Trust But Verify: How to Evaluate and Hold Your Security Providers Accountable
Accreditation, certifications, and contracts matter — but they are not a substitute for ongoing verification. Here is how to evaluate your security providers and hold them accountable to the standard you need.
By Tom Brennan
The security incidents that hurt organizations the most are often ones where a trusted provider failed — an MSSP that missed a critical alert, a penetration testing firm that missed a critical vulnerability. Trust but verify.
Evaluating Security Providers Before You Hire
Relevant Certifications
- Penetration testing firms: CREST membership, PTES adherence, OSCP/CRTO certified testers
- MSSPs: SOC 2 Type II, ISO 27001, 24/7 operations with documented SLAs
References and Case Studies
Ask for client references in your industry. Ask specifically about how the provider handled incidents and difficult findings. How a provider handles adversity tells you more than their sales materials.
Holding Providers Accountable Ongoing
- Establish clear SLAs with financial consequences for failure
- Require quarterly business reviews for ongoing service relationships
- Include right-to-audit clauses in all security provider contracts
- Use third-party validation to verify MSSP performance periodically
Proactive Risk operates with full transparency. We welcome right-to-audit provisions and actively encourage clients to validate our work independently.
Explore Related Resources