back.

Don’t accept “we’re protected against that” as an answer. Ask your MSP to walk through the actual mechanics of the breach. Was it a phishing email that tricked an employee into handing over credentials? An unpatched VPN appliance? A third-party vendor with weak access controls?

Then ask them to map that same path onto your environment. Do you use the same VPN brand? Do you have multi-factor authentication in front of it? Would an employee clicking that exact link land somewhere your monitoring would catch, or somewhere it wouldn’t?

A good MSP answers this in specifics: which systems, which controls, which gaps. A vague “we’ve got you covered” means they haven’t actually looked.

Question 2: When Was Our Last Real Security Assessment, and What Did It Find?

Security isn’t a one-time setup. It’s an ongoing process of testing, finding gaps, and closing them. The second question is about timing and evidence, not intentions.

Ask when your last real assessment happened. Not a sales conversation. Not a general checkup. A structured review of your vulnerabilities, your patch levels, and your exposure.

Then ask what it found, and what changed as a result.

Do We Have Documented Proof, Not Just Verbal Assurance?

If the answer is a confident “we check things regularly,” push further. Ask for the report. Ask for the logs. Ask for dates.

A provider running things properly should be able to hand you documented security monitoring, not just describe it from memory. That documentation should show what was tested, what was found, and what got fixed.

TNEUS clients undergo documented security assessments and backup testing as part of ongoing managed services, not just after an incident makes the news. That’s the baseline every business should expect from an IT partner. If your provider can’t produce anything on paper, treat that as an answer in itself.

For businesses that need more strategic oversight than a standard help desk provides, fractional security leadership can fill that gap. It means reviewing your risk posture on an ongoing basis rather than reacting only when something breaks.

Question 3: What Is Our Actual Recovery Time If We’re Hit Tomorrow?

Prevention matters, but no defense is perfect. The third question flips from “can this happen to us” to “what happens after it does.”

Ask for a real number: how many hours or days would it take to restore your systems if ransomware hit tonight? This is your recovery time objective, or RTO. Ask, too, how much data you’d lose in the process. That’s your recovery point objective, or RPO.

Vague answers like “we’d get you back up pretty quickly” aren’t good enough. You need hours, not adjectives.

Backup Testing and Business Continuity Guarantees

Having backups is not the same as having tested backups. Plenty of businesses discover, mid-crisis, that their backup files are corrupted, incomplete, or years out of date because no one verified them.

Ask your MSP how often backups are tested, not just scheduled. Ask what a restoration drill actually looks like and when the last one happened.

This is also where ransomware recovery planning and a written business continuity plan come into play. Both should exist before an incident, not get improvised during one. If your provider can’t point to a specific recovery time and a tested backup process, you don’t actually know how resilient your business is.

Question 4: Are We Covered for This Threat Type Specifically, or Just Threats in General?

General protection and specific protection are not the same thing, even though they get talked about as if they are.

A business that assumes “we have a firewall” equals “we’re protected” is applying general coverage to a specific, evolving threat. That’s the same gap that turns isolated incidents into industry-wide headlines. Firewalls and antivirus software matter. But they’re broad tools, and breaches usually succeed through a narrow, specific weakness.

Ask your MSP whether you have the controls that would have stopped this particular attack. If the breach involved stolen credentials, do you enforce multi-factor authentication everywhere, including for administrator accounts and remote access? If it involved an unpatched VPN or software vendor, how quickly does your provider apply patches for that specific product?

If the breach involved a compromised third-party vendor, ask how your provider vets the vendors and software your business relies on. Zero trust principles, where nothing on the network is automatically trusted just because it’s already inside, are especially relevant here. A generic “we monitor for threats” answer skips the part where you find out if you were exposed to this threat.

Question 5: What Changes After This, What’s Different Next Week?

The final question tests whether your MSP treats a headline breach as useful intelligence, or just news.

A strong provider should walk away from this conversation with a short list of concrete actions. Maybe it’s patching a specific system faster. Maybe it’s rolling out MFA to a group of users who don’t have it yet. Maybe it’s adjusting monitoring rules to catch the specific pattern seen in the breach.

If the answer is essentially “nothing, we’re already covered,” that’s a red flag, not reassurance. Threats evolve constantly. A provider that never adjusts anything after a major incident either isn’t paying attention or isn’t being honest with you.

The difference between a proactive IT partner and a reactive one often shows up exactly in this moment: one calls you before you ask, the other waits to be asked.

What Good Answers Sound Like, And Red Flags to Watch For

By now you’ve noticed a pattern. Good answers are specific. They name systems, numbers, dates, and actions. Weak answers are vague and reassuring in tone but empty in substance.

A good MSP tells you exactly which of your systems share the vulnerability behind the headline breach. They can name your last assessment date and summarize its findings. They give you an actual recovery time in hours, not a comforting guess. They distinguish between general protections you already have and specific controls the breach exposed as missing. And they bring you a plan, not just a status update.

Signs Your MSP Isn’t Taking the Breach Seriously

Watch for a few warning signs. If your provider brushes off the question with “don’t worry, you’re fine,” without offering to check anything, that’s deflection, not evidence. If they can’t produce documentation when asked, that’s a gap in accountability, not just paperwork.

If every conversation about security turns into an upsell pitch instead of a straight answer, that’s worth noticing too. And if you have to be the one who brings up the breach, rather than your provider reaching out first, ask yourself how many other risks are going unmentioned.

These patterns often overlap with broader signs your IT provider is falling short on proactive service in general, not just around breach response.

If your last conversation with your MSP left you with more questions than answers, that’s worth acting on. A proactive IT management approach means these five questions get answered before you ever have to ask them, not scrambled together after you do.

Business owners across Charlotte, Concord, Huntersville, Gastonia, Rock Hill, and the rest of the region rely on TNEUS for exactly this kind of proactive check-in. If you want a second opinion on whether your business is exposed to the same attack behind the latest headline, request a security review and see how your current setup holds up. It’s a practical first step, and it connects directly to the broader cybersecurity services in Charlotte that keep businesses like yours out of the next headline.

And if this exercise makes you reconsider your provider relationship altogether, a resource on how to choose a managed IT provider can help you compare what you have against what you should expect.

Smart Technology to Maximize Productivity