How to Choose A Cyber Security Consultant

How to choose a cyber security consultant

Table of Contents

The best way to evaluate a cyber security consultant isn’t to check their certifications or read their case studies. It’s to ask them specific technical questions and listen carefully to how they answer.

Vague answers to specific questions tell you something concrete: the consultant isn’t running environments at the level they’re describing. These aren’t trick questions. Any capable provider should answer them without hesitation.

Ask about patching

“How do you manage the patching requirement for internet-facing services?”

A good answer names a tool, a timeline and a reporting mechanism. Something like: “We use Intune for Windows patching. Internet-facing services are on a 48-hour SLA from patch release. You get a monthly compliance report showing anything outside that window. For actively exploited vulnerabilities, we can push immediately.”

A vague answer sounds like: “We handle all your patching as part of the service.”

No tool. No timeline. No reporting. Follow up by asking what happens when a patch needs testing before deployment. A good answer describes an exceptional process. Silence is an answer too.

Ask about multi-factor authentication

“Which MFA methods do you use, and are there any you won’t recommend?”

A good answer addresses method, scope, and the difference between maturity levels. Something like: “We require authenticator apps as a minimum – SMS is no longer sufficient for Essential Eight Level Two compliance. We configure Azure AD to block SMS as a fallback and enforce MFA across VPNs, backup portals, and admin accounts, not just email. For higher risk environments we move to hardware keys.”

A vague answer sounds like: “We use Microsoft Authenticator.”

That tells you nothing about SMS fallback, which systems are in scope, or whether they understand the distinction between maturity levels. Ask specifically: “Which systems will MFA be enforced on?” The answer should go well beyond email.

Ask about application control

“What’s the difference between application control and endpoint protection?”

A good answer is direct: “Endpoint protection uses a blocklist – it blocks known threats. Application control uses an allowlist – only approved software can run. They’re fundamentally different. At Level Two, application control extends to scripts and installers, not just executable files. We implement it in audit mode first, usually for four to six weeks, to work through the legitimate exceptions before we enforce.”

A vague answer sounds like: “We have endpoint protection that prevents unauthorised software from running.”

If they describe endpoint protection as application control, they’re not implementing the Essential Eight correctly.

Ask about backups

“Walk me through how your backup setup would prevent a ransomware attack from destroying our backups.”

A good answer covers isolation, access controls and testing. Something like: “Backups run to a separate cloud subscription with its own credentials, so your production environment can write to it but can’t delete or modify anything. We use immutable storage with a retention lock. Every quarter we do a documented test restoration – an actual file recovery with a written record.”

A vague answer sounds like: “Your backups go to the cloud.”

This tells you nothing about isolation, access controls or whether the backups have ever actually been restored. If they haven’t tested recovery, you don’t have a backup strategy – you have a backup assumption.

Ask what happens when things go wrong

“What happens if we get breached while you’re managing our security?”

Many businesses forget to ask this before signing. It’s the most important question on this list.

A good answer is specific: who you call, what happens in the first hour, whether there’s after-hours support, how they handle forensics and evidence preservation, and what support looks like through recovery. A good provider has thought about this and can walk you through it.

A poor answer sounds like: “We’ll help you sort it out.” No process, no timeline, no clarity on who’s responsible for what.

This question also tells you something about how the provider thinks about their own accountability. A consultant who’s confident in their controls has a clean answer. One who isn’t tends to get vague.

Running through these five questions in a first conversation takes fifteen minutes. The answers, and more importantly, the confidence or hesitation behind them, tell you more than a website or a brochure.

Windstil provides cyber security consulting for Australian businesses. Our active clients enjoy a structured, ongoing approach to Essential Eight, with clear prioritisation, consistent progress and guidance to improve their maturity over time. 

Subscribe to our newsletter

  Stay informed with practical IT and cyber security insights, along with company updates, announcements, and the work we’re doing with businesses like yours.