Free Resource · guide

How Should a Company Evaluate an MSP's Cybersecurity Stack?

Evaluate an MSP's cybersecurity stack by checking for seven layers in writing, endpoint detection and response, email filtering, MFA enforced everywhere, disciplined patching, backups that ransomware can't encrypt, monitoring with a named human answering alerts, and ongoing user training, then asking the operational questions brochures never answer: who reviews the alert at 2am, when did you last test a restore, and what happens when a laptop is stolen. Any provider who answers with product names instead of processes is selling you software, not security.

Every MSP proposal says “comprehensive cybersecurity.” The word costs nothing to print. What separates a real security stack from a brochure is operational: which layers actually run on your machines, who watches them, and what happens in the first hour after something goes wrong. Most buyers can’t tell the difference from the proposal alone, and providers with thin stacks count on that. Here is a framework for looking under the hood before you sign, layer by layer, question by question.

Why the brochure can’t be trusted

Not because MSPs lie, mostly, but because security language has no enforcement. “Endpoint protection” can mean modern detection and response with a human watching it, or a free antivirus license nobody has opened since install. “Backup included” can mean immutable offsite copies tested monthly, or a job that has been silently failing since March. Both providers check the same box on your comparison spreadsheet.

The fix is to stop evaluating the vocabulary and start evaluating the operation. For each layer below, the question is never “do you have this,” which always gets a yes. It’s “show me how it runs, who watches it, and what I receive as evidence.”

The seven layers a real stack runs

Endpoint detection and response

Traditional antivirus checks files against a list of known bad ones. That stopped being enough years ago, because modern attacks use legitimate tools and never drop a recognizable file. Endpoint detection and response, EDR, watches behavior instead: a process encrypting files at speed, a login tool moving sideways between machines, a script launching where scripts don’t belong. Good EDR can isolate a compromised machine from the network automatically, which is often the difference between one bad laptop and an encrypted company.

What to verify: EDR on every workstation and server, not just “critical” ones, and a clear answer to who responds when it fires. EDR that alerts into an unread mailbox is antivirus with better marketing.

Email filtering and phishing defense

Most incidents start in the inbox, a fact both CISA and the FBI’s IC3 reporting have made hard to argue with. The email layer should include filtering that inspects links and attachments before delivery, controls against sender impersonation, and a way for staff to report suspicious messages that a human actually reviews.

What to verify: what happens to a reported phish. If the answer is “the user deletes it,” nobody is learning which attacks are getting through.

MFA everywhere, including on the MSP

Multi-factor authentication on email, remote access, VPN, and every administrative account is the cheapest, highest-value control in the entire stack. A stack without enforced MFA is a stack where one reused password beats everything else on this list.

Then the question providers don’t expect: does the MSP enforce MFA on its own tools? The remote management platform an MSP uses holds admin access to every client it serves, which makes MSPs themselves prime targets. An MSP that secures your accounts but not its own has built you a vault with the key under the mat.

Patching discipline

Unpatched software is how known, already-fixed vulnerabilities keep producing new victims. Patching sounds boring precisely because it works. What matters is cadence and coverage: operating systems and third-party applications, on a stated schedule, with reporting that shows what’s patched and what’s pending, and a process for the machines that keep missing their window.

What to verify: ask for a sample patch report. A provider who patches on discipline can produce one in a minute. A provider who patches “as needed” cannot.

Backups ransomware can’t reach

Ransomware crews learned long ago to find and encrypt backups before triggering the main event. That’s why the backup layer needs at least one copy that is immutable or offline, meaning it cannot be altered or deleted even with stolen admin credentials, stored away from your primary environment.

And a backup only counts if it restores. Backup jobs report success while quietly producing unrestorable data more often than anyone likes to admit, which is why test restores on a schedule belong in the agreement, not in the goodwill. Our data backup and recovery page covers what a managed backup layer includes; the short version for evaluation purposes is one question: “When did you last restore from backup, and how long did it take?” Watch whether the answer includes a date.

Monitoring, and a human who answers

Every tool above generates alerts. Alerts are only security if someone qualified reads them and acts, at 2am on a Saturday, not just during business hours, because attackers demonstrably prefer nights, weekends, and holidays. Ask the provider to walk through the path: alert fires, then what, seen by whom, escalated how, and when do you get told.

This is where thin stacks collapse under questioning. Buying monitoring software is easy. Staffing a response to it is expensive, and it’s exactly the line item quietly missing from the cheaper proposal.

Security awareness training

Your staff sit at the end of every technical control, and attackers know it. Recurring short training plus simulated phishing keeps people appropriately suspicious, and the simulation reporting tells you and the provider where the residual risk sits. One annual video satisfies a compliance checkbox and nothing else.

The questions that expose a thin stack

You don’t need to be technical to run this evaluation. You need three scenario questions, asked to every provider identically:

“Who reviews a security alert at 2am, and what do they do with it?” You’re listening for a process with humans in it, names, escalation steps, when you get called. “Our software handles it” means nobody handles it.

“When did you last restore data from a backup? How long did it take?” A date and a duration means restores actually happen. A pause means they don’t.

“One of our laptops was stolen tonight. Walk me through what happens.” A real stack has an answer: the drive is encrypted so the data is unreadable, sessions and credentials get revoked remotely, the device gets wiped or locked, and there’s a record of what was on it. A thin stack offers to change the user’s password in the morning.

