How to Evaluate an MSP’s Cybersecurity Stack Before You Sign

To evaluate an MSP’s cybersecurity stack, check every layer against 4 states. Licensed, deployed, monitored, and acted on. A proposal only ever proves the first one. Everything after that is a claim, and the distance between state 1 and state 4 is where the expensive incidents live.

Security line items tell you what got licensed. They tell you nothing about who reads the alert at 3 a.m., or who’s allowed to isolate a machine without calling you first. This walks the stack layer by layer, shows what “Microsoft Defender” actually means across 4 separate products, and lists the 9 artifacts to ask a provider for instead of the questions everybody already knows how to answer.

I read a lot of these proposals. The security section is usually the shortest one. It’s also the least understood, which is an unfortunate pairing, because that same short section is what decides whether a bad Tuesday turns into a bad quarter that shows up in your year-end numbers.

A typical security block reads like this. Managed antivirus. Email filtering. Backup. MFA. Security awareness training. Five lines, one price. Every provider on your shortlist has roughly the same five lines, which is exactly why the security section never breaks a tie and why buyers end up deciding on something else entirely. Our cybersecurity services page covers what those layers do. This is about auditing somebody else’s.

The real difference isn’t the tool names. It’s whether anybody is on the other end of the tool. Every product installed, licensed, and glowing green in the console still leaves you exposed if the alert that mattered fired late on a Friday night into a shared mailbox that nobody opened again until Monday morning.

Printed MSP proposal on a desk with a red pen circling a security line item

What is an MSP cybersecurity stack?

An MSP cybersecurity stack is the set of security products a provider licenses, configures and operates on your behalf, usually covering endpoints, identity, email, backup, patching and the network edge. It’s normally sold inside the monthly per-seat fee, or as a security tier layered on top of base support.

Six layers is the common shape. Some providers sell 4 and call it complete. Others sell 11 and call it a platform.

Neither number tells you much. The second question is the one that does, and almost nobody asks it. Who operates it?

A stack isn’t a shopping list. It’s a set of running processes, and every one of them has an owner, a schedule, and something specific that happens when it fires at an hour when nobody is at their desk. Ask about the running process.

Why does a stack that looks complete on paper still miss things?

Because a proposal can only prove one of 4 states. They aren’t equivalent. Every layer of every security stack sits in exactly one of them.

  • Licensed. Somebody bought a seat count. That’s a line on an invoice and nothing more.
  • Deployed. The agent is actually on the machines. On which machines, and how does anyone know it’s all of them?
  • Monitored. A human or an automated system reads what the agent produces, on a schedule you can name out loud.
  • Acted on. Somebody has standing authority to isolate a host, kill a session or revoke a token at 3 a.m. without phoning you first.

A proposal proves state 1. That’s the whole list.

These aren’t a ladder that gets climbed evenly, either. Plenty of stacks are beautifully licensed, fully deployed, monitored on paper, and completely dead at state 4, because the runbook says notify the client and nobody at the client answers their phone at 3 a.m. either. State 4 is the money. It’s also the most expensive state for a provider to staff properly, which is exactly why it’s the one that quietly goes missing from the scope without anybody mentioning it.

LayerLicensed looks likeMonitored looks likeActed on looks like
EndpointAn EDR product named on the quoteA named alert queue somebody works, on a published shift scheduleStanding authority to isolate a host without a phone call first
IdentityMFA listed as includedSign-in risk and impossible-travel alerts reviewed dailyA session revoked and a password reset before you’re even told
EmailA filtering product namedQuarantine and release requests handled inside a stated SLAA malicious sender blocked tenant-wide within the hour
BackupA backup product and a retention numberJob failure reports read every morning by a named roleA failed job re-run and escalated the same business day
PatchingPatch management as a bullet pointA monthly compliance percentage per device groupOut-of-band emergency patching when a CVE hits the KEV catalog
Network edgeFirewall management listedFirmware versions tracked against vendor advisoriesFirmware applied on an emergency window, not next quarter

Take the proposal in front of you. Try to fill in columns 3 and 4 from memory. You can’t. That’s the exercise.

Which layers have to be there at all?

