I’ve read enough cybersecurity marketing to develop a reflex: the moment a pitch leans on a phrase like “state of the art protection” or “advanced threat prevention,” I stop listening for the claim and start listening for what’s missing underneath it. Buzzwords are cheap. What separates a real cybersecurity partner from a sales deck is whether they can answer plain, boring questions about monitoring, training, and what happens on the worst day, the day something actually gets through. If you’re evaluating cyber security companies in Calgary, skip the slogans and ask these instead.
Start with monitoring, because “we monitor your systems” means nothing without a follow-up question: monitored by whom, and how fast does a human find out when something looks wrong? A dashboard that nobody watches at 2am is not monitoring, it’s decoration. Ask what the actual detection-to-notification time looks like, and ask what counts as an alert worth waking someone up for versus one that sits in a log nobody reads until Monday.
Training is the part everyone claims and almost nobody measures
Every provider says they do security awareness training. Fewer can tell you how often, and almost none can tell you whether it’s working. A once-a-year video nobody watches past the first thirty seconds is not training, it’s a compliance checkbox. Ask what the actual cadence is, ask whether phishing simulations get run against real staff, and ask what happens when someone clicks the simulated bad link: is it a teaching moment, or a gotcha that makes employees quietly resent the whole program? The goal isn’t to catch people failing. It’s to build a habit of pausing before clicking, and that only comes from repetition, not a once-a-year slideshow.
Multi-factor authentication is another one worth being precise about. Be suspicious of anyone who claims a single security control is bulletproof or universally applied without exception, because that’s not how real environments work. What you want to hear instead is a plan: a provider actively helping set up strong multi-factor authentication across accounts, prioritizing the ones that matter most, with a clear sense of where gaps still exist and a plan to close them. Confidence stated as an absolute is usually a sign nobody’s actually looked closely.
Patching sounds unglamorous and it’s exactly where things go wrong
Most breaches don’t start with some elaborate zero-day attack. They start with a known vulnerability that had a patch available for months and nobody applied it. Ask how patch management actually works: is it automated, is it tested before it’s pushed, and is there a schedule you can see rather than a vague assurance that “we keep things updated”? A partner who can show you a patching cadence is worth more than one who tells you not to worry about it.
There’s a way to cut through the marketing language entirely, and it’s to ask what the provider actually gets measured against. Frameworks like CIS Controls exist precisely because they turn vague promises into a checklist an outside auditor can verify, and a provider willing to align their practices against something like that, or willing to point to independent verification such as SOC 2 Type II certification, is telling you something a slogan can’t: that a third party has actually looked at how they operate, not just how they describe it. That’s a very different conversation than trusting a claim because it sounded confident on a sales call.
Then there’s the question nobody wants to ask until it’s too late: what happens the day something gets through anyway. Every environment eventually faces an incident, and the honest partners are the ones who talk about response plans instead of pretending prevention is airtight. Ask what the incident response process actually looks like: who gets called, how fast, what the containment steps are, and what a written guarantee around resolution actually covers. A provider willing to put a real commitment in writing, something like a documented guarantee tied to actual outcomes rather than vague reassurance, has usually thought this through further than one offering only a confident smile.
None of this requires becoming a security expert yourself. It just requires refusing to accept an adjective in place of an answer. Ask what’s monitored, how training actually runs, how patches get tested, and what happens on the bad day. If a provider gets vague at any of those four questions, you’ve learned what you needed to know, and it didn’t cost you a contract to find out.