TL;DR:
- Your MSP typically has more access to your systems than any of your employees — a compromised MSP means a compromised business
- At minimum, require Cyber Essentials certification, MFA on all admin accounts, and a written incident response procedure before signing
- MSP supply chain attacks have risen sharply since 2022 — attackers target MSPs to reach multiple client businesses simultaneously through the MSP’s remote management tools
Most small businesses that use a Managed Service Provider (MSP) for IT support and management hand over significant — sometimes complete — access to their IT environment. The MSP can typically log into your systems remotely, manage your software updates, access your email system, and in many cases reset passwords for any account.
That access is exactly what makes MSPs valuable. It’s also why a compromised MSP is a disaster for every business it manages. High-profile attacks on MSPs — including the Kaseya VSA attack of 2021, which reached 1,500 downstream businesses — have demonstrated that attackers specifically target MSPs as a way to simultaneously compromise many small businesses through a single point of entry.
Choosing an MSP on price alone is a significant security risk. Here’s what to check before you sign.
What to Check Before You Commit
Cyber Essentials Certification
Cyber Essentials is the UK government’s baseline cybersecurity certification. Cyber Essentials Plus involves external verification of controls. Any MSP you consider should hold at least Cyber Essentials; Cyber Essentials Plus is a stronger indicator.
Ask to see the current certificate — it’s valid for 12 months and must be renewed. If a prospective MSP is not certified, ask why not. Some legitimate MSPs are in the process of certifying; many simply haven’t prioritised it.
The NCSC maintains a searchable register of certified organisations at ncsc.gov.uk/cyberessentials.
Multi-Factor Authentication on Admin Accounts
The most common way MSP tools are compromised is through stolen credentials for the remote monitoring and management (RMM) software the MSP uses to access client systems. If the MSP’s admin accounts for their RMM platform (ConnectWise, NinjaRMM, Kaseya, Datto, etc.) are not protected by MFA, a password breach directly exposes every client they manage.
Ask directly: “Do all of your technicians use multi-factor authentication to access client systems?” The answer should be yes, with no exceptions. Ask which MFA method — authenticator app or hardware key is acceptable; SMS-based MFA is weaker but better than nothing.
How They Protect Their Own Systems
An MSP’s internal security posture is a direct indicator of risk to you. Ask:
- Are your technician workstations managed with endpoint protection? What product?
- Do you use a privileged access workstation (PAW) — a dedicated, hardened machine used only for client access?
- Do you separate your internal network from the tooling you use to access client systems?
- How do you store client passwords? (The answer should be a dedicated password manager, not spreadsheets or personal vaults)
Incident Response Procedure
If the MSP suffers a breach and their tooling is used to access your systems, how will they notify you and how quickly? UK GDPR requires notification of personal data breaches to the ICO within 72 hours. An MSP that touches your data is in scope.
Request a copy of their incident response procedure. It should include:
- A defined time to notify affected clients (ideally within 4-8 hours of a confirmed breach)
- Contact details for the person responsible for security incidents
- A description of what logging they maintain that would allow them to determine whether your systems were accessed following their own breach
If they cannot provide documentation of their IR process, treat that as a significant red flag.
What to Put in the Contract
The MSP agreement typically runs to many pages. The security-critical clauses to check or add:
Data processing agreement (DPA): If the MSP accesses or stores any personal data about your customers or employees, a DPA is required under UK GDPR. If the MSP is based outside the UK or EEA, you need appropriate data transfer mechanisms in place.
Notification obligation: Require the MSP to notify you within a specified timeframe (24-48 hours is reasonable) if they have any reason to believe their systems or access has been compromised in a way that may have affected your environment.
Access logging: Require the MSP to maintain logs of all remote access sessions to your systems and make those logs available to you on request or in the event of an incident.
Right to audit: A clause allowing you (or an independent party) to audit the MSP’s security controls related to your data. Large MSPs may push back on this; smaller ones usually agree. The clause itself signals to the MSP that you take security seriously.
Offboarding procedure: What happens to your data, credentials, and access if you terminate the relationship? The contract should specify a timeframe for credential revocation and data return or destruction.
Questions That Reveal MSP Security Culture
Beyond checklists, a few direct questions tell you a lot about how an MSP thinks about security:
“What happens if one of your technicians clicks a phishing email?” A good answer describes their layered controls: endpoint protection, MFA on tooling, monitoring, and an incident response process. A bad answer is “we train our staff not to do that.”
“How do you manage client credentials?” Good answer: a dedicated privileged access management tool (e.g. Keeper Enterprise, CyberArk) with separate vaults per client. Mediocre answer: LastPass or 1Password teams. Bad answer: anything involving spreadsheets, email, or sharing credentials on calls.
“Have you ever had a security incident that affected a client? What happened?” This question is not a trap — MSPs with good security culture have experienced incidents and learned from them. An MSP that claims a perfect record and is reluctant to discuss past incidents is either inexperienced or not being candid.
The Access You Should Always Control Yourself
Regardless of your MSP relationship, certain access should remain directly in your hands:
- Domain registrar account: Your domain name is foundational — if it’s hijacked, email, website, and many other systems fail. Keep registrar login credentials with your own MFA, not managed by the MSP
- Email admin account: One break-glass admin account with MFA should be accessible to you directly
- Cloud accounts: AWS, Azure, or Google Cloud root accounts should have your own MFA, not just MSP-managed access
- Backups: At least one copy of your backup should be independently accessible to you, separate from MSP-managed systems
If your MSP is involved in a security incident, you need the ability to lock them out and begin recovery while the investigation proceeds. That ability requires maintaining independent access to your most critical systems.
A Practical Evaluation Process
When shortlisting MSPs:
- Send a written questionnaire covering the points above — legitimate MSPs will answer in writing
- Ask for references from clients in similar industries and similar size
- Request to see their Cyber Essentials certificate directly (not just a claim of certification)
- Ask for a sample of the activity logs they would maintain for your environment
- Review the contract clauses above with whoever signs contracts at your business — ideally with brief legal review of the DPA
Choosing an MSP is a security decision, not just a procurement decision. The right provider reduces your risk substantially. The wrong one introduces a backdoor to your entire business.