There’s an actual answer here, and it isn’t a vendor’s opinion. The Center for Internet Security publishes Implementation Group 1, a foundational set of 56 safeguards written for exactly the kind of company that hires an MSP in the first place. Small to mid-sized. Limited in-house security expertise. Low tolerance for downtime.

You aren’t going to audit 56 safeguards during a sales cycle. Nobody does. But IG1 gives you a defensible floor, and in Texas it quietly does something else on top of that, which comes up further down this page.

Condensed to the layers a credible stack has to cover, you’re looking for these.

  • Endpoint detection and response on every workstation and server, not antivirus on its own
  • Enforced multi-factor authentication on email, remote access, and every administrative account
  • Email filtering with impersonation and payload protection, not just spam scoring
  • Backup with at least one copy your provider’s own admin credentials cannot delete
  • Patch management with a stated deployment window for critical vulnerabilities
  • Centralized logging that survives the machine it came from
  • Security awareness training with results you’re allowed to see
  • A documented incident response plan naming who calls whom, in what order

Two of those earn a note. Patching moved up the list this year, because Verizon’s 2026 Data Breach Investigations Report found that 31% of breaches now start with a software vulnerability, which puts exploitation ahead of stolen credentials as the top way in. Ransomware turned up in 48% of breaches over the same window. So a patch cycle measured in weeks is a live exposure. Not a housekeeping preference.

Identity is the other one. MFA by itself is table stakes now, and the useful question is what sits behind it. If your provider runs a Microsoft tenant for you, ask which Conditional Access policies they’ve configured, and whether they can export the list without a project. A provider running a standard policy set across their whole client base will send it the same afternoon. One building it per client from scratch will not, and that answer is worth as much as the export.

Anything sold above that line is a real conversation. Anything missing below it is a gap they should be naming out loud, rather than hoping you don’t count.

What does “Microsoft Defender” actually mean on your proposal?

Four different Microsoft products get written onto proposals as “Microsoft Defender.” They are not the same product. Two include EDR. Two don’t, and one of those two is what ships bundled with the more expensive Microsoft license.

IT manager comparing two admin console screens against a printed licensing comparison sheet

Microsoft publishes the comparison itself. Defender for Endpoint Plan 1 includes next-generation antivirus, attack surface reduction rules, web and network protection, and manual response actions your technician can take by hand. It does not include EDR. It also leaves out automated investigation and remediation, automatic attack disruption, threat analytics, and vulnerability management, all of which live in Plan 2.

Defender for Business, the one bundled inside Microsoft 365 Business Premium, does include EDR in an optimized form. It adds automated investigation and automatic attack disruption too. Capped at 300 users.

Put those two paragraphs together and an odd result falls out. Plan 1 is what’s bundled with Microsoft 365 E3. So a 200-seat company on E3 can be running strictly less endpoint detection than a 25-seat company on Business Premium, while paying more per seat for the productivity licensing sitting underneath it. That isn’t a hypothetical. It’s what happens any time a proposal says “Microsoft Defender, included” and nobody writes down which one.

What the proposal saysWhat you actually getEDRAutomated responseUsually bundled with
Microsoft Defender AntivirusThe antivirus engine built into WindowsNoNoWindows itself, at no extra cost
Defender for Endpoint Plan 1Next-gen antivirus, attack surface reduction, web and network protection, manual response actionsNoNoMicrosoft 365 E3
Defender for BusinessPlan 1 plus optimized EDR, automated investigation, attack disruption, capped at 300 usersYes, optimizedYesMicrosoft 365 Business Premium
Defender for Endpoint Plan 2Full EDR, advanced hunting, threat analytics, 6 months of data retentionYesYesMicrosoft 365 E5
Defender for Office 365Email and collaboration protection, not an endpoint product at allNot applicableNot applicableBusiness Premium and E5

Ask for the SKU name and the plan number in writing. Inside the scope document, not in an email from a salesperson. The same rule applies to every product on the list, because nearly every vendor name that appears on an MSP proposal is a product family rather than a tier, and the tier is the part that determines what you actually own.

Who’s watching this at 2 in the morning?

Do the arithmetic. A week holds 168 hours. Business hours, Monday through Friday, 8 to 5, is 45 of them. That’s 26.8% of the week.

