Skip to main content

Should Your MSP Handle All Your Cyber Security Needs?

Media Should Your MSP Handle All Your Cyber Security Needs?

 

For many small and medium-sized businesses, the Managed Service Provider already looks after almost everything IT-related.

Your MSP may manage:

  • computers
  • Microsoft 365
  • networks
  • firewalls
  • user accounts
  • backups
  • software updates
  • cloud services
  • remote support

So there is an obvious question:

Should your MSP handle all your cyber security as well?

In many cases, your MSP is actually one of the best organisations to manage a large proportion of your day-to-day cyber security.

They already understand your systems. They can deploy security controls directly. They know your users and devices. And when something goes wrong, they can often respond without waiting for another company to gain access to the environment.

But there is an important distinction:

You can outsource cyber security operations. You cannot outsource your organisation's ultimate responsibility for cyber risk.

The right question therefore isn't simply:

“Should our MSP do our cyber security?”

It's:

“Which security responsibilities should our MSP own, which remain with us, and how do we know everything is actually being done?”

Why an MSP Is Often Well Placed to Manage Cyber Security

Modern cyber security and ordinary IT management are increasingly difficult to separate.

Consider patch management.

Is that IT support or cyber security?

What about:

  • Microsoft 365 configuration
  • multi-factor authentication
  • device encryption
  • administrator permissions
  • endpoint protection
  • backups
  • firewall management
  • Conditional Access
  • email security

They're all operational IT controls.

They're also fundamental cyber security controls.

Having one capable provider responsible for both can therefore make considerable sense.

The UK's National Cyber Security Centre specifically recognises that SMEs commonly use MSPs to manage important data, IT services and cyber security. Its current guidance focuses not on avoiding MSPs, but on choosing them carefully and defining the relationship properly.

The Advantage of One Joined-Up Provider

Imagine your endpoint security platform detects ransomware activity on a laptop.

If your cyber security company and IT company are separate, the process might involve:

Security provider detects alert → contacts customer → customer contacts MSP → MSP identifies device → security provider provides instructions → MSP takes action.

With a properly equipped MSP managing both:

Alert detected → device identified → device isolated → account investigated → response begins.

Fewer handovers can mean faster action.

And during a genuine cyber incident, minutes can matter.

Your MSP Already Understands the Environment

A good MSP should already know:

  • which devices you operate
  • which employees have access
  • which Microsoft 365 tenant you use
  • where your important data resides
  • which applications are business-critical
  • how your network is structured
  • how your backups operate
  • which users have privileged access

That context is extremely valuable during a security incident.

A separate security provider starting from scratch may first need to understand the environment before it can act effectively.

But Not Every MSP Is a Cyber Security Provider

This is where businesses need to be careful.

An MSP might say:

“Cyber security included.”

What does that actually mean?

It could mean:

Microsoft Defender is switched on.

Or it could mean:

  • managed endpoint detection and response
  • identity monitoring
  • vulnerability management
  • Microsoft 365 security
  • email threat protection
  • Conditional Access
  • security monitoring
  • incident response
  • backup monitoring
  • security awareness
  • compliance support
  • regular security reviews

Those are very different propositions.

Do not evaluate security based on whether an MSP's website contains the words cyber security.

Ask what is actually delivered.

Antivirus + Firewall + Backup Is Not a Complete Cyber Security Strategy

All three remain important.

But modern attacks increasingly target identity and business processes as well as individual computers.

An attacker may never need to infect a PC.

If they steal a Microsoft 365 session, compromise an administrator account or persuade finance to send money to a fraudulent bank account, traditional antivirus may have very little to detect.

A modern security strategy should consider areas including:

  • identity and access
  • phishing-resistant authentication
  • email security
  • endpoint protection
  • vulnerability management
  • patching
  • privileged access
  • cloud security
  • backups
  • security monitoring
  • incident response
  • staff awareness
  • business continuity
  • supplier risk

Ask your MSP how these pieces fit together.

Ask Who Is Actually Monitoring the Security Tools

This is one of the most important questions.

Your MSP tells you:

“You have EDR.”

Good.

But who monitors it?

What happens if it generates a high-severity alert at 2:13am on Sunday?

Does somebody investigate?

Is the computer isolated automatically?

Does a Security Operations Centre review it?

Is action delayed until Monday morning?

When is your business contacted?

Buying a security product and operating a security service are not the same thing.

Ask:

Who monitors our alerts, during which hours, and what happens when something serious is detected?

24/7 Doesn't Always Mean What You Think

Be precise when asking about round-the-clock protection.

There is a significant difference between:

Security technology operates 24/7

and:

A qualified person actively responds to security incidents 24/7.

