Summarize with AI
Open this article in your favorite AI assistant for a quick summary.
by Charles Weaver
When I saw the article (I am not linking it here, you can search for it online) about an MSP (Managed Solution Provider) being sued by their law firm client, I thought this would be a messy can of worms. Turns out, I was right. But it is not a messy can of worms because I think an MSP did something wrong and it will harm the profession. No, this is a messy can of worms because this is a break/fix company who is getting sued and at least some people think they are an MSP. Well, I do not, and I am going to tell you why.
The first thing I did after I read this story was go to the company's website to find out if this was a company I knew. Turns out, it was not.
The next thing I did was to dig deeper into the type of company this was. After a few minutes of poking around the website, it occurred to me that this was not an MSP at all, but a break/fix, or reactive IT (Information Technology) company.
Now, why is this distinction important? Ralph Waldo Emerson once said, "a foolish consistency is the hobgoblin of little minds, adored by little statesmen, and philosophers and divines." Put differently, the time has come to realize that a break/fix company calling itself an MSP does not mean that company is an MSP. The time has also come to stop calling break/fix providers MSPs. So, let us dig further and examine what we know.
Was there a managed services agreement?
According to the article, there was an oral agreement between the parties. Aside from the legal question of whether an actual agreement was in place, we can say that this practice falls well outside the managed services profession's best practice of requiring signed agreements between MSP and managed services client. Look at Objective 9 of the UCS (Unified Certification Standard for Cloud & Managed Service Providers) and you can clearly see the requirement for signed agreements between MSP and client.
Duty of the break/fix company
According to the article, on February 24, 2023, there were "connectivity issues" experienced by the client. Three days later there was a "major outage" which is the focus of the lawsuit. The outage was followed by a ransomware demand, and despite the client having backups of its data, the data backups were deleted by the ransomware gang.