Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Managed IT services can give a growing business access to technical and cybersecurity support without hiring every specialist in-house. They can help maintain systems, configure security controls, monitor activity and support incident response—but they reduce risk rather than guarantee protection. The arrangement is only as sound as its access controls, monitoring, backup plan and written division of responsibilities.

What a managed IT provider can do for cybersecurity

Small and midsize businesses may outsource security work when they lack the staff, expertise, resources or budget to build a full in-house team. NIST describes managed service providers (MSPs), managed security service providers (MSSPs) and fractional CISOs as common outsourcing options. Depending on the agreement, a provider may maintain systems, configure controls, monitor activity or assist with response.

Start by defining the outcomes you need and which systems and data the provider will cover. A provider can contribute expertise and operational capacity, but outsourcing some cybersecurity does not transfer the business’s responsibility for protecting its own and its customers’ information. NIST recommends documenting service levels and responsibilities and considering industry, legal, regulatory and contractual needs when evaluating vendors. See NIST’s guidance on building a small-business cybersecurity team.

Why an MSP relationship also creates security risk

An MSP often needs access to customer systems to do its job. That access, along with remote-management tools, can create a path into the customer environment if the provider’s account, infrastructure or tools are compromised. CISA and international partners have warned that threat actors use MSPs “as launch pads to breach their customers’ networks.” This describes a threat, not a claim that every MSP is unsafe. CISA’s May 11, 2022 advisory calls for a shared commitment to security by providers and customers.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Remote monitoring and management (RMM) software lets providers monitor endpoint health and administer systems remotely. The capability is not inherently unsafe, but it needs to be secured and monitored: attackers have exploited RMM platforms to gain a foothold in MSP servers and, by extension, customer networks. Review CISA/JCDC’s Remote Monitoring and Management Cyber Defense Plan for the risks associated with these tools.

Controls to require before granting provider access

Discuss and document security expectations before the MSP begins work. CISA guidance emphasizes secure remote access, monitoring and logging, endpoint detection and network defense, and MFA where possible. Put the following controls into practice with the provider:

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  • Limit privileges. Give provider accounts access only to the systems and tasks they manage. Avoid unnecessary administrative rights, use named accounts where feasible, and disable provider accounts when they are not needed.
  • Secure remote connections. Require MFA for remote access where supported. Restrict provider VPN traffic to a dedicated VPN and review connections between provider and customer systems. A physical FIDO2 security key may be an MFA option if the relevant account or remote-access system supports it; CISA does not endorse a particular key or brand.
  • Monitor and retain activity records. Agree which provider actions are logged, who reviews the logs, how long they are kept and how your business can inspect them. Retain and validate records of provider activity.
  • Clarify subcontractor access. Establish whether subcontractors may access your systems and what access controls apply to them.
  • Plan for incidents together. Set notification triggers and timing for confirmed or suspected incidents involving provider infrastructure or administrative networks. Name contacts, define cooperation expectations and include the provider in incident-response and continuity planning.

CISA’s MSP and small-business hardening guidance and customer risk considerations provide further recommendations. CISA’s May 11, 2022 advisory announcement also quotes Director Jen Easterly urging providers and customers to follow the guidance to help protect themselves and organizations globally.

Make backup and recovery responsibilities explicit

Having an MSP involved does not prove that business data can be recovered. Agree who configures and maintains backups, which systems and data are covered, where copies are stored and who is responsible for restoration. Include offsite or isolated copies where appropriate, and require tests that demonstrate files can actually be restored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

NIST’s National Cybersecurity Center of Excellence guide focuses on planning, maintaining and testing backups against ransomware and other data-loss events. Use it alongside the agreement to clarify recovery roles: Protecting Data from Ransomware and Other Data Loss Events.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to compare MSPs for a growing business

Compare providers against the same scope and the outcomes your business needs. Ask each candidate to answer these questions in writing, then compare quotes only after confirming that the services cover equivalent systems, responsibilities and support.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  1. Scope and outcomes: Which business systems, accounts and data are included? What security outcomes and services are you seeking?
  2. Relevant experience: What experience does the provider have with businesses of your size and in your industry? Can it address applicable legal, regulatory and contractual needs?
  3. Division of duties: Which tasks does the MSP own, which remain yours, and what service levels apply?
  4. Access safeguards: How are least privilege, named accounts, MFA and secure remote access implemented? What rules govern subcontractors?
  5. Monitoring and logs: What activity and systems are monitored, who reviews the results, how long are logs retained, and how can you inspect provider activity?
  6. Incident handling: What triggers a notification, how quickly will you be contacted, who are the points of contact, and how will the provider support your response?
  7. Backup and recovery: Who configures backups, where are copies kept, how often is restoration tested, and who leads recovery?
  8. Comparable quotes: What does each quote include or exclude? Compare cost after aligning scope and service levels rather than choosing on price alone.

CISA’s vendor and supplier assessment fact sheet includes a use case for vetting MSPs with critical access to business systems or data. It reports that more than 30 million small and medium-sized businesses operate in the United States and that they account for nearly half of the nation’s gross domestic product; those figures describe the U.S. SMB context, not the security effectiveness of MSPs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.