How to Vet Your MSP's Security Claims
- 5 days ago
- 7 min read

By Yonatan Hoorizadeh — CISSP, CISM, CRISC, AAISM
Published By: Purple Shield Security
Published: July 8, 2026
Last updated: July 8, 2026
To vet an MSP's security claims, ask five things before you sign: who owns security decisions in writing, who the named security person is and their credentials, how many tools they run and who reads the alerts, how they handled their last incident, and whether an independent vCISO reviews their work. Vague answers are the red flag.
"We have an MSP, so we're covered." We hear some version of this in almost every first conversation. And most of the time, the person saying it can't tell me what their managed service provider (MSP) actually does for security. They are paying for IT support and assuming security comes bundled in. Usually it doesn't.
Here is the part nobody tells small business owners: managing your systems and securing them are two different jobs. Plenty of good MSPs are great at the first and quietly weak on the second. The gap between those two is where breaches live. You don't need to become a security expert to protect yourself. You just need better questions before you sign, and you need to know what a weak answer sounds like.
Does having an MSP mean your business is secure?
No. Having an MSP means someone is managing your IT. Security is a separate discipline, and many MSPs deliver it as a light add-on rather than a core service. Managing systems means keeping email flowing and laptops patched. Securing them means threat detection, incident response, access governance, and log monitoring. One does not automatically include the other.
This distinction matters because the assumption itself is the risk. A business that believes it is covered stops asking questions, skips the outside review, and finds out where the gaps were only after an incident forces the conversation. The fix is not to distrust your provider. It is to make them show you what you are actually paying for.
Who actually owns security decisions, you or your MSP?
Ask this first, and get the answer in writing inside the contract, not in a sales deck. You want a clear line: these security responsibilities sit with the MSP, and these sit with you. This is the shared responsibility model, and when it is left vague, the practical result is that nobody owns security and it quietly goes undone.
If the provider can't draw that line cleanly, that is your first red flag. "We handle all of that" with no specifics usually means no one has mapped who is responsible for what. When an incident hits, that ambiguity becomes a finger-pointing exercise while your data is still exposed.
Who is the real person handling your security?
Ask for a name, then ask about that person's credentials and experience. In a lot of smaller shops, the "security guy" is also the network guy and the help desk guy. If one person is your system administrator, network administrator, and security administrator all at once, that is a problem. Those are three different jobs, and security ends up getting whatever time is left at the end of the day, which is usually none.
Push on whether they have anyone dedicated to security or whether it is a side duty for someone already stretched thin. Then ask what high-level certifications their security staff actually hold. Credentials like the CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), and CRISC (Certified in Risk and Information Systems Control) take years and signal real depth. A vendor badge for one product the MSP resells is not the same as knowing how to secure an environment.
Team size matters too. Ask how many people are on the team and how many of them touch security. A three-person shop covering fifty clients is spread thin no matter how talented they are, and honest math here tells you a lot about how much attention your environment will actually get.
How many tools are they running, and who reads the alerts?
Ask how many security tools they run on you, then ask who reads the output of each one. This surprises people, because the instinct is that more tools equals more safety. It doesn't. A pile of tools nobody is tuning, watching, or responding to is just noise and license cost. A single tool that is actually monitored beats ten that sit there blinking.
I have walked into environments with a dozen security products installed and not one person reading the alerts any of them generated. That is the trap: the dashboard looks impressive, the invoice is real, and the protection is theoretical. The follow-up question that cuts through it is simple. When one of these tools fires an alert at 2am, who sees it, and what happens next?
Coverage hours belong in the same conversation. Ask whether monitoring is 24/7 or just business hours. Attackers know when your MSP goes home. Ransomware crews deliberately hit on Friday nights and holiday weekends because they know nobody is watching until Monday. If your provider clocks out at 6pm, that stretch is your exposure window, and it is a wide one.
Can they walk you through a real incident?
Ask the provider to walk you through their last security incident: how they caught it, how fast, and what they did about it. A real answer sounds specific, with dates, steps, decisions, and what they would do differently. A vague "oh, we handle those as they come up" means one of two things. Either they have never actually been tested, or they have been and they don't want to tell you how it went.
