Kevin Gemeroy
Kevin is founder and president of Dynamic Computing. For more than two decades, he has been a trusted technology partner for Seattle-area businesses and nonprofits.
Who We Are
Industries
Solutions
Service Areas
Resources
Not every security breach is a major event. Some are caught quickly, affect only a single account or device, and cause little or no lasting damage.
An employee clicks a phishing link and their email is briefly compromised. A former employee has access they shouldn’t have. Malware makes it onto a workstation but is stopped before it can spread. A suspicious login reveals a password has been compromised.
In situations like these, it’s easy to fix the immediate problem and move on. After all, no sensitive data was stolen, operations weren’t disrupted, and the company avoided a much more serious incident. Security success, right?
Not exactly.
Even a small breach can be a big warning sign. And many companies, in their rush to move on from a security incident that seemed minor, often fail to ask an all-important follow-up question, which is:
How did the security breach happen in the first place?
If your business and its IT provider don’t ask this question following an incident, you’re already well behind the eight ball. Sure, that breach you just had was contained relatively quickly, but the conditions that allowed it to happen are likely still in place. And if you don’t really dig into what’s going on, the next incident can easily be much, much worse.
No IT provider can honestly guarantee that a company will never experience a cyber security incident. Threats are always evolving, employees make mistakes, software has vulnerabilities, and attackers are always poking and prodding.
But just because no security measure is bulletproof doesn’t mean your IT environment shouldn’t be designed and managed to greatly reduce risks.
Take, for example, something as simple as an employee entering their Microsoft 365 credentials into a convincing phishing site.

Quickly reporting the problem and having IT change the credentials is all well and good, but once that little fire is out, it’s time to step back and look at the bigger security picture. That means asking:
If the answer to any or all of these questions from your IT provider is “we’re working on it,” that’s a lot of smoke. If the answer is “no” or “we’re not sure,” your IT security is actively on fire.
In fact, most minor security incidents often hint at bigger problems. A former employee who can still log in can indicate an inconsistent offboarding process. Malware on a workstation can reveal gaps in endpoint protection or patching. A missing laptop can expose weaknesses in encryption, remote management, or device inventory.
Most companies assume that if they have an IT provider, someone is on top of security. The thing to keep in mind, though, is that “managed IT” can mean very different things depending on the provider.
Some providers, usually smaller ones, are primarily reactive. They respond when something breaks, help employees with technical problems, and for the most part keep systems running.
All those things are important, but maintaining technology isn’t the same as actively managing security risk. It’s baseline IT, which can work fine when a company is small, but can completely overwhelm a small internal or external IT team once the company grows.
Another common issue is IT providers relying too heavily on individual security products. They install endpoint protection, get backups running, enable MFA here and there, and call everything secured.
But security shouldn’t be a collection of products or solutions. It needs to be a system of overlapping controls, policies, configurations, monitoring, and processes. Think of security this way: A lock on the front door of your house can help stop people from breaking in, but it’s only effective if that front door is the only way into your house.
A security incident is an issue. It’s also an opportunity to dig into your relationship with your IT provider.
After the incident is addressed, your provider should be able to explain these 5 whats:
If their response feels defensive, vague, or overly focused on minimizing what happened, it’s worth paying attention to.
Because, yes, incidents occur—and they will likely occur again—but dancing around the topic, or acting like it’s been fixed so let’s just all move on already, suggests your provider doesn’t really know the current state of your IT environment.
That’s a major problem. And it’s often when a company needs to take a deep breath and conduct a comprehensive IT audit.
Many IT providers don’t like conducting, or even participating in such a big undertaking. But while it can certainly be a painful step for both the company and the IT provider, resistance to it often hints at deep security concerns.
Why? Because a comprehensive IT audit is just that—comprehensive. It means reviewing a laundry list of things, including:
Auditing these cornerstones of solid security management takes time, effort, and a willingness to answer hard questions. The goal shouldn’t be to prove a current IT provider is doing a bad job, but to establish an objective understanding of where things stand.
And if your IT provider drags their feet, rushes through the process, or objects to having an outside firm check their work? That’s not just a warning sign, it’s a blaring alarm.
At the end of the day, a relatively minor security breach can feel like a lucky escape. And in some cases, it is.
But the security issue you know isn’t necessarily the one you should be most worried about. The bigger concern is the vulnerabilities you don’t see, the ones percolating in your IT that your provider isn’t aware of or is pretending to have addressed.
So if you own a business and have recently been alarmed by a security breach of some kind—or even if you don’t really have a firm understanding of what security measures your company has in place—the sooner you start asking questions, the better.
If you ask most business owners why they switched IT providers, the answer usually isn't because of one single issue or event.It wasn't a ransomware...
A year or two ago, many organizations were still asking whether AI would meaningfully impact their industry.
For many organizations, AI security still feels vague or overly technical. Something reserved for security teams or large enterprises with dedicated AI...