By Charles Weaver
Highlights
- What end-user concerns need to be addressed with regards to MSP security
- Lessons learned from the past several years
- Standardized security best practices all MSPs should apply
The evolution of managed service provider (MSP) security practices has a long history going back to the mid-1990s. The threats were different back then, as were the technologies used and the customer expectations. Today, in this era of expanding cybersecurity threats, the modern MSP must adopt a vastly different internal security posture. MSPs have long understood the value of delivering managed security solutions to customers, but the time has come to set those same security expectations inward.
End-user Concerns with the Modern Day MSP
To begin, let us be clear about the legitimate concerns consumers of managed services have. The democratization of cyberattacks means that organizations have a legitimate belief that they will be attacked, regardless of whether they have anything of value to be stolen. This critical distinction is what defines this new age of cybercrime and cybersecurity from previous eras when organizations would deploy IT security resources in accordance with their perceived risk.
The balancing of resources with the nature of the data and infrastructure being protected must still take place. Nobody expects a small business to pay enterprise prices to protect their data. However, with the proliferation of data breach notification laws and data privacy regulations, all organizations, regardless of size, must take certain baseline precautions. The same is true of MSPs.
Clients expect their MSPs to be secure. How can the MSP protect the client if the MSP itself is not also secure? These security expectations often manifest themselves in the form of transparency and information requests. The end-user customer may already believe in the benefits of the MSP relationship. What the client also needs is reassurance about the nature of the MSP’s internal security and data privacy controls, so that no additional or unreasonable risk transfers to the client organization.
For the vast majority of MSPs, this information request from clients is not about radically changing how they have run their MSP organization. Instead, it is about effectively communicating to the customer what steps the MSP is already taking to protect the delivery pipeline.

