A Borrowed Key, Not a Broken Lock: Vetting Your MSP After the '75% Breached' Year
Hiring an IT provider hands one company the keys to all your systems. Here's why MSP procurement is a vendor risk decision — plus a due-diligence questionnaire to audit your provider before you sign or renew.
When an attacker wants to hit fifty small businesses at once, they don't break into fifty offices. They break into the one company that already holds the keys to all fifty. That company is often a managed service provider.
The logic is uncomfortable but simple. Your MSP has remote access to your servers, your email, your backups, and usually your admin credentials. They have the same access to your competitor down the road and the accountancy firm across town. Compromise the MSP once, and you've compromised everyone on its books. This isn't theoretical. The Kaseya incident in 2021 saw a single vulnerability in remote monitoring software cascade through MSPs into an estimated 1,500 downstream businesses. More recently, the sector has been named repeatedly in advisories from the UK's National Cyber Security Centre and the US Cybersecurity and Infrastructure Security Agency as a favoured route for attackers who want scale.
And the numbers make it worse. Recent industry surveys have put the share of MSPs reporting a successful attack in a single year at around three in four. Whether the precise figure is 70% or 80% depends on who you ask and how they count, but the direction is clear: the people you pay to protect you are themselves being hit at an alarming rate.
So here's the reframe. Choosing an MSP is not a lock you're installing. It's a key you're handing to someone else. The question isn't whether the lock is strong — it's whether the person holding the key can be trusted to keep it safe.
Why this is a vendor risk decision, not an IT purchase
Most SME buyers evaluate an MSP the way they'd evaluate a broadband deal. What's the monthly cost? What's the response time? Is the helpdesk any good? All reasonable questions, but they miss the biggest one entirely.
When you sign with an MSP, you are concentrating risk. Before the contract, your breach exposure was spread across your own patchy defences. After it, a large chunk of that exposure sits inside one vendor's network. If they get sloppy with their own security, you inherit the consequences — and you may not find out until your files are encrypted or your customer data turns up on a leak site.
Procurement teams in larger organisations already treat this as third-party risk management. They send questionnaires, demand evidence, and reserve the right to audit. Smaller businesses rarely do, partly because they assume the MSP is the security expert and partly because they don't know what to ask. That gap is exactly what attackers rely on.
The good news is that you don't need a compliance department to close it. You need a short list of pointed questions and the confidence to walk away if the answers are vague.
The awkward questions worth asking
A credible provider will welcome these. A defensive or evasive one is telling you something. Print this out, send it before you sign, and send it again at renewal.
1. Access and privilege
- Do you enforce multi-factor authentication on every account that can touch our systems — including your own engineers' remote access tools? This is the single most important control. If the answer is anything other than a firm yes, stop here.
- How do you manage privileged accounts? Look for a privileged access management system, unique credentials per client, and no shared admin passwords floating around in a spreadsheet.
- Do your engineers use just-in-time access, or do they hold standing admin rights to our environment? Standing access means one compromised laptop opens everything, permanently. Time-limited access shrinks the window.
2. Their own security posture
- Are you certified to Cyber Essentials Plus? For a UK MSP this should be table stakes. Ask to see the certificate and check the date.
- Do you hold ISO 27001, and can we see the scope statement? Scope matters — a certificate that covers only the head office and not the service delivery platform isn't worth much.
- When was your last independent penetration test, and will you share a summary of the findings? You're not entitled to the full report, but a refusal to share even a summary suggests there's something to hide.
- How do you patch your own remote management and monitoring tools? These tools are the crown jewels for an attacker. Ask about their patching timelines and how quickly they act on vendor advisories.
3. Segregation and blast radius
- Is our environment logically separated from other clients? You do not want a flat network where a breach at one customer can move sideways into yours.
- Where are our backups stored, and are they isolated from your production management systems? If ransomware hits the MSP, immutable, segregated backups are what save you.
4. Detection and response
- How would you know if you'd been breached, and how quickly? Look for evidence of monitoring, logging, and a security operations capability rather than a shrug.
- What's your incident response plan, and how does it involve us? Ask for the notification timeline. Under UK GDPR, personal data breaches must be reported to the ICO within 72 hours — you need to know they'll tell you fast enough to meet your own obligations.
- Have you had a security incident in the last two years, and what did you change afterwards? Everyone gets probed; the honest answer is rarely 'never'. What matters is whether they learned from it.
5. Supply chain and staff
- What tools do you rely on that we're indirectly exposed to? Their software stack becomes your attack surface.
- Do you carry out background checks on staff, and how is access removed when someone leaves? Insider risk and orphaned accounts are underrated threats.
- Do you hold cyber insurance, and what does it cover if a breach originates with you? Read the small print on liability in the contract itself.
What good answers look like
You're not expecting perfection. You're looking for a provider who answers specifically rather than in marketing language, who offers evidence without being cornered into it, and who treats their own security as seriously as they claim to treat yours. A provider that says 'we require MFA everywhere, here's our Cyber Essentials Plus certificate, and here's a redacted summary of our last pen test' is in a different league from one that says 'security is a top priority for us'.
Be wary of three responses in particular: hesitation to share any certification, shared admin credentials, and no clear breach notification commitment. Any one of those is grounds for a serious conversation before renewal.
The takeaway
The '75% breached' year isn't a reason to distrust MSPs as a category. Outsourcing IT security to specialists is still, for most SMEs, far safer than trying to do it alone. But it does mean the decision deserves the same scrutiny you'd give to handing someone a key to your building — because that's precisely what you're doing.
Ask the questions. Keep the answers on file. And revisit them every renewal, because a provider's posture in 2022 tells you nothing about their posture today. A good MSP won't just tolerate this due diligence — they'll respect you for it, because they're asking exactly the same questions of their own suppliers.
If you'd like a copy of the questionnaire above as an editable checklist, or you want a second opinion on your current provider's answers, that's a conversation we're always happy to have.
