MSP Security Due Diligence: Nine Questions Texas Businesses Should Ask

Evaluate an MSP’s remote access, identity, logging, backup separation, incident duties, subcontractors, evidence, and exit plan without relying on an unsupported breach statistic.

Back to Blog
(Updated )
2 min read
Isometric chain of network nodes representing a managed IT supply chain with one central link fractured and glowing as a single point of compromise

An MSP can hold privileged access to many customer systems, so provider selection should include security and continuity evidence—not only service features and price. The questions below turn that risk into a practical evaluation process.

Current as of 2026-08-15

CISA’s joint MSP advisory recommends that customers address provider security controls in contractual arrangements.

Decision summary

  • Ask how privileged remote access is authenticated, limited, monitored, and removed.
  • Define shared responsibilities and incident-notification duties in writing.
  • Confirm backup administration is separated from ordinary support access.
  • Require evidence and test the exit path before signing.

Questions about access and identity

  • Which named identities can access our systems, and is phishing-resistant MFA enforced?
  • How is access scoped by customer, role, device, and time?
  • How are emergency and vendor accounts approved, logged, and reviewed?

Questions about detection and response

  • Which provider and customer logs are retained, for how long, and who can retrieve them?
  • What event triggers customer notification, through which channel, and within what timeframe?
  • Who can isolate systems or revoke sessions during an incident?

Questions about resilience and supply chain

  • Can the provider administer or delete production and backup copies through the same identity path?
  • Which subcontractors and platforms inherit access to customer data or systems?
  • How will credentials, documentation, logs, and configurations be returned or destroyed at exit?

Turn answers into evidence

CISA’s MSP customer risk considerations recommends requirements, service levels, vetting, and access to relevant security telemetry. Ask for current samples, attestations, and test results rather than accepting unverified labels.

Next step for your environment

Score providers against one requirements matrix and make unresolved security responsibilities explicit contract exceptions. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.

Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.

Sources and update trigger

Review trigger: Refresh when CISA or NIST updates managed-service supply-chain guidance.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles