Start with the problem your business needs to control
A device-security product can be valuable without covering every route through which business data is used or lost. An account, mailbox, cloud application, backup and administrator role each have their own controls and dependencies. Compare the complete requirement, not just the number of product features.
NIST’s Cybersecurity Framework is intended to help organisations understand and manage cybersecurity risk. It is a useful reference for broadening the discussion beyond one protective tool; citing it does not mean a supplier or customer has been certified. NIST Cybersecurity Framework.
For a Kenyan organisation seeking managed support, ask for a service boundary you can read: named systems, operating hours, permitted actions, customer responsibilities and an escalation path. “Managed” without those details can mean different things to different suppliers.
Software and operational responsibility are different purchases
A license may include product updates and access to features. It does not automatically include configuring your tenant, enrolling every device, investigating an alert or training a new administrator. Check whether the quotation is for software, initial setup, recurring management or a combination.
Equally, a managed service does not remove your business’s accountability. Your team may still need to approve disruptive changes, maintain accurate staff records, protect administrator access and decide how long a service can be interrupted. Responsibilities should be explicit on both sides.
Compare coverage by business layer
Identity
Useful question for the provider: Who reviews administrator access, MFA and departed users?
Evidence to request: Account/control checklist and ownership record
Useful question for the provider: Who configures protection and handles suspicious-mail reports?
Evidence to request: Agreed policy and escalation example
Endpoints
Useful question for the provider: Which devices are enrolled, healthy or unsupported?
Evidence to request: Asset and coverage report
Configuration
Useful question for the provider: Who authorises and verifies changes and updates?
Evidence to request: Change record and exception list
Visibility
Useful question for the provider: Which alerts are reviewed and during which hours?
Evidence to request: Defined queue and handling procedure
Recovery
Useful question for the provider: Who owns copies, restoration tests and dependencies?
Evidence to request: Approved restore-test evidence
An unconfigured feature and an operationally owned control are not the same outcome. Ask to see a sanitised or clearly labelled example of the reporting you would receive, without requesting another customer’s sensitive records.
Understand device protection without overstating it
Endpoint capabilities and licensing vary. Define the supported operating systems, ownership types, servers and enrolment method. A report should distinguish a device that is enrolled from one that is actually checking in and receiving policy.
Agree what happens to unsupported, offline or personally owned devices. Do not assume that a product license grants permission to inspect an employee’s personal files. The Managed Endpoint Protection service should describe the approved policy, visibility and remediation boundary rather than promise perfect protection.
Ask exactly what alert handling includes
Who reviews an alert? What information is available? Which actions are permitted without further approval? When should the business contact be called? What happens outside the agreed human service hours?
A notification sent to an unattended inbox is not equivalent to an investigation. Likewise, an investigation is not automatically containment or recovery. Distinguish these stages in the service description and request a way to identify unresolved exceptions.
Foxbyte’s published human hours are Monday-Friday 08:00-17:30 and Saturday 09:00-13:00, Africa/Nairobi; Sunday/public holidays are closed unless separately contracted. This page does not claim a staffed 24/7 SOC, MDR, emergency incident-response team or penetration-testing service.
Include accounts, email and recovery in the conversation
Microsoft’s business-security overview separates account security, email/collaboration security and device security, and describes different capabilities by subscription. That reinforces why a buyer should check the actual license and configured scope instead of treating all Microsoft 365 plans as identical. Microsoft business-security overview.
For accounts and email, use Microsoft 365 and Email Security and the buyer checklist to identify specific questions. For recovery, inspect what was restored, when and by whom. A recent backup-job success alone does not show that the business can resume work.
Agree the customer responsibilities
List the information and decisions the service needs from you: staff changes, critical systems, authorised contacts, maintenance windows and approval limits. Identify who retains master credentials privately and how emergency access is controlled. Never send passwords or one-time codes in ordinary support requests.
Clarify which projects are outside the recurring agreement, such as a large migration or recovery after an incident. Also define license renewal, onboarding/offboarding and the handover at the end of the engagement. A long list of exclusions should not conceal the core service; it should make the practical agreement understandable.
What a useful review should show
A proportionate review can show covered assets, control changes, significant alerts, unresolved issues and next actions. Each important action needs an owner and an agreed priority. Avoid presenting a single security score as proof that all risk has been removed.
Measure improvement against the agreed scope and recorded baseline. Request explanations for missing visibility or unsupported systems rather than silently treating them as protected. If the provider cannot verify a control, the report should say so.
Choose a scoped service, not a comforting label
Begin with the systems and outcomes that matter most to your operations. Foxbyte’s Managed Cybersecurity service separates baseline review, hardening and agreed management. The backup and ransomware-readiness guide helps you question recovery assumptions without expecting guaranteed decryption.
Discuss your security priorities