You’re signing a contract with your managed services provider (MSP) to manage your infrastructure, identity, endpoints, and often your most sensitive data. But here’s what most organizations don’t do: they don’t actually verify the MSP’s security posture before handing over the keys.
They ask about certifications. They review SLAs. They check references. But they rarely dig into the security controls that protect them.
If you’re evaluating a new MSP—or wondering if your current one is actually trustworthy—these three security assessments should be non-negotiable.
Assessment #1: Access control & privilege management
What you’re checking:
How does your MSP ensure their administrators (who have keys to your kingdom) aren’t creating backdoors or leaving standing access?
This is where many organizations get blindsided. An MSP tech needs admin access to do their job. But does that access expire? Is it logged? Can they explain what that access was used for?
Red flags:
- They can’t explain their privileged access management (PAM) process.
- Admin accounts are shared across multiple technicians, and there’s no audit trail for who accessed what and when.
- They aren’t taking responsibility for driving the continual improvement of the access control posture.
- Credentials are stored in shared password managers with no access controls.
What to ask:
- “How do you manage privileged access? Walk me through your PAM process”
- “Are admin accounts auditable and can access or actions be attributed to a specific technician?”
- “How long does privileged access persist after a ticket is closed?”
- “Can you show me a sample audit log of privileged activities in my environment for the last 90 days?”
Red flag if they say: “Our senior techs have permanent admin access so they can respond faster” or “We don’t track individual access—we track by support ticket.”
Assessment #2: Incident response & breach notification
What you’re checking:
If something bad happens in your environment, does your MSP have an actual plan? Or will they panic-call you at 2 AM with no strategy?
This is about readiness. A mature MSP should have a documented incident response plan specifically for their clients. They should know the difference between a phishing incident and a ransomware incident and have different playbooks for each.
Red flags:
- They don’t have a documented incident response plan
- Their plan doesn’t include you (the client) in the communication flow
- They can’t articulate their forensics capability or who handles it
- There’s no defined timeline for notifying you of a potential breach
What to ask:
- “Do you have a documented incident response plan? Can I see it?”
- “Walk me through what happens if you detect ransomware in my environment”
- “How quickly would I be notified of a potential breach?”
- “Who handles forensics, and what’s your process?”
- “What’s your relationship with incident response firms if escalation is needed?”
Red flag if they say: “We’ll handle it and let you know once we’ve fixed it” or “Incident response depends on the situation—we don’t have a formal plan.”
Assessment #3: Data security & encryption standards
What you’re checking:
How does your MSP handle your data at rest and in transit? Are they using encryption standards that won’t be obsolete in 3 years? Do they actually understand what they’re encrypting?
This matters whether they’re managing your file servers, Azure infrastructure, or backup systems. If data isn’t encrypted with current standards, it’s vulnerable.
Red flags:
- They use outdated encryption (MD5, SHA1, DES, or they can’t name what they use)
- Backups aren’t encrypted
- Data in transit isn’t encrypted (FTP instead of SFTP, unencrypted RDP, etc.)
- They store customer credentials or sensitive data in plaintext logs
What to ask:
- “What encryption standards do you use for data at rest? In transit?”
- “Are all backups encrypted? Who holds the encryption keys?”
- “Show me how you handle sensitive data in logs and communication”
- “If you manage my Azure infrastructure, how are storage accounts encrypted?”
Red flag if they say: “Encryption slows things down, so we only encrypt sensitive data” or “We use whatever Windows defaults to.”
Why this matters in 2026
At Sikich, we approach these assessments as table stakes, not optional extras. When we onboard a client, we document our access controls with full audit logging and maintain active incident response playbooks tailored to their specific environment. We are transparent with our partners and we believe transparency builds trust—and because hiding these details is what untrustworthy MSPs do.
The organizations we work with aren’t asking “do you have security?” anymore. They’re asking “prove it, and explain your reasoning.” That’s the standard that should apply to any MSP in 2026.
The hard truth
If an MSP won’t answer these security assessment questions clearly, or gets defensive about them, that’s your answer. They’re either not mature enough to articulate their practices, or they don’t have practices at all.
A trustworthy MSP will welcome these questions. They’ll produce documentation. They’ll explain their reasoning. They’ll tell you where they don’t do something and why that’s acceptable for your risk profile.
That’s the MSP you can trust.
Have any questions about MSP security?
What questions have you asked that revealed the most about an MSP’s actual security maturity? If your MSP doesn’t answer these security assessments satisfactorily, please reach out to our experts at any time.
This publication contains general information only and Sikich is not, by means of this publication, rendering accounting, business, financial, investment, legal, tax, or any other professional advice or services. This publication is not a substitute for such professional advice or services, nor should you use it as a basis for any decision, action or omission that may affect you or your business. Before making any decision, taking any action or omitting an action that may affect you or your business, you should consult a qualified professional advisor. In addition, this publication may contain certain content generated by an artificial intelligence (AI) language model. You acknowledge that Sikich shall not be responsible for any loss sustained by you or any person who relies on this publication.