Every MSP proposal says “comprehensive cybersecurity.” The word costs nothing to print. What separates a real security stack from a brochure is operational: which layers actually run on your machines, who watches them, and what happens in the first hour after something goes wrong. Most buyers can’t tell the difference from the proposal alone, and providers with thin stacks count on that. Here is a framework for looking under the hood before you sign, layer by layer, question by question.
Why the brochure can’t be trusted
Not because MSPs lie, mostly, but because security language has no enforcement. “Endpoint protection” can mean modern detection and response with a human watching it, or a free antivirus license nobody has opened since install. “Backup included” can mean immutable offsite copies tested monthly, or a job that has been silently failing since March. Both providers check the same box on your comparison spreadsheet.
The fix is to stop evaluating the vocabulary and start evaluating the operation. For each layer below, the question is never “do you have this,” which always gets a yes. It’s “show me how it runs, who watches it, and what I receive as evidence.”
The seven layers a real stack runs
Endpoint detection and response
Traditional antivirus checks files against a list of known bad ones. That stopped being enough years ago, because modern attacks use legitimate tools and never drop a recognizable file. Endpoint detection and response, EDR, watches behavior instead: a process encrypting files at speed, a login tool moving sideways between machines, a script launching where scripts don’t belong. Good EDR can isolate a compromised machine from the network automatically, which is often the difference between one bad laptop and an encrypted company.
What to verify: EDR on every workstation and server, not just “critical” ones, and a clear answer to who responds when it fires. EDR that alerts into an unread mailbox is antivirus with better marketing.
Email filtering and phishing defense
Most incidents start in the inbox, a fact both CISA and the FBI’s IC3 reporting have made hard to argue with. The email layer should include filtering that inspects links and attachments before delivery, controls against sender impersonation, and a way for staff to report suspicious messages that a human actually reviews.
What to verify: what happens to a reported phish. If the answer is “the user deletes it,” nobody is learning which attacks are getting through.
MFA everywhere, including on the MSP
Multi-factor authentication on email, remote access, VPN, and every administrative account is the cheapest, highest-value control in the entire stack. A stack without enforced MFA is a stack where one reused password beats everything else on this list.
Then the question providers don’t expect: does the MSP enforce MFA on its own tools? The remote management platform an MSP uses holds admin access to every client it serves, which makes MSPs themselves prime targets. An MSP that secures your accounts but not its own has built you a vault with the key under the mat.
Patching discipline
Unpatched software is how known, already-fixed vulnerabilities keep producing new victims. Patching sounds boring precisely because it works. What matters is cadence and coverage: operating systems and third-party applications, on a stated schedule, with reporting that shows what’s patched and what’s pending, and a process for the machines that keep missing their window.
What to verify: ask for a sample patch report. A provider who patches on discipline can produce one in a minute. A provider who patches “as needed” cannot.
Backups ransomware can’t reach
Ransomware crews learned long ago to find and encrypt backups before triggering the main event. That’s why the backup layer needs at least one copy that is immutable or offline, meaning it cannot be altered or deleted even with stolen admin credentials, stored away from your primary environment.
And a backup only counts if it restores. Backup jobs report success while quietly producing unrestorable data more often than anyone likes to admit, which is why test restores on a schedule belong in the agreement, not in the goodwill. Our data backup and recovery page covers what a managed backup layer includes; the short version for evaluation purposes is one question: “When did you last restore from backup, and how long did it take?” Watch whether the answer includes a date.
Monitoring, and a human who answers
Every tool above generates alerts. Alerts are only security if someone qualified reads them and acts, at 2am on a Saturday, not just during business hours, because attackers demonstrably prefer nights, weekends, and holidays. Ask the provider to walk through the path: alert fires, then what, seen by whom, escalated how, and when do you get told.
This is where thin stacks collapse under questioning. Buying monitoring software is easy. Staffing a response to it is expensive, and it’s exactly the line item quietly missing from the cheaper proposal.
Security awareness training
Your staff sit at the end of every technical control, and attackers know it. Recurring short training plus simulated phishing keeps people appropriately suspicious, and the simulation reporting tells you and the provider where the residual risk sits. One annual video satisfies a compliance checkbox and nothing else.
The questions that expose a thin stack
You don’t need to be technical to run this evaluation. You need three scenario questions, asked to every provider identically:
“Who reviews a security alert at 2am, and what do they do with it?” You’re listening for a process with humans in it, names, escalation steps, when you get called. “Our software handles it” means nobody handles it.
“When did you last restore data from a backup? How long did it take?” A date and a duration means restores actually happen. A pause means they don’t.
“One of our laptops was stolen tonight. Walk me through what happens.” A real stack has an answer: the drive is encrypted so the data is unreadable, sessions and credentials get revoked remotely, the device gets wiped or locked, and there’s a record of what was on it. A thin stack offers to change the user’s password in the morning.
Providers running a genuine operation enjoy these questions, because they’re the questions their weaker competitors can’t answer. That reaction is itself a signal.
Red flags that end the evaluation
- Antivirus presented as the security layer. If the endpoint story is a legacy antivirus product, the whole stack dates from the same era.
- No MFA on the MSP’s own tools. Ask directly. Hesitation is your answer.
- No written incident response plan. If they can’t show you the plan during the sales process, it doesn’t exist, and it will be improvised during your breach.
- Alerts with no named responder. Monitoring that terminates in a dashboard nobody watches.
- “Backups are included,” full stop. No immutability, no test schedule, no restore evidence.
- Answers made of product names. Vendors change; process is what you’re buying. A provider who answers every question with a logo is reselling licenses, not running security.
Any one of these is worth a pointed follow-up. Two or more, and you’re looking at a stack that exists mainly in the proposal.
Comparing proposals apples to apples
Prices for “managed IT with security” vary widely, and the variance almost always lives in the security column. To compare honestly:
- Make the seven layers your rows. EDR, email filtering, MFA, patching, immutable tested backups, monitored response, training.
- For each layer, record three things per proposal: is it included for every user and device, who monitors and responds, and what evidence you receive monthly.
- Price the gaps. A proposal that’s cheaper by a few hundred dollars a month and missing 24/7 alert response isn’t cheaper. It has relocated the cost to the incident.
- Demand it in writing. Whatever survives the comparison belongs in the agreement itself, named controls, cadences, and deliverables, not in the sales deck. What that looks like clause by clause is covered in what a managed IT agreement should include.
One more comparison habit worth keeping: ask each provider what evidence pack you’d receive at cyber insurance renewal time. Insurers now ask, in writing, whether you run MFA, EDR, filtered email, tested isolated backups, and training, and a wrong attestation can void a claim. The provider’s stack is what you’ll be attesting to. A provider who can’t produce the evidence is asking you to sign the insurance application on faith.
What this looks like when it’s real
Braintek has run this kind of layered program for Houston and Dallas–Fort Worth businesses since 2002, built into managed IT rather than sold as a pile of separate security products, for fully managed clients of roughly 10 to 50 people and co-managed alongside in-house IT teams at larger organizations. The layers above aren’t a wish list; they’re the working structure of our cybersecurity services, monitored, maintained, and documented so the insurance questionnaire gets answered honestly. When something needs a human, one answers, typically in about 60 seconds on the phone. That’s a measured typical, not a guarantee, and any provider you evaluate should give you their own measured numbers rather than adjectives.
If you’re evaluating providers right now, run every candidate through the framework above, including us. And if the evaluation convinces you that your current provider’s stack is thinner than the invoice suggests, switching is less disruptive than you think, and the security gaps you found are exactly the transition checklist for whoever comes next.