So a stack monitored during business hours is unwatched for roughly 73% of the time it exists. Ransomware crews know that number as well as you do, which is why deployment lands so reliably on a Friday night, or on the first morning of a long weekend when the office is empty and the phones roll to voicemail.

Lone security analyst watching endpoint alert queues in a dim operations room after 2 a.m.

This is the line between EDR and MDR. It’s worth being precise about the words, because providers usually aren’t. EDR is a product. MDR is a staffed service wrapped around a product, where a security operations team reads the alerts and acts on them. A provider can sell you an excellent EDR and still have nobody reading it after 5 p.m. We took the category difference apart properly in MSP vs MSSP.

Three questions get you a real answer. None of them is “do you offer 24/7 monitoring.” Everyone says yes to that one.

  • Is the overnight shift your own staff or a third party? If it’s a third party, name them.
  • What’s the escalation path for a confirmed endpoint detection at 2 a.m., by role and by name?
  • Do your analysts have standing authority to isolate one of our machines, or do they call us first?

The third one matters most. The honest answer from a lot of providers is that they call first, which is entirely defensible for a law firm and genuinely terrible for a manufacturer running a production line that costs thousands of dollars an hour to restart. That tradeoff gets sharp fast in the manufacturing environments we work in. Isolate the wrong host and you stop the line yourself.

How do you tell a monitored alert from a logged one?

A logged alert exists somewhere. A monitored alert has a name attached to it.

Ask for 2 numbers and 1 document. The numbers are mean time to detect and mean time to respond for the last quarter. Already a client? Ask for yours specifically. If you’re not, ask for their book average, accept that it’s a marketing figure, and then ask what the worst single case was in that same quarter, because the worst case tells you considerably more about a provider than any average ever will.

The document is the runbook.

A runbook that names roles is fine. One naming a rotation, a phone tree and a fallback contact is better. A runbook that doesn’t exist in writing is itself the answer. Stop the meeting there.

One unglamorous thing left. Where do alerts go? If the honest answer is a shared inbox, you don’t have monitoring. You have email. And alert volume in a shared inbox has exactly one standard ending, which everybody who has ever sat in that inbox already knows. Somebody mutes the thread.

Response-time promises are their own genre of fiction, incidentally. We benchmarked what those numbers actually mean across Texas MSP SLA benchmarks.

What protects the MSP’s own tools?

Your provider’s remote monitoring and management agent holds administrative rights on every machine you own. Their remote access tool too. That isn’t a criticism. It’s how the model works, and it also means their tooling is a far more valuable target than your network is, because a single compromise there reaches every client on their book at once.

CISA, the FBI and MS-ISAC published a joint advisory on precisely this pattern. Attackers abusing legitimate RMM software rather than bringing malware of their own, because the legitimate tool is already installed and already trusted by everything around it. Remote access products commonly used by MSPs have landed on CISA’s Known Exploited Vulnerabilities catalog more than once.

Four questions. A provider who takes security seriously will enjoy answering them.

  • Is MFA enforced on your RMM and your remote access tool, for every technician, with no exceptions?
  • Is each client environment separated so that a compromise of one can’t pivot into the others?
  • How fast do you patch your own tooling when one of its CVEs hits the KEV catalog?
  • Who inside your company can reach our environment, and how often is that list reviewed?

Then ask for the SOC 2 Type II report. Read the subservice organization section specifically. A lot of MSPs carve out their data centre, their SOC provider, or both, and a carve-out means those controls weren’t tested in that report at all. It isn’t a scandal. It’s a scope boundary, and you’re entitled to ask for the carved-out party’s own report to cover the gap. If the audit period ended more than a few months ago, ask for the bridge letter too.

Settle tenant ownership before you sign, separately from the audit questions. Your Microsoft tenant should be yours, with a global admin account your provider doesn’t control. Providers who resell your licensing through their own CSP agreement sometimes hold those keys instead. Workable until it isn’t. Leaving an MSP is a much shorter conversation when you already own the front door.

What does this have to do with your insurance and Texas law?

Two things. Both convert a technical decision into a financial one.

