Almost every managed IT contract includes a line about watching your systems. Security monitoring for small business is sold as a single thing, and most owners assume it means somebody would notice if an attacker got in.
A large study published this year suggests that assumption is worth checking, because being recorded and being noticed turn out to be two very different outcomes.
What we monitor your systems usually means
When your provider says they monitor your systems, three separate jobs are hiding inside that one sentence.
The first is stopping things at the door, which is what your email filter, your antivirus and your firewall do. The second is keeping a record of what happened, so that somebody could go back and reconstruct it later. The third is telling a human being, in something close to real time, that something is wrong right now.
Almost every contract covers the first two. The third is the one that decides whether you find out on Tuesday morning or three weeks later, and it is the one nobody ever asks about.
The gap between something being recorded and somebody being told
A company called Picus Security ran 338 million simulated attacks inside real customer networks during the first half of 2026 and published what the defenses did.
The protections blocked about 69% of the attacks outright, which is a genuine improvement on the year before. Of the attacks that did get through, a little over half left a record behind, at 58%.
Then the number falls off a cliff. Only 14% produced an alert that would actually reach a person. The report calls the widening gap between what gets recorded and what gets flagged the single most persistent weakness in the defenses it measured, and that number has not moved in a year.
Put plainly, fewer than one attack in seven set off anything that a human being would see.
Why the recording on its own is worth so little
There is a comforting version of this that goes: at least it was all captured, so we can work out what happened afterwards.
That is true, and it matters for your insurer and for any customer who asks. It does nothing at all for you during the days the attacker is still inside.
The reason the gap exists is unglamorous. Recording activity is close to automatic once the software is installed. Turning that record into an alert takes somebody deciding which patterns are worth interrupting a human for, writing that rule down, testing that it actually fires, and then trimming it so it does not cry wolf forty times a day. That work never finishes, because your systems change and so do the attacks.
Nobody buys that work explicitly. It sits inside a monthly fee, and it either gets done or it quietly does not.
It helps to picture what those three weeks look like from inside a company of 40 people, because they are not dramatic. Nothing crashes. One or two people mention that the shared drive feels slow, and somebody else notices a folder they do not recognize and assumes a colleague made it. The work goes on. The recording is faithfully capturing all of it, and it will make excellent reading in a month, once somebody has a reason to go and look. What is missing in those three weeks is the one message that would have sent a person to look on day one.
What happens once somebody is already inside
The same study measured something else worth knowing. Once an attacker had valid access and was moving around inside the network, the defenses stopped only 37% of what they attempted, against 69% at the entrance.
The reason is simple enough. Someone signed in with a working username and password looks like an employee. They open files an employee would open, at hours an employee would work. There is very little for a filter to catch, which is exactly why the alert matters more at this stage than at any other.
What this means for a business with no security team
Read the numbers honestly and they are not directly your numbers.
The companies in that study run security programs of their own. They have staff whose job is to write and maintain those alerting rules. They are considerably larger than a firm of 40 people, and they still only managed to alert on 14% of what reached them.
So the useful conclusion for a smaller business is not that the situation is hopeless. It is that this particular job is hard even for people who do it full time, and that nobody should assume it is happening quietly in the background for a flat monthly fee.
The way to find out is to ask, in language that does not let a vague answer pass.
Questions to ask your IT provider
Five questions. None of them requires you to understand anything technical, and all of them are hard to answer with reassurance alone.
- When something suspicious happens on our systems at 2 in the morning, who receives that, and on what device? You are listening for a person and a channel. A dashboard nobody opens is not an answer.
- How many alerts did we generate last month, and what happened to each one? A very low number and a very high number are both worth a follow-up question.
- Which specific things would set off an alert for us? Ask for three concrete examples, such as a login from another country, a large number of files being copied, or an account being created outside your normal process.
- When did you last test that those alerts actually fire? This is the one that separates a monitoring service from a logging service. If the answer is that it has never been tested, that is your finding.
- If somebody signs in with a valid password that they stole from us, what would tell you? This is where most small business monitoring is thinnest, and it is the scenario the study says is most likely.
If you would rather have someone go through those five answers with you, that is a conversation we have most weeks.
If the answers come back vague
Plenty of providers will answer those five questions honestly and tell you that alerting is thin. That is a better outcome than a confident answer with nothing behind it, and it does not have to turn into a large project.
Ask for one alert rather than a program. Pick a single event that would never be normal in your company, agree who receives the message and on which phone, and have them prove it works by triggering it once in front of you. A sign-in from a country where you have no staff is usually the easiest one to start with, and it costs almost nothing to set up on the systems most small companies already run.
One alert that reaches a person beats a monitoring package nobody has ever tested.