Providers running a genuine operation enjoy these questions, because they’re the questions their weaker competitors can’t answer. That reaction is itself a signal.

Red flags that end the evaluation

  • Antivirus presented as the security layer. If the endpoint story is a legacy antivirus product, the whole stack dates from the same era.
  • No MFA on the MSP’s own tools. Ask directly. Hesitation is your answer.
  • No written incident response plan. If they can’t show you the plan during the sales process, it doesn’t exist, and it will be improvised during your breach.
  • Alerts with no named responder. Monitoring that terminates in a dashboard nobody watches.
  • “Backups are included,” full stop. No immutability, no test schedule, no restore evidence.
  • Answers made of product names. Vendors change; process is what you’re buying. A provider who answers every question with a logo is reselling licenses, not running security.

Any one of these is worth a pointed follow-up. Two or more, and you’re looking at a stack that exists mainly in the proposal.

Comparing proposals apples to apples

Prices for “managed IT with security” vary widely, and the variance almost always lives in the security column. To compare honestly:

  1. Make the seven layers your rows. EDR, email filtering, MFA, patching, immutable tested backups, monitored response, training.
  2. For each layer, record three things per proposal: is it included for every user and device, who monitors and responds, and what evidence you receive monthly.
  3. Price the gaps. A proposal that’s cheaper by a few hundred dollars a month and missing 24/7 alert response isn’t cheaper. It has relocated the cost to the incident.
  4. Demand it in writing. Whatever survives the comparison belongs in the agreement itself, named controls, cadences, and deliverables, not in the sales deck. What that looks like clause by clause is covered in what a managed IT agreement should include.

One more comparison habit worth keeping: ask each provider what evidence pack you’d receive at cyber insurance renewal time. Insurers now ask, in writing, whether you run MFA, EDR, filtered email, tested isolated backups, and training, and a wrong attestation can void a claim. The provider’s stack is what you’ll be attesting to. A provider who can’t produce the evidence is asking you to sign the insurance application on faith.

What this looks like when it’s real

Braintek has run this kind of layered program for Houston and Dallas–Fort Worth businesses since 2002, built into managed IT rather than sold as a pile of separate security products, for fully managed clients of roughly 10 to 50 people and co-managed alongside in-house IT teams at larger organizations. The layers above aren’t a wish list; they’re the working structure of our cybersecurity services, monitored, maintained, and documented so the insurance questionnaire gets answered honestly. When something needs a human, one answers, typically in about 60 seconds on the phone. That’s a measured typical, not a guarantee, and any provider you evaluate should give you their own measured numbers rather than adjectives.

If you’re evaluating providers right now, run every candidate through the framework above, including us. And if the evaluation convinces you that your current provider’s stack is thinner than the invoice suggests, switching is less disruptive than you think, and the security gaps you found are exactly the transition checklist for whoever comes next.

Want a second opinion on a security proposal?

Send over the proposal or your current provider's security summary. We'll tell you which layers are real, which are marketing, and what questions to ask next, whether you ever work with us or not.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

What layers should an MSP's security stack include at minimum?

Endpoint detection and response on every workstation and server, email filtering with anti-phishing controls, multi-factor authentication on email, remote access, and admin accounts, managed patching with a stated cadence, backups with at least one copy attackers can't alter, monitoring with a human response path, and recurring security awareness training. Missing any one of these leaves a gap the others can't cover.

Is antivirus the same thing as endpoint detection and response?

No. Traditional antivirus matches files against known signatures. EDR watches behavior, flags activity that looks like an attack in progress, and can isolate a compromised machine from the network. A proposal that lists antivirus as its endpoint layer is describing a 2010 stack, and it's the single most common sign of a thin one.

What questions expose a weak MSP security stack fastest?

Three work well. Who reviews a security alert at 2am on a Saturday, and what do they do with it. When did you last actually restore data from a backup, and how long did it take. Walk me through what happens if one of our laptops is stolen tonight. Providers with a real stack answer with names and steps. Providers without one answer with product logos.

Should the MSP itself have MFA and security controls on its own tools?

Yes, and you should ask directly. Your MSP's remote management tools hold administrative access to your entire environment, which makes the MSP itself a high-value target. An MSP that can't describe MFA on its own remote access, separation of admin accounts, and its own incident response plan is a risk you inherit the day you sign.

How do I compare security across two MSP proposals with different prices?

Build a checklist of the seven layers and mark each proposal against it, including who monitors, who responds, and what evidence you receive monthly. Price differences usually trace to a missing layer or to monitoring that exists on paper only. A cheaper proposal missing EDR monitoring or tested restores isn't cheaper, it just moves the cost to your worst day.

Does cyber insurance care what my MSP's stack looks like?

Directly. Insurance applications now ask whether you run MFA, EDR, email filtering, tested and isolated backups, and security training, and a wrong answer can void a claim. Your MSP's stack is what you're attesting to, so the evaluation you do before signing is also the evaluation your insurer will effectively do after an incident.

What does a written incident response plan from an MSP look like?

A document naming who gets called, in what order, with what authority, how affected machines get isolated, when and how you're notified, and who talks to your insurer, your attorney, and your customers. It doesn't need to be long. It needs to exist before the incident, and the MSP should be willing to show it to you during the sales process.

How often should an MSP test backup restores?

Restores should be tested on a recurring schedule, not just verified as "job completed." A backup job that reports success can still produce an unrestorable copy. Ask for the date of the last test restore and how long it took. A provider who has to look that up, or can't, has never done one.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.