Your cyber insurance application asks whether MFA is enforced, whether EDR is deployed, whether backups are immutable and tested. You sign that application. Your MSP doesn’t. If a control you attested to wasn’t genuinely in place on the day the loss happened, the carrier has grounds to deny the claim and, depending on the policy wording, to unwind the coverage from inception.

Finance director and IT director working down the control checkbox column of a cyber insurance application

So the attestation is a stack audit with legal consequences bolted on, and you’re the one holding the pen. Walk the application questions against the 4 states from that first table before you sign either document. Anything still sitting at “licensed” should not be answered yes.

The second thing is Texas-specific and fairly new. Senate Bill 2610 took effect on September 1, 2025. It creates a safe harbor from exemplary damages for Texas businesses under 250 employees that maintain a cybersecurity program conforming to a recognized framework, scaled by headcount. Under 20 employees gets simplified requirements around password policy and training. From 20 to 99, the statute names CIS Controls Implementation Group 1. From 100 to 249, it points at the larger frameworks like NIST or the ISO 27000 series.

Read that as procurement. Because that’s what it is. If you employ 60 people in Texas, the stack you buy decides whether you qualify, which turns a security conversation into a legal one somewhere around the third meeting. Ask your provider to map their standard security tier against IG1, safeguard by safeguard, and to name the gaps honestly. A provider who can’t produce that mapping has told you something useful about how they think.

It’s a safe harbor against exemplary damages. Not a shield against liability generally. Worth having, worth not misunderstanding.

What should the security half of the bill cost?

Public benchmarks put full managed IT somewhere in the $100 to $250 per user per month range for 2026, with security-inclusive tiers sitting at the upper end of that. Priced separately, the components land roughly like this. EDR in the single digits to low teens per endpoint. Managed detection and response anywhere from $8 to $35 per endpoint, depending on coverage hours and log volume. Email security around $5 to $10 per user.

Treat all of that as a sanity check. Not a quote. What matters more than the number is which side of the line each item sits on.

Price the stack 2 ways. Once as the bundle, once as line items with the security components broken out separately. Two things fall out. You learn what’s genuinely included versus what turns into a change order in month 4, and you get a number that’s actually comparable across providers who bundle their tiers differently.

When 2 quotes for the same scope come back far apart, the security tier is usually where the gap lives. We pulled that apart in why two Houston MSPs quote different prices for the same scope. And if you’re weighing an outside provider against keeping it internal, the security stack is the line item that breaks the comparison. A single internal hire doesn’t come with a SOC attached. That math sits in in-house IT vs an MSP.

The 9 things to ask for instead of asking a question

Questions get answers. Answers are free. Ask for artifacts instead, because every item below is something a competent provider can produce inside a week, and something a weak one will stall on for a month while promising it’s coming. The stalling is the signal.

  1. A screenshot of the endpoint console filtered to your device count, held up against the seat count from your HR system
  2. The exact SKU name and plan number of every security product, written into the scope document
  3. The most recent restore test report, with a date and a system name on it
  4. The Conditional Access policy export, or at minimum the named-locations list
  5. The escalation runbook for a confirmed endpoint detection at 2 a.m., with roles and phone numbers
  6. Last quarter’s mean time to detect and mean time to respond, plus the worst single case
  7. The SOC 2 Type II report, including the subservice organization section and a current bridge letter
  8. The out-of-scope rate card, so you know what a change order costs before you need one
  9. A written answer to what happens to their RMM agent on your machines the day your contract ends

Nine requests. Get 7 back without friction and you’re dealing with a genuine security practice. Get 3 and you’re dealing with a help desk that resells security products, which is a perfectly legitimate business to run and a completely different one to buy, and it ought to be priced accordingly.

None of this replaces a wider evaluation. Our managed IT services checklist covers the commercial side, and the MSP scorecard turns a shortlist into a weighted number once you’re down to finalists. Running a formal procurement? The MSP RFP process piece has the sections to include. Contract language lives in MSP contract terms. There’s a broader version of the whole vetting process in our MSP evaluation checklist. Already shortlisting by market? We’ve compared providers across Houston and worked through the multi-site question in Dallas and Fort Worth.

