https://www.sikich.com

3 Non-negotiable security assessments before trusting your MSP in 2026

INSIGHT 5 min read

You’re signing a contract with your managed services provider (MSP) to manage your infrastructure, identity, endpoints, and often your most sensitive data. But here’s what most organizations don’t do: they don’t actually verify the MSP’s security posture before handing over the keys.

They ask about certifications. They review SLAs. They check references. But they rarely dig into the security controls that protect them.

If you’re evaluating a new MSP—or wondering if your current one is actually trustworthy—these three security assessments should be non-negotiable.

Assessment #1: Access control & privilege management

What you’re checking:

How does your MSP ensure their administrators (who have keys to your kingdom) aren’t creating backdoors or leaving standing access?

This is where many organizations get blindsided. An MSP tech needs admin access to do their job. But does that access expire? Is it logged? Can they explain what that access was used for?

Red flags:

  • They can’t explain their privileged access management (PAM) process.
  • Admin accounts are shared across multiple technicians, and there’s no audit trail for who accessed what and when.
  • They aren’t taking responsibility for driving the continual improvement of the access control posture.
  • Credentials are stored in shared password managers with no access controls.

What to ask:

  • “How do you manage privileged access? Walk me through your PAM process”
  • “Are admin accounts auditable and can access or actions be attributed to a specific technician?”
  • “How long does privileged access persist after a ticket is closed?”
  • “Can you show me a sample audit log of privileged activities in my environment for the last 90 days?”

Red flag if they say: “Our senior techs have permanent admin access so they can respond faster” or “We don’t track individual access—we track by support ticket.”

Assessment #2: Incident response & breach notification

What you’re checking:

If something bad happens in your environment, does your MSP have an actual plan? Or will they panic-call you at 2 AM with no strategy?

This is about readiness. A mature MSP should have a documented incident response plan specifically for their clients. They should know the difference between a phishing incident and a ransomware incident and have different playbooks for each.

Red flags:

  • They don’t have a documented incident response plan
  • Their plan doesn’t include you (the client) in the communication flow
  • They can’t articulate their forensics capability or who handles it
  • There’s no defined timeline for notifying you of a potential breach

What to ask:

  • “Do you have a documented incident response plan? Can I see it?”
  • “Walk me through what happens if you detect ransomware in my environment”
  • “How quickly would I be notified of a potential breach?”
  • “Who handles forensics, and what’s your process?”
  • “What’s your relationship with incident response firms if escalation is needed?”

Red flag if they say: “We’ll handle it and let you know once we’ve fixed it” or “Incident response depends on the situation—we don’t have a formal plan.”

Assessment #3: Data security & encryption standards

What you’re checking:

How does your MSP handle your data at rest and in transit? Are they using encryption standards that won’t be obsolete in 3 years? Do they actually understand what they’re encrypting?

This matters whether they’re managing your file servers, Azure infrastructure, or backup systems. If data isn’t encrypted with current standards, it’s vulnerable.

Red flags:

  • They use outdated encryption (MD5, SHA1, DES, or they can’t name what they use)
  • Backups aren’t encrypted
  • Data in transit isn’t encrypted (FTP instead of SFTP, unencrypted RDP, etc.)
  • They store customer credentials or sensitive data in plaintext logs

What to ask:

  • “What encryption standards do you use for data at rest? In transit?”
  • “Are all backups encrypted? Who holds the encryption keys?”
  • “Show me how you handle sensitive data in logs and communication”
  • “If you manage my Azure infrastructure, how are storage accounts encrypted?”

Red flag if they say: “Encryption slows things down, so we only encrypt sensitive data” or “We use whatever Windows defaults to.”

Why this matters in 2026

At Sikich, we approach these assessments as table stakes, not optional extras. When we onboard a client, we document our access controls with full audit logging and maintain active incident response playbooks tailored to their specific environment. We are transparent with our partners and we believe transparency builds trust—and because hiding these details is what untrustworthy MSPs do.

The organizations we work with aren’t asking “do you have security?” anymore. They’re asking “prove it, and explain your reasoning.” That’s the standard that should apply to any MSP in 2026.

The hard truth

If an MSP won’t answer these security assessment questions clearly, or gets defensive about them, that’s your answer. They’re either not mature enough to articulate their practices, or they don’t have practices at all.

A trustworthy MSP will welcome these questions. They’ll produce documentation. They’ll explain their reasoning. They’ll tell you where they don’t do something and why that’s acceptable for your risk profile.

That’s the MSP you can trust.

Have any questions about MSP security?

Author

Jayson Roesel is a Managing Consultant at Sikich with more than 20 years of experience in the IT industry. His deep background across all facets of managed service provider (MSP) environments enables him to design and deliver scalable, security‑focused, and future‑ready solutions. Jayson’s broad technical expertise, combined with his consultative approach, allows him to guide organizations through complex technology challenges and build strategic roadmaps that support long‑term growth and resilience.