An MSP, or managed service provider, wears many different hats for businesses. As an outsourced, third-party IT department, the main purpose of an MSP is to manage, monitor, and ensure a company’s technology infrastructure remains secure. They monitor servers and networks, push out system updates, and provide cloud setup and support. Additionally, an MSP also provides technical assistance to employees — assisting with anything from installing software to resetting passwords to troubleshooting various computer issues.
MSPs can be a great investment for companies that don’t want to manage any IT issues on their own, or perhaps they are finding that their current in-house department isn’t set up for a company’s growth. Whether you currently have an MSP or are thinking of partnering with one, it’s important to know that they don’t serve the same role as a cybersecurity vendor.

Cybersecurity vendors focus exclusively on threat monitoring. They will install antivirus software, manage firewalls, and implement endpoint detection and response (EDR) to stop malicious hackers from breaking into a company’s system. With 24/7 monitoring, cybersecurity vendors can prevent an attack from happening by reporting and addressing any suspicious behavior.
Although MSPs and cybersecurity vendors have different operational goals and functions, they need to work hand-in-hand to create the most solid technical infrastructure. With that, there are three questions every MSP should ask before partnering with a cybersecurity vendor.
What Are Your Security Operations Center Capabilities?
First, it’s important to understand if the vendor’s Security Operations Center (SOC) is in-house or outsourced. The choice is dependent on the business and its preferences. In-house teams may be a higher investment than a third party, but an in-house team may be able to provide better service. Note that if the client is in a highly regulated industry, maintaining strict control may be the best move. An in-house team can have direct control and oversight, with fewer people involved.
With this question, you’ll also want to know how many analysts will be dedicated to the company. Like with anything, the less headcount, the more overworked they may be and therefore the higher likelihood that a threat will be missed. Also ask what the analyst training and certification requirements are for their staff. Industry standards include CISSP and CompTIA, but there may be others needed for a specific industry.
How Do You Handle Incidents Outside of Business Hours?
Hackers are smart. They know that teams are monitoring their systems during the typical workweek from 9 a.m. to 5 p.m. That’s why reports show 56% of ransomware attacks happened over a weekend or holiday, and 47% of attacks at a healthcare organization occurred when staff levels were reduced. Asking how a cybersecurity vendor responds to threats outside of the typical workday is critical before implementation. You will want to confirm the vendor is set up for 24/7 security, 365 days a year, as opposed to a more passive alert logging system.
Alongside this, ask what the Service-Level Agreements (SLAs) are for threat containment. An SLA is the formal contract between an MSP and a vendor, and will define the exact level of service. Within this document, you’ll want to see when and how a vendor will get in contact with you if there is a potential threat. Be sure to demand a concrete response time — such as within 2 hours of a threat — as opposed to a vague response, like “as soon as possible.”
Ideally, during the conversation you’ll also get an understanding of what collaboration will look like during an active threat or breach. Know who will take the lead in alerting the business, how employees will be made aware of the situation, and how the MSP and vendor will work together to resolve the issue.
What Are Your Data Access Boundaries?
Finally, you’ll also want to know regulations around the cybersecurity vendor’s data access boundaries. Data access boundaries are the policy limits that set which systems, applications, and/or workflows a vendor is allowed to reach. Think of them as the parameters within which they have access to a business’s internal processes. Least privilege enforces that vendors only have access to the exact information required for their role, while global admin rights remove any restrictions.
It’s important to know about a vendor’s data access boundaries to prevent a breach from compromising a client’s networks and systems. If a breach were to occur on the vendor side, the hacker could then potentially have access to the company’s secure data. This happens when a client’s data is stored in a multi-tenant environment, meaning a breach could expose cross-client data. Because MSPs are legally responsible for client data, knowing the vendor’s level of access can help further protect a business and therefore an MSP’s own reputation.
Additionally, it’s also important to know how quickly an MSP can revoke or suspend a vendor’s access to their systems. A quick response time — anywhere from a few minutes to an hour — can make all the difference in preventing an active threat from spreading through a compromised third-party pipeline.
Final Thoughts
Finding the right cybersecurity vendor for your client may take some research, yet the more you know before implementation, the better off you and the business will be. Having a comprehensive evaluation checklist and including the questions noted above can ensure the vendor meets the client’s risk profile, regulatory standards, and technical needs.