An EDR agent running continuously does not automatically mean somebody will investigate every critical alert at 3am.

Your MSP should explain exactly what the service provides.

Ask What Happens During a Real Incident

Imagine ransomware is detected tomorrow morning.

What happens?

Your MSP should be able to explain.

Questions should include:

Who investigates the alert?

Who can isolate affected computers?

Who disables compromised accounts?

Who determines whether data has been accessed?

Who restores systems?

Who communicates with management?

Who contacts the cyber insurer?

Who coordinates specialist forensic support if needed?

Who helps determine whether regulatory reporting may be required?

If nobody can answer those questions before an incident, the response will be considerably more difficult during one.

Create a Cyber Security Responsibility Matrix

This is probably the biggest improvement I would make to the original article.

Don't rely on:

“Our MSP takes care of security.”

Write down exactly who does what.

The NCSC specifically recommends that MSP contracts clearly define roles and responsibilities and says a matrix of responsibilities describing what the MSP does and what remains with the customer is good practice.

For example:

Security responsibilityMSPCustomerSpecialist
Windows patching  
Endpoint security  
Microsoft 365 security  
Backup monitoring  
Staff completing training  
Approving financial controls  
Security monitoring  
Penetration testing  
Incident responseIf required
Regulatory decisions Adviser if required
Business risk acceptance  

Your actual matrix will depend on your organisation and service agreement.

The important thing is that nothing is assumed.

Your MSP Is Part of Your Supply Chain Risk

There's another side to this relationship that businesses sometimes overlook.

Your MSP protects you.

But your MSP can also have privileged access to:

  • your devices
  • administrator accounts
  • Microsoft 365
  • backups
  • networks
  • security platforms
  • sensitive information

That makes the security of your MSP important too.

The NCSC specifically warns SMEs that MSPs may have access to systems and customer data and recommends scrutinising the provider's own security before appointing them.

This is not a reason to avoid MSPs.

It's a reason to conduct proper due diligence.

Questions to Ask About Your MSP's Own Security

Ask your provider questions such as:

How do you protect privileged access to our systems?

Do your technicians use MFA?

How is administrative access logged?

Do you apply least privilege?

How quickly are former employees' accounts disabled?

How do you protect your remote-management platform?

How would you notify us if your own systems were compromised?

What security certifications do you maintain?

Do subcontractors have access to our systems or information?

The NCSC's MSP guidance specifically highlights recognised certifications, least privilege, incident notification, obsolete accounts, backup arrangements and supplier risk among the issues customers should investigate.

Cyber Essentials Plus Is Worth Asking About

The NCSC recommends looking for MSPs with recognised certifications and specifically identifies Cyber Essentials Plus as an example.

Certification doesn't magically guarantee that a provider is perfect.

But it can provide evidence that fundamental security controls have been independently assessed rather than simply claimed.

Ask what certifications your MSP maintains and what those certifications actually cover.

What Should Be in the Contract?

Security promises made during a sales meeting aren't enough.

Important responsibilities should appear in the agreement.

The NCSC recommends MSP contracts clearly address matters including:

  • roles and responsibilities
  • incident reporting
  • liability
  • technical reporting
  • service levels
  • regular reviews
  • least privilege
  • obsolete accounts and infrastructure
  • termination arrangements

That last point is easily overlooked.

What happens when you leave the MSP?

Who removes their administrator accounts?

Who transfers documentation?

Who releases domain, tenant and backup access?

Who hands over security configurations?

Security needs to be considered at the end of the relationship as well as the beginning.

Your Business Still Owns the Risk

This is the central point.

Suppose your MSP recommends:

phishing-resistant MFA

and management says:

“Too inconvenient.”

The MSP cannot eliminate the risk created by that decision.

Likewise, your MSP cannot decide:

  • how much risk the board accepts
  • which employees should authorise payments
  • what data the business is allowed to collect
  • whether staff follow procedures
  • which regulatory obligations apply
  • whether management funds necessary improvements

Those remain business decisions.

The NCSC's broader Cyber Assessment Framework makes the same principle clear for third-party services: organisations still need confidence that relevant security requirements are being met even when functions are operated by external suppliers.

Outsourcing the work doesn't mean outsourcing accountability.

When Independent Cyber Security Testing Makes Sense

There is also a legitimate question:

Should the company that configured your security be the only company that ever assesses it?

Not necessarily.

Independent testing can provide another perspective.

That could include:

  • penetration testing
  • Cyber Essentials Plus assessment
  • vulnerability assessments
  • configuration reviews
  • compliance audits
  • incident-response exercises
  • backup recovery tests

This doesn't mean you distrust your MSP.

