A network security service provider proves itself or does not in the first ninety days, and a small organisation that knows what to look for can read the whole future relationship in that window, while exit is still cheap and attention is still high. The window has a natural structure: the first month produces the onboarding artefacts, the inventory, the baseline, the hardening list; the second month produces the first real report and the first review; the third month is when you run the drill, the deliberate test of response that providers pass or fail in private. Judged against that structure, vague comfort or vague unease becomes evidence either way. This guide walks the ninety days as a checklist: what must exist at each stage, the early warnings that predict decay, and the handover of your own written expectations that starts the clock properly.
Days one to thirty: the artefacts
Onboarding must produce four things you can hold: a network inventory, every device on the boundary and behind it, including the surprises, there are always surprises; a configuration baseline, the firewall rules and segmentation as found, archived; a hardening list, what they found weak, ranked, with dates; and the agreed procedures, what they act on unasked, whom they call, the change classes needing your sign-off. A provider that reaches day thirty without these four has substituted familiarity for onboarding, and the missing artefacts never appear later; they are the foundation the rest of the relationship stands on, and their absence is the earliest reliable warning.
Days thirty to sixty: the first report and review
The first monthly report is the template for every future one: it should show patching state, alerts and outcomes, changes made, and progress against the hardening list, and arrive unchased on the agreed date. Read it with the founding question, could I hand this to an insurer or auditor as evidence? The first review meeting then sets cadence: thirty minutes, the hardening list's movement, the surprises resolved or accepted in writing. Two warnings at this stage: a report that describes activity rather than state, we handled 47 alerts, without what remains open; and hardening items silently sliding, the list is dated for exactly this reason.
Days sixty to ninety: the drill, and your paper
Before the quarter closes, run the drill: a planned, announced-in-general test, an after-hours call to the emergency line, or a simulated incident agreed with their management, and watch the procedure execute. The result is information money cannot otherwise buy: response reality while it is still rehearsal. Fold the outcome into the incident procedure in your own set, the numbers proven, the contacts verified. Your paper frames the whole window: handing the provider your written access and incident documents on day one, the set the free sheet counts and Hardenvo Pro generates, tells them what they are being judged against, and providers rise or reveal themselves against written expectations far faster than against hopeful ones.
Questions people ask about network security service provider
What should a network security provider deliver in the first month?
Four artefacts: a complete network inventory including the surprises, an archived configuration baseline, a ranked and dated hardening list, and written procedures covering autonomous actions, contacts and sign-off classes. Missing artefacts at day thirty never appear later.
How do I evaluate the first monthly report?
It should state condition, not just activity: patching state, alerts with outcomes, changes, hardening progress, arriving unchased. Test: could it go to an insurer as evidence today? Activity-only reporting is the earliest decay signal.
Should I test my provider's response?
Yes, once, deliberately, inside the first quarter: an after-hours call or an agreed simulation. It converts response from a brochure claim to a measured fact, and the measured numbers belong in your own incident procedure.