
Summarize with AI
Open this article in your favorite AI assistant for a quick summary.
The MSPAlliance Position on the Regulation of Managed Service Providers
Recent legislative actions requiring the registration of managed service providers (MSPs) as a prerequisite for performing work on specific clientele is a significant development in our profession. Never before has there been an outright and direct regulation impacting MSPs specifically. Previous legislative and regulatory actions have been confined to indirect activities primarily aimed at the clients or consumers of managed services.
This paper will offer an industry response to such regulation and guidance for regulators and legislators on the impact of registration (and other regulatory) requirements on MSPs.
Need for Transparency & Accountability
MSPAlliance members acknowledge the government's need and legitimacy to have transparency and accountability when it comes to how MSPs operate. The need for oversight is particularly compelling when it involves public bodies such as state departments, agencies, law enforcement, utilities, and other entities.
Aside from governmental organizations, there is a legitimate need for transparency and accountability to the general public. Private entities need to know their MSPs are operating safely and within the confines of industry best practices.
Regulatory & Legislative Guidance from the MSP Community
While legislators and regulators have the right to expect transparency and accountability from MSPs, those outcomes should not increase the risk of the professional MSP community, including their clients. As such, the following recommendations are offered as guidance for regulatory and legislative actions involving MSPs.
Registration Privacy and Security
MSP registration may offer needed transparency and accountability, but such information could (and likely will) be used by bad cyber actors. For example, MSP registration requiring the listing of MSP corporate officers, directors, and owners, could, if made public, provide a targeted “hit list” for hackers. Furthermore, such hackers would also have a list of MSP executives involved in specific activities, providing valuable intelligence that could be used against the MSP and their clients.