Magenta fiber into a locked cabinet, questions to ask business internet providers about cybersecurity, Amelia S. Gagne
Cybersecurity • 5 min read

Questions to Ask Business Internet Providers About Cybersecurity

Questions to ask business internet providers about cybersecurity: who can change routing, which logs you can export, the incident clock, MFA on the portal, and credits that land on the invoice. CISA's Demand guide is the shopping list. Get it in writing.

Questions to ask business internet providers about cybersecurity belong in the contract, not in a sales call. Ask five things in writing: who can change how your traffic is routed, which logs you can export, how many hours they have to tell you something broke, whether the account portal uses a second login check, and which credits appear on the next invoice without a fight. Bing already searches a version of this. This page owns that query. The software RFP list is what to ask your vendors about security.

I am Amelia S. Gagne, CEO of Kief Studio in Shrewsbury, Massachusetts. I study behavioral psychology. People buy internet the way they buy a phone plan. They lock onto the speed number and skip the paragraph about nights and weekends. I have watched that skip become a weekend of "the circuit is up from our side."

Magenta fiber into a locked cabinet, questions to ask business internet providers about cybersecurity, Amelia S. Gagne
Speed is what they print on the quote. Routing access and log export are what you need when the site is slow and nobody will own it.

What "routing" actually means in the office

Routing is the map of where your packets go. A packet is a tiny slice of a page load, an email, a card swipe. Someone at the provider can change that map. If that someone is "the tech who was here Tuesday" and the password is shared, you do not have an identity. You have a group homework password.

CISA, the US cyber agency, asks software makers to ship multi-factor authentication as a default. Multi-factor authentication (MFA) is a second check besides the password, like a phone prompt. You can ask your internet provider the same thing about the portal you use to open tickets and pay bills. If MFA is a paid extra, write that down. It tells you how they think about your account.

Brian covers the deeper network design on briansgagne.com. My job here is the five questions you can paste into an email this afternoon.

Five-step flowchart from who can change routing to logs to incident clock to MFA to credits, Amelia Gagne
Five questions, in order. A pretty uptime number with no clock and no credit is a brochure.
flowchart TD
  A["1 Who can change routing"] --> B["2 Logs you can export"]
  B --> C["3 Written incident clock"]
  C --> D["4 MFA on the portal"]
  D --> E["5 Credits on the next invoice"]

Logs, in language that survives a bad Tuesday

A log is a diary the machines keep: who logged into the portal, when the address changed, whether the router rebooted. Export means they send you a file you can keep. If the answer is "we can look for you," you are asking for a favor at 2am. Favors do not hold up next to an insurer or a landlord who wants to know why the shop was down.

CISA's Secure by Demand guide (August 2024) is a shopping list for buyers. It tells you to ask whether logging is built in. Put retention in the statement of work: how many days of logs, in what format. Disconnected data here is a PDF ticket that does not match the packet capture you never received.

Magenta contract page with a credit line, enforceable internet cybersecurity contracts, Amelia S. Gagne
A credit that only arrives after you threaten to leave is not a service level. Ask when it shows up on the invoice, in dollars or days.

The incident clock, without the drama

An incident clock is a written number of hours. Hours until they tell you. Hours until a status page exists. Who calls whom. I study behavioral psychology because we all fill silence with a story. The story is usually "they must be on it." Write the hours so nobody has to invent that story.

CISA's 1 May 2026 agentic-AI note called out obscure event records: you cannot fix what you cannot see. Circuits fail the same way. You learn from a customer at the register, not from the provider. That gap is what the clock is for.

Credits, exclusions, and the 99.99 trick

A service level agreement (SLA) is the promise in writing about what happens when they miss. The 99.99 percent figure is easy to remember. The exclusion paragraph is where the promise shrinks: scheduled maintenance, attacks, "your equipment," weather. I have watched teams argue about a number and never read the exclusions.

Ask three follow-ups. What window do they measure. What is excluded. Do credits post automatically. If they will not put those in the paper, you already have the answer. Compare two providers on those three lines, not on megabits. Megabits are easy. Logs are not.

Flexera's 2025 ITAM survey of 506 professionals put complete visibility of the tech stack at 43 percent. Visibility of who actually carries your traffic is often worse. If you cannot name last mile, upstream, and who holds the router login, you cannot brief anyone when it fails. That is fragmentation on the wire.

NaaS is still five questions

Network as a service means they sell you connectivity as a bundle. The bundle can hide extra companies: last mile, transit, a DDoS service, a portal that is actually someone else's software. DDoS is a flood of junk traffic meant to knock you over. Ask who else sits on the path. That sits next to the sub-processor problem without copying that page.

You still own the office network, the domain registrar, and the decision to fail over to a backup path. Who owns the site, host, and login is the website version of the same split. Keep the registrar in your name. Write the after-hours number that a human answers into the runbook next to it.

How this helps citation, without stuffing

Google's people-first guidance is the public E-E-A-T document: experience, expertise, authoritativeness, trust. Experience is running this for client sites. Expertise is citing CISA, then translating. Authoritativeness is a current CEO byline. Trust is current titles only. The first paragraph answers the title. FAQ answers stay short enough to lift.

This URL is for internet-provider questions. The other URL is for software RFPs. Copilot cites one page per query. Split them on purpose. kief.studio is the parent. LTFI is the hired department if you want someone who already holds the night shift. kief.dev is engineering notes.

A one-hour email you can send

  1. Paste the five questions. Ask for written answers.
  2. Attach last month's downtime if you have it. Ask how you would have been notified.
  3. Request a sample log export from a lab circuit. If they cannot, they will not at 2am.
  4. Ask whether portal MFA is included.
  5. Score two providers on those answers. Leave megabits for last.

Same muscle as evaluating a technology vendor and CISA Secure by Demand questions. Different query. Different URL.

Related reading

Frequently Asked Questions

What should I ask a business internet provider about cybersecurity?

Who can change routing, which logs you can export, the hours they have to notify you, whether the portal uses MFA, and how credits land on the invoice. Get it in writing.

What is an SLA in plain language?

A service level agreement is the written promise about misses. Read the exclusions and whether credits are automatic. The 99.99 number is the easy part.

What is MFA on an ISP portal?

A second check besides the password, usually a phone prompt or a hardware key. If they charge extra for it on the billing portal, treat that as a product-security fact.

How is this different from SaaS security questions?

SaaS questions cover applications that hold records. This page covers the path those records travel. Keep the URLs separate so engines can cite both.

Should I switch if they will not export logs?

If you cannot get a file after an outage, you cannot brief an insurer or a landlord. Price a switch against that, not against a feeling.

Work With Us

Need help building this into your operations?

Kief Studio builds, protects, automates, and supports full-stack systems for businesses up to $50M ARR.

Newsletter

New writing, straight to your inbox.

Strategy, psychology, AI adoption, and the patterns that actually compound. No spam, easy to leave.

Subscribe