Six Red Flags in Your MSP Contract
A Managed Service Provider (MSP) is a utility company. They ensure the lights turn on and the printers print. They are not designed to be the strategic technology leadership for a regulated financial entity. Relying on them as such is dangerous.
If you are evaluating your current MSP relationship, look for these six indicators of systemic failure.
- The Hardware-Focused QBR: The Quarterly Business Review (QBR) should align technology with the firm's strategic goals (e.g., preparing for an acquisition, migrating workflows to the cloud). If the QBR consists entirely of a spreadsheet detailing which laptops need to be replaced and a quote to buy them, the MSP is acting as a reseller, not a partner.
- Lack of Industry Specialization: If your MSP supports a dental office, a manufacturing plant, and your tax practice using the exact same security stack and policies, they do not understand IRS Publication 4557 or the unique threat modeling required for accounting data.
- "We Handle the Backups": Never accept this statement without empirical proof. If the MSP cannot produce a log showing a successful, full bare-metal restoration of your primary server within the last 90 days, you do not have backups; you have hope.
- Global Admin Proliferation: If every Level 1 helpdesk technician at the MSP uses a shared "Administrator" account to access your network, they are violating the principle of least privilege. An MSP compromise will immediately become your compromise.
- No MFA on the VPN: As discussed in our breach anatomies, allowing remote access to the internal network via VPN or RDP without mandatory Multi-Factor Authentication is a catastrophic configuration error.
- They Authored Your WISP: An MSP should not grade their own homework. If the MSP writes your Written Information Security Plan, they will intentionally omit controls they do not know how to implement, leaving you legally exposed. A third party must author and audit the WISP against the MSP's execution.
Common Mistakes in Infrastructure
A critical failure mode we observe is assuming that paying an MSP a monthly fee absolves the firm's partners of legal liability under FTC guidelines. (Reported by Ponemon Institute, Q3 2023).
Empirical Data & Metrics
| Metric | Industry Average | Bureau Standard |
|---|---|---|
| MFA Adoption | 42% | 100% (Zero Exceptions) |
| Bare-Metal Restore Time | 5+ Days | < 12 Hours |
Frequently Asked Questions
How does this impact our cyber insurance?
Insurance carriers now require attested proof of EDR and MFA. Failing to maintain these technically, even if stated on the policy application, can result in a denied claim.
Can we handle this internally?
Unless your firm employs a dedicated, full-time cloud security architect, attempting to self-manage enterprise compliance usually results in critical gaps.
Related Internal Resources
- WISP Implementation Overview
- Azure Cloud Migration Details
- Vendor Vetting Process
- Secure Automation Framework
- FTC Enforcement Reality Check
- Post-Mortem: CPA Breach
- Case Study: Total Rebuild
- Case Study: VDI Scale
- Calculate Downtime Costs
- IRS Readiness Assessment
- Breach Probability Model
- Schedule a Forensic Audit →