Where this evaluation won’t help you

The audit tells you what a provider has and who operates it. It doesn’t tell you whether they’ll be any good at it.

Judgment leaves no artifact. Knowing which alert to chase at 2 a.m. and which one to close as noise is a skill, and no document proves it. The closest proxy I’ve found is asking a provider to walk you through a real incident they handled badly. Not their best case. A bad one. What they missed, how long it took to notice, what changed afterwards.

A provider with a good answer to that has been through something. One who claims nothing has ever gone sideways is either very new or not being straight with you, and neither of those is what you want holding administrative credentials on every machine in your building.

Reference calls earn their keep here too, in a way they don’t elsewhere. Ask about their worst week. Not their onboarding.

How Uprite handles this

We’re a managed IT and security provider. Weigh this section accordingly.

Our position is that the 4-state test should be answerable by any provider inside a single meeting, including us. When we scope a security tier, SKU names and plan numbers go into the scope document rather than a proposal summary. Out-of-scope work sits on a published rate card. The escalation path for an after-hours detection gets written down before the contract starts, not after the first incident, because writing it during an incident is how the wrong person ends up making the isolation call.

We’ve supported Texas businesses since 1999, across Houston, San Antonio, Dallas and Fort Worth, with a team of 42.

The layer-by-layer view of what we run is on our cybersecurity solutions page. If you’d rather skip the reading and have somebody walk your current stack against the 4 states, that’s an assessment. It takes about an hour.

What buyers ask us before they sign

How do I know if an MSP’s security is actually any good?

Ask for evidence, not answers. A provider with a real security practice can produce a dated restore test report, an escalation runbook and a SOC 2 Type II inside a week. One who stalls on all 3 has already answered the question, and no amount of follow-up meetings is going to change that answer into a better one.

Is antivirus enough if we’re a small company?

No, and it hasn’t been for years. Antivirus blocks what it already recognizes. EDR records what happened on the machine so somebody can reconstruct an intrusion that never looked like malware, which describes a growing share of them. Size doesn’t change the math. A 30-person firm holding client financial data gets hit by the same automated tooling that finds a 3,000-person one, and the 30-person firm usually has far less room to absorb a week of downtime.

Should our MSP handle security, or do we need a separate firm?

Either arrangement works. What doesn’t work is assuming your MSP does security because they installed antivirus and turned on MFA. Decide which model you’re buying, write it into the scope, price it. One provider handling both is simpler to run and easier to hold accountable. Splitting it gives you a second set of eyes and a natural check on the first party, which some regulated firms specifically want.

What if a provider says everything is included and won’t break out security pricing?

That’s a negotiating position, not a technical constraint. Every provider knows their own cost per seat per product, because that’s how they buy it. A refusal to itemize usually means the bundle is thinner than it sounds, or the margin sits somewhere they’d rather not point at. Ask once more in writing. Still no? Score it as a data point and move on.

How often should the stack get reviewed after we sign?

Quarterly for coverage numbers, annually for the stack itself. The quarterly one is boring. Agent coverage against headcount, patch compliance by device group, backup restore tests, MFA exceptions. On Microsoft 365, ask for the Secure Score trend line alongside those, because a score drifting downward quarter over quarter is a maintenance problem showing itself early. The annual review asks the harder question about whether the products still fit the business, which matters more than people expect after a year of hiring, an acquisition, or a move into a regulated line of work.

Does a SOC 2 report mean our data is safe?

It means an independent auditor tested stated controls over a stated period. Nothing more. Read the scope, the period, the exceptions section, and the subservice organizations. A Type II with 3 documented exceptions and honest remediation notes tells you more about a provider than a spotless Type I ever will.

We’re 60 people in Texas. What’s the minimum we should be buying?

CIS Implementation Group 1 is the defensible floor. At 20 to 99 employees it’s also what SB 2610 names for the safe harbor, so the legal answer and the security answer land in the same place, which doesn’t happen nearly as often as it should. Practically, that means EDR everywhere, enforced MFA, filtered email, tested backups with one copy your provider can’t delete, patching with a stated window, logging, training, and a written incident response plan. Anything past that is a business decision about risk tolerance rather than a baseline question.

About Author

Learn More