Consider an accountant.

A competent internal finance team can prepare accounts, while an independent auditor may still provide useful assurance.

Cyber security can work similarly.

Your MSP operates the controls.

An independent specialist periodically tests particular areas.

When You May Need a Specialist Cyber Security Provider

A capable MSP can potentially provide almost everything a typical SME requires.

But some organisations have more specialist requirements.

You may need additional expertise if you require:

  • sophisticated penetration testing
  • red-team exercises
  • digital forensics
  • advanced threat hunting
  • specialist SOC capabilities
  • complex regulatory assessments
  • specialist operational-technology security
  • major incident response
  • complex international compliance

The answer doesn't have to be replacing the MSP.

Often the best arrangement is:

MSP + specialist

with clearly defined responsibilities.

Multiple Providers Can Create Their Own Security Risk

Adding another security company doesn't automatically improve security.

You can accidentally create gaps.

Imagine:

MSP: “We thought the SOC handled that.”

SOC: “We only generate alerts. We thought the MSP responded.”

Customer: “We thought both of you handled it.”

Meanwhile, nobody isolated the compromised computer.

The more providers involved, the more important the responsibility matrix becomes.

During an incident, everyone should know:

  • who detects
  • who investigates
  • who isolates
  • who communicates
  • who restores
  • who escalates

A cyber incident is the worst possible time to discover that responsibilities were never agreed.

Don't Forget Your MSP's Suppliers

Your MSP may also depend on other companies.

For example:

  • cloud platforms
  • backup providers
  • security vendors
  • remote-management platforms
  • SOC providers
  • software distributors

That creates a supply chain.

The NCSC recommends organisations understand their supplier dependencies so cyber risks can be assessed and managed rather than treating suppliers as a black box.

You don't necessarily need a list of every company your MSP has ever purchased software from.

But for important services, you should understand significant dependencies and subcontracting arrangements.

Seven Questions I'd Ask Any MSP About Cyber Security

If you're evaluating your current MSP—or choosing a new one—start here:

  1. Exactly which cyber security services are included in our agreement?
  2. Who monitors security alerts and during what hours?
  3. What happens if you detect a serious incident at 3am?
  4. How do you protect your own privileged access to our systems?
  5. Which responsibilities remain with us?
  6. How are incidents, vulnerabilities and security performance reported to us?
  7. Which security certifications or independent assessments can you demonstrate?

If the answers are vague, investigate further.

Warning Signs Your MSP May Not Be Providing Enough Security

I'd be concerned if a provider:

  • cannot explain its security stack
  • describes antivirus alone as comprehensive cyber security
  • cannot explain who monitors alerts
  • doesn't use MFA for privileged access
  • cannot produce clear security reports
  • never reviews user permissions
  • never discusses vulnerabilities
  • doesn't test backups
  • has no clear incident-response process
  • cannot explain what happens outside office hours
  • refuses to clarify its own security practices
  • cannot tell you what isn't included

A good provider should be comfortable explaining both its capabilities and limitations.

So, Should Your MSP Handle All Your Cyber Security?

For many SMEs:

Most of it, potentially yes.

A capable, security-focused MSP can be extremely well placed to manage:

  • endpoint security
  • patching
  • Microsoft 365 security
  • identity controls
  • email protection
  • firewalls
  • backups
  • vulnerability management
  • security monitoring
  • device management
  • incident response

Keeping these services together can improve consistency and reduce the gaps between ordinary IT operations and cyber security.

But:

Don't hand everything over and stop paying attention.

Business leadership should still:

  • understand its major cyber risks
  • know what the MSP provides
  • know what isn't included
  • approve security policy
  • review security reporting
  • maintain business continuity arrangements
  • understand regulatory responsibilities
  • periodically validate important controls

The best relationship isn't:

“Cyber security is the MSP's problem.”

It's:

“Our MSP operates and advises on our security, while we jointly understand exactly who is responsible for what.”

How Hamilton Group Can Help

Hamilton Group combines managed IT support with practical cyber security so businesses don't have to treat everyday IT management and security as completely separate disciplines.

We can help with:

  • managed endpoint protection
  • Microsoft 365 security
  • identity and access security
  • MFA and phishing-resistant authentication
  • email security
  • firewall and network protection
  • security monitoring
  • patch and vulnerability management
  • backup and disaster recovery
  • security awareness training
  • Cyber Essentials
  • security baselines
  • incident-response planning
  • managed IT support

We also believe businesses should understand what they're paying for, what is being monitored and where responsibilities sit.

If you're unsure whether your current MSP is providing the cyber security protection your business actually needs, visit or call 0330 043 0069 to discuss your current setup.