Skip to main content

Choosing a managed service provider (MSP)

An SME’s guide to selecting and working with managed service providers.

NatalyaBurova via Getty Images

Many small to medium-sized enterprises (SMEs) use managed service providers (MSPs) to deliver IT products and services, manage important data, and to provide cyber security. This guidance describes how to select and work effectively with MSPs, and includes a checklist you can use when sourcing MSPs.

Note:

If you’re part of an IT team responsible for working with MSPs within larger organisations (over 250 people), you should refer to the NCSC’s more detailed Cloud Security Guidance.






Services to request

  • Timely patch management for all systems and software

  • Automated, off-site data backups and regular testing of restore processes

  • Security monitoring and logging, with alerts for suspicious activity

  • Use of 2SV across all access points

  • Clear incident response and management procedures

  • Application of timely security updates and firmware patches

Contract and agreement considerations

  • Is there a detailed Service Level Agreement (SLA)?

  • Are roles, responsibilities, and liabilities clearly defined?

  • Does the contract specify how and when security incidents are notified?

  • Are there provisions for regular reviews and reporting?

  • Is the principle of least privilege applied to MSP access?

  • Are there clauses for managing obsolete accounts and infrastructure?

  • Is there a clear process for contract review, renewal, or termination?

Risk and responsibility

  • Have you assessed your MSP’s supply chain risks?

  • Are accountability and liability for cyber security incidents explicitly documented?

  • Do MSPs have a tested incident response and recovery plan?

  • Are backup and disaster recovery procedures outlined and agreed upon?

  • Is there a process for regular security training and awareness?

Published

Reviewed

Version

1.0