Cybersecurity / Foxbyte Insights

Managed cybersecurity versus antivirus: compare the responsibility

Antivirus is a tool or capability. Managed cybersecurity is an agreed operating service: who configures protections, reviews information, responds within scope and reports what still needs attention. Buying a license does not answer those responsibility questions.

Foxbyte InsightsPublished Updated

Cybersecurity connects access, protection and recovery with business ownership.

Start with the problem your business needs to control

A device-security product can be valuable without covering every route through which business data is used or lost. An account, mailbox, cloud application, backup and administrator role each have their own controls and dependencies. Compare the complete requirement, not just the number of product features.

NIST’s Cybersecurity Framework is intended to help organisations understand and manage cybersecurity risk. It is a useful reference for broadening the discussion beyond one protective tool; citing it does not mean a supplier or customer has been certified. NIST Cybersecurity Framework.

For a Kenyan organisation seeking managed support, ask for a service boundary you can read: named systems, operating hours, permitted actions, customer responsibilities and an escalation path. “Managed” without those details can mean different things to different suppliers.

Software and operational responsibility are different purchases

A license may include product updates and access to features. It does not automatically include configuring your tenant, enrolling every device, investigating an alert or training a new administrator. Check whether the quotation is for software, initial setup, recurring management or a combination.

Equally, a managed service does not remove your business’s accountability. Your team may still need to approve disruptive changes, maintain accurate staff records, protect administrator access and decide how long a service can be interrupted. Responsibilities should be explicit on both sides.

Compare coverage by business layer

Identity

Useful question for the provider: Who reviews administrator access, MFA and departed users?

Evidence to request: Account/control checklist and ownership record

Email

Useful question for the provider: Who configures protection and handles suspicious-mail reports?

Evidence to request: Agreed policy and escalation example

Endpoints

Useful question for the provider: Which devices are enrolled, healthy or unsupported?

Evidence to request: Asset and coverage report

Configuration

Useful question for the provider: Who authorises and verifies changes and updates?

Evidence to request: Change record and exception list

Visibility

Useful question for the provider: Which alerts are reviewed and during which hours?

Evidence to request: Defined queue and handling procedure

Recovery

Useful question for the provider: Who owns copies, restoration tests and dependencies?

Evidence to request: Approved restore-test evidence

An unconfigured feature and an operationally owned control are not the same outcome. Ask to see a sanitised or clearly labelled example of the reporting you would receive, without requesting another customer’s sensitive records.

Understand device protection without overstating it

Endpoint capabilities and licensing vary. Define the supported operating systems, ownership types, servers and enrolment method. A report should distinguish a device that is enrolled from one that is actually checking in and receiving policy.

Agree what happens to unsupported, offline or personally owned devices. Do not assume that a product license grants permission to inspect an employee’s personal files. The Managed Endpoint Protection service should describe the approved policy, visibility and remediation boundary rather than promise perfect protection.

Ask exactly what alert handling includes

Who reviews an alert? What information is available? Which actions are permitted without further approval? When should the business contact be called? What happens outside the agreed human service hours?

A notification sent to an unattended inbox is not equivalent to an investigation. Likewise, an investigation is not automatically containment or recovery. Distinguish these stages in the service description and request a way to identify unresolved exceptions.

Foxbyte’s published human hours are Monday-Friday 08:00-17:30 and Saturday 09:00-13:00, Africa/Nairobi; Sunday/public holidays are closed unless separately contracted. This page does not claim a staffed 24/7 SOC, MDR, emergency incident-response team or penetration-testing service.

Include accounts, email and recovery in the conversation

Microsoft’s business-security overview separates account security, email/collaboration security and device security, and describes different capabilities by subscription. That reinforces why a buyer should check the actual license and configured scope instead of treating all Microsoft 365 plans as identical. Microsoft business-security overview.

For accounts and email, use Microsoft 365 and Email Security and the buyer checklist to identify specific questions. For recovery, inspect what was restored, when and by whom. A recent backup-job success alone does not show that the business can resume work.

Agree the customer responsibilities

List the information and decisions the service needs from you: staff changes, critical systems, authorised contacts, maintenance windows and approval limits. Identify who retains master credentials privately and how emergency access is controlled. Never send passwords or one-time codes in ordinary support requests.

Clarify which projects are outside the recurring agreement, such as a large migration or recovery after an incident. Also define license renewal, onboarding/offboarding and the handover at the end of the engagement. A long list of exclusions should not conceal the core service; it should make the practical agreement understandable.

What a useful review should show

A proportionate review can show covered assets, control changes, significant alerts, unresolved issues and next actions. Each important action needs an owner and an agreed priority. Avoid presenting a single security score as proof that all risk has been removed.

Measure improvement against the agreed scope and recorded baseline. Request explanations for missing visibility or unsupported systems rather than silently treating them as protected. If the provider cannot verify a control, the report should say so.

Choose a scoped service, not a comforting label

Begin with the systems and outcomes that matter most to your operations. Foxbyte’s Managed Cybersecurity service separates baseline review, hardening and agreed management. The backup and ransomware-readiness guide helps you question recovery assumptions without expecting guaranteed decryption.

Discuss your security priorities
Talk to Us

Talk to Us

AI-assisted · Human help available

How can we help?

I’m Foxbyte’s AI assistant. Ask about a service, or talk to a person.

Scroll to Top