← Back to blog

2026-09-07 · Security Basics

Ask Your IT Host These 8 Questions Before You Renew

Eight practical questions to ask your IT host before you renew — MFA proof, backup restores, patching, offboarding, and what a good answer sounds like.

Renewal is the calm moment to check that your managed IT provider or MSP (managed service provider) can show the work — not just describe it.

Print this card, or copy the table below. Collect a dated answer and a piece of proof for each question. CISA’s Four Cybersecurity Essentials for Businesses and Cybersecurity Performance Goals cover the same ground: require MFA (multi-factor authentication), update software, keep backups you can restore, and know what happens when something looks wrong.

What should I ask my IT host before I renew? Ask for proof of MFA coverage, a restore from the last 90 days, how backups are isolated and who holds the keys, patch cadence, who has Global Admin (MFA still required on break-glass), same-day offboarding, after-hours alerts, and insurance-ready evidence.

How to use this card (5 minutes)

  1. Pick the meeting. A 20-minute call or a written reply is enough. Send the eight questions in advance.
  2. Ask for proof, not adjectives. A screenshot, dated log, or ticket number beats “we’re covered.”
  3. Write what you hear. Use the table below. Leave blanks as unknown. Do not guess.
  4. Set a follow-up date if anything is missing — before you sign, not after.

Look, listen, and document. You do not need to change settings on this call.

The 8 questions

For each item: what to ask, what a good answer sounds like, and what is too vague to accept.

1. When did you last verify MFA coverage?

Ask: “When did you last confirm MFA is required, people are enrolled, and it works on real apps — not just that a policy exists?”

Point them at the 20-minute MFA coverage drill. Microsoft’s Multifactor authentication for Microsoft 365 guidance is one enforcement path: Security Defaults or Conditional Access — never both. Zero Trust guidance for small businesses calls this “verify explicitly.”

  • Good: “We ran coverage on [date]. Here’s the enrollment export and three sign-in checks. Path is Security Defaults or Conditional Access — not both.”
  • Vague: “MFA is on for everyone.” No date, no enrollment list, no real-app check.

2. Can you show a successful restore from the last 90 days?

Ask: “Can you show a restore of a real file or mailbox from the last 90 days — opened, usable, and written down?”

CISA CPG 2.0 (3.O, Maintain System Backups & Restoration Ability) asks organizations to store backups offsite and offline and to test recovery on a recurring basis. A 90-day restore is a practical renewal check. Use the 15-minute backup test if you want to run one yourself.

  • Good: “Restore on [date]. File [name], source [system], opened successfully. Log is here.”
  • Vague: “Backups run every night.” Running is not restoring.

3. Are backups offline, offsite, or immutable — and who holds the keys?

Ask: “Where does the copy live that ransomware cannot easily reach, and who can unlock it?”

The #StopRansomware Guide recommends offline, encrypted backups and regular integrity tests. Cloud sync alone is not that copy. If the host holds encryption keys, write down who else can reach them if that person is out.

  • Good: “One copy is offline, offsite, or immutable. Keys are held by [role]. The owner has a documented recovery path.”
  • Vague: “Everything is in the cloud.” No isolation, no key owner.

4. What is the patch cadence?

Ask: “How often do you apply security updates to Microsoft 365, endpoints, and firewalls — and how do I see that it happened?”

Four Essentials includes “update business software.” CPG 2.0 asks for timely patching of known vulnerabilities, especially on anything reachable from the internet.

  • Good: “Monthly, or faster for critical fixes. Here’s last month’s patch report or ticket list. Exceptions are written down.”
  • Vague: “We keep everything up to date.” No schedule, no last-run date.

5. Who has Global Admin — and does break-glass still use MFA?

Ask: “Who holds Global Administrator today, including any emergency (break-glass) account? Confirm that account still requires MFA.”

Prefer a FIDO2 security key for that emergency account. Store the key with recovery materials. Never skip MFA on break-glass. “Emergency” is not a reason to leave a password-only Global Admin. NIST SP 800-63B-4 and CPG 2.0 (3.F) put phishing-resistant methods first; SMS last.

  • Good: “Two named Global Admins, both enrolled. Break-glass uses a security key. Here’s the role list dated [date].”
  • Vague: “We keep a password-only emergency admin so we can always get in.” That is a gap. Do not accept it.

Does a break-glass admin account need MFA? Yes. Prefer a FIDO2 security key. Do not create a no-MFA exception.

6. Can you offboard the same day someone leaves?

Ask: “If someone leaves at 2 p.m., what is disabled by end of day — email, VPN, shared passwords, devices, and admin roles?”

CPG 2.0 (3.D, Revoking Credentials for Departing Staff) calls for a defined offboarding process that revokes access to systems and facilities.

  • Good: “Same-day checklist: mailbox, sign-in, VPN, password vault, devices, admin roles. Owner [name] runs it. Last drill: [date].”
  • Vague: “We disable them when you tell us.” No checklist, no clock.

7. What happens after hours if you suspect ransomware?

Ask: “Who do I call after 6 p.m., what do you do in the first hour, and when do you notify me?”

CPG 2.0 asks MSP contracts to say how and when the provider notifies you of an incident. StopRansomware includes a response checklist. You need a path, not a slogan.

  • Good: “On-call contact, first-hour steps (isolate, preserve, notify owner), and a written path if ransomware is suspected.”
  • Vague: “Call the help desk and we’ll take a look.” No after-hours owner, no suspicion path.

A full ransomware-recovery playbook is coming soon. Until then, use CISA’s #StopRansomware Guide.

8. Can you give us insurance-ready evidence?

Ask: “If our insurer asks for MFA, backup, and patching proof, what dated artifacts can you hand us this week?”

This is a folder habit, not legal or coverage advice. A dated log is more useful than a marketing PDF.

  • Good: “MFA coverage log, last restore log, patch report, admin/role list — each dated. We can refresh at renewal.”
  • Vague: “We can fill out the form.” A form without artifacts is a claim, not evidence.

Document answers

Copy this table. One row per question. Proof can be a screenshot, export, ticket, or shared log.

QuestionAnswerProofDateFollow-up
1. MFA coverage last verified
2. Restore in last 90 days
3. Offline / offsite / immutable + key holder
4. Patch cadence
5. Global Admin / break-glass (MFA still required)
6. Same-day offboarding
7. After-hours / ransomware suspicion path
8. Insurance-ready evidence

Save as IT-host-renewal-YYYY-MM-DD where the owner can find it.

When the answer is “we’ll get back to you”

That is allowed. It is not a yes.

Write the date they said it. Ask for the proof by a date before you sign. If the item is MFA coverage, a recent restore, or break-glass MFA, treat a missing answer as a hold.

A host who needs a week to find a restore log is giving you useful information. A host who cannot produce one before renewal is also giving you useful information.

What if my IT host says they’ll get back to me? Record the date, set a proof deadline before you sign, and leave the row as unknown until the artifact arrives.

Related guides

Endpoint detection (EDR) guidance is coming soon. This card does not link unpublished posts.


Educational content only — not legal, insurance, or compliance advice.

Need help implementing this in Houston?

Houston Secure IT can walk through MFA, backups, and a practical baseline with you.

713-364-8666Houston Secure IT / shop line