Insights

MSPs Keep You Operational. They Don't Watch for Breaches.

Dave Goldberg Dave Goldberg · 6 min read
MSPs keep you operational

Managed IT and managed security are different functions

Not knowing the difference could cost you.

Too often, if you ask a small business owner who handles their cybersecurity they will answer “our IT provider does”. It might feel true to them. The provider installed the antivirus, maybe provides some automated backups, even configured the firewall. To them that sounds very “security-like”.

But what's covered in their services agreement tells a far different story.

  • Uptime
  • Support SLAs
  • Device maintenance
  • Software licensing
  • Email configuration

But where are the cybersecurity measures? Patching? Alerting? Access?

Managed service providers are operations companies. They are built, staffed and paid to keep things running, and most of them do that well. Keeping things running and defending you from an adversary are different disciplines with different economics. Unless the contract says otherwise in specific terms, you have contracted with the first and assumed the second.

Why the gap exists

It is nobody's bad faith. It's their business model. An MSP earns a fixed fee per user or device, which rewards efficiency and quiet months. Security work is the opposite of efficient. It is investigation, tuning, restore testing and awkward conversations about risk, most of it invisible when it succeeds. So it gets done to the level the contract specifies. Contracts written around uptime specify little to none of it.

There is a second, more important reason to care. Your MSP holds administrative access to all your services. They are a bigger target than any single customer. The 2026 Verizon DBIR found third parties involved in 55% of small business breaches, nearly double the rate of larger organizations. The relationship you rely on for protection is statistically the most common way in.

Some MSPs do offer cybersecurity as a separate service, managed detection and response, virtual CISO hours, a security operations center for monitoring. That is a real option and potentially an easy button if they are already managing your environment. But it's an addition to the base contract, not something baked in by default. If you have not explicitly bought it, you likely do not have it.

None of this argues against using an MSP. Most small businesses should. It argues for knowing exactly what you have bought, and the fastest way to find out is to ask.

Here are six questions to ask your MSP to help understand what they actually cover.

1. What does our agreement cover for security, and what is explicitly out of scope?

This answer belongs in writing.

A good answer is a specific list on both sides of the line. “We manage antivirus, patching and firewall rules. We do not provide monitoring, perform incident response or implement user training.”

A bad answer looks like vague reassurance. “Don't worry. We take care of it”.

Reassurance is not the same as a specific and scoped list. When something falls through a gap neither of you agreed on the problem is yours.

2. Who patches what, and how quickly?

Patching sounds covered because workstations update automatically. But that's just a piece of what protects you. What about the firewalls, VPN appliances, routers, firmware and third-party applications? Ask for the boundary of what they patch and what they don't. Ask to see last month's patching report for everything internet-facing.

A good answer produces the report.

A bad answer explains why the report would be difficult.

That's a red flag that the work is not being tracked and probably not reliably being done.

3. Is multi-factor authentication on everything that faces the internet, including your access to our systems?

The second half of the question matters most. Your MSP's remote access tools are a door into your business. Attackers who compromise a provider walk through it into every client at once. Additionally, having MFA should also eliminate shared credentials by the MSP to access your environment.

A good answer confirms MFA on your email and remote access and on the MSP's own tools, with unique credentials per technician.

A bad answer covers your users and goes quiet about theirs.

4. Are you performing backups and for which systems? When did someone last test our backups?

Backup jobs succeeding is not the same as recovery working. Ransomware crews delete or encrypt backups they can reach. Restores that are never tested have a habit of failing or taking weeks while you're not operational.

A good answer includes which systems, dates, a duration and a copy that sits offline or otherwise beyond an attacker.

A bad answer is the green dashboard showing a backup happened. The dashboard measures the job, not the outcome.

5. If we were breached, what would you see, and what happens next?

This question separates managed IT from managed security quickly. Who (or what) is watching alerts, during which hours, and what does your contract oblige the MSP to do about it? Is incident response included? Do you know their response time? Is it overtime work billed by the hour?

A good answer is specific about detection coverage and committed response.

A bad answer is “You'll be the first to know if something happens.”

6. If you were compromised, how and when would we find out?

This is the one they might feel uncomfortable to answer but it could be the most revealing. A provider that takes its own security seriously will have an answer for you.

A good answer includes detail on the MSP's controls, their testing, and their commitment to notify clients of their own security incidents.

A bad answer is an MSP that dances around the question. They are broadcasting where your security sits in their priorities.

You are not being pushy by asking. You are doing exactly what larger firms do to their suppliers and for exactly the same reason.

Role clarity, then priorities

The point of these questions is not to catch your provider out. It is to establish role clarity. The MSP runs operations. But you own the risk. The downtime, the customer calls, and the losses land on you.

Once the roles are clear the work begins to fill the gaps. Of everything you discover that's out-of-scope what should you pay to add, and in what order?

Ask the six questions first. If the answers leave you with a list and no way to rank it, we should talk.

See your cyber risk in financial terms

Book a Demo