Two more questions in this bucket feel like paperwork but aren't. First, what happens to your data if you leave? If they can't answer cleanly, they have never thought about it, and how they treat your data on the way out reflects how they treat it the whole time they have it. Second, do they carry cyber liability insurance, and can you see proof? An uninsured provider is betting nothing ever goes wrong, and when something does, you inherit that bet. A serious provider hands over the certificate without blinking.
Does anyone independent check the MSP's security work?
This is the question that separates a real security posture from a comfortable story: does the MSP work with an outside vCISO (virtual Chief Information Security Officer) or fractional CISO to review its security work? The reason it matters is structural. The judge cannot also be the defense attorney. The cook cannot also be the health inspector. An MSP auditing its own security is grading its own homework, and the grade always comes back an A.
That is not because MSPs are dishonest. It is because nobody can see their own blind spots. The entire value of independent review is that a second set of eyes, with no stake in defending the existing setup, finds the gaps the people who built it can't. This is the role a vCISO or fractional CISO plays: an experienced security leader who reviews the work, checks it against a real framework, and answers to you rather than to the provider.
When an MSP already has an independent security advisor reviewing its work, that tells you they take the job seriously enough to invite scrutiny. When they get defensive at the very idea, that tells you something too. At Purple Shield Security we are often that outside set of eyes, and the honest truth is that the MSPs worth keeping tend to welcome the review rather than resist it.
What are the red flags to watch for?
Watch how the provider responds as much as what they say. The answers matter, but the body language of the answers often tells you more. These are the signals that should make you slow down before you renew:
Dodging specifics and falling back on "trust us, we handle it."
Reselling one security product as if it were a complete strategy.
No named person responsible for your security.
Business-hours-only monitoring dressed up as full coverage.
No independent review of their own security work.
Getting defensive or annoyed that you asked at all.
That last one is the tell. The good providers welcome these questions, because a client who cares makes their work visible and their job easier. The ones who bristle are usually protecting something.
Frequently asked questions
Does my MSP have to handle security, or is that a separate service?
It is usually separate, even when it is bundled into one invoice. Standard managed IT covers uptime, patching, and help desk support. Security monitoring, incident response, and governance are often either an add-on tier or not included at all. Ask your MSP to show you in writing exactly which security functions your contract covers.
Can an MSP audit its own security work?
It can, but you should not rely on it as your only check. An MSP reviewing its own security has every incentive to grade itself favorably and no way to see its own blind spots. Independent review by an outside vCISO or fractional CISO exists precisely to catch what the team doing the work cannot.
What certifications should my MSP's security staff have?
Look for senior, vendor-neutral credentials such as CISSP, CISM, or CRISC held by the person actually responsible for your security. These signal years of security-specific experience. A certification to install or resell one product is not the same thing, so ask who holds what, not just whether the firm "has certified staff."
Is 24/7 monitoring really necessary for a small business?
For most businesses handling customer or regulated data, yes. Ransomware operators deliberately strike nights, weekends, and holidays because that is when business-hours-only providers are offline. If your MSP does not monitor around the clock, that gap is a predictable window attackers already know how to use.
How do I know if my MSP is actually protecting me?
Run the five questions in this article: who owns security in writing, who the named security person is and their credentials, how many tools they run and who reads the alerts, how they handled their last incident, and whether an independent advisor reviews their work. If you can't answer those about your own provider, that gap is worth closing before an incident closes it for you.
Where this leaves you
Your MSP might be excellent. A lot of them are. But "we have an MSP" is a hope, not a security posture, and hope is a bad thing to discover you were relying on after an incident. Run the list and make them show you. If the answers come back solid, now you know instead of assume.
And if you go through this and realize you can't answer half of these questions about your own provider, that is worth fixing before something forces the conversation for you. You may not need to switch providers. You need to know what you are paying for. If you want an independent set of eyes on whether your MSP's security holds up, that is a conversation worth having with Purple Shield Security.



