An MSP can hold privileged access to many customer systems, so provider selection should include security and continuity evidence—not only service features and price. The questions below turn that risk into a practical evaluation process.
Current as of 2026-08-15
CISA’s joint MSP advisory recommends that customers address provider security controls in contractual arrangements.
Decision summary
- Ask how privileged remote access is authenticated, limited, monitored, and removed.
- Define shared responsibilities and incident-notification duties in writing.
- Confirm backup administration is separated from ordinary support access.
- Require evidence and test the exit path before signing.
Questions about access and identity
- Which named identities can access our systems, and is phishing-resistant MFA enforced?
- How is access scoped by customer, role, device, and time?
- How are emergency and vendor accounts approved, logged, and reviewed?
Questions about detection and response
- Which provider and customer logs are retained, for how long, and who can retrieve them?
- What event triggers customer notification, through which channel, and within what timeframe?
- Who can isolate systems or revoke sessions during an incident?
Questions about resilience and supply chain
- Can the provider administer or delete production and backup copies through the same identity path?
- Which subcontractors and platforms inherit access to customer data or systems?
- How will credentials, documentation, logs, and configurations be returned or destroyed at exit?
Turn answers into evidence
CISA’s MSP customer risk considerations recommends requirements, service levels, vetting, and access to relevant security telemetry. Ask for current samples, attestations, and test results rather than accepting unverified labels.
Next step for your environment
Score providers against one requirements matrix and make unresolved security responsibilities explicit contract exceptions. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.
Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.
Sources and update trigger
Review trigger: Refresh when CISA or NIST updates managed-service supply-chain guidance.
continue reading
More ITECS blog articles
About ITECS Team
The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.
View full profile and articles