Choosing and Managing Your MSP. A vetting checklist and practical guide for selecting a Managed Service Provider, and structuring the relationship for the Pragmatic GRC Methodology.

Why This Deserves Its Own Page

If you’ve read this far in the book, you’ve already met your MSP more than once—whether you noticed it or not. The very first case study in Chapter 1, “The Vanishing Managed Service Provider,” is an MSP relationship gone wrong. Chapter 4 warns you explicitly about who holds your root administrative credentials. By Chapter 6, “IT Manager or MSP” is listed as the owner for most of your five KPIs.

In other words: the methodology assumes you have one, trusts it with real authority, and never once tells you how to choose it well or manage it once it’s in place. This page closes that gap.

A note on where this came from: this isn’t theoretical. It’s built from watching the same relationship play out dozens of times—sometimes as the reason a business sailed through a security review, sometimes as the reason it didn’t.

What Good and Bad Actually Look Like

Before the checklist, it helps to know what you’re watching for. Most MSP relationships don’t fail all at once—they drift, one skipped update or one vague answer at a time.

Signs You’re in Good Hands

  • They can tell you exactly who holds your root/admin credentials, and it’s a name you recognize on your own team, not just theirs
  • They send you monthly reports without you having to ask
  • They welcome an independent security review instead of resisting it
  • They tell you about a mistake before you find it yourself

Signs Worth a Hard Conversation

  • Only they know the admin passwords, and getting them requires a support ticket
  • Patch and backup reports are vague (“all good”) rather than specific
  • They get defensive when you ask for evidence, not just a status update
  • Offboarding a departed employee takes days, not minutes

Before You Sign: The Selection Checklist

Use this during the vetting conversation itself, not after you’ve already decided. Every question here maps to something this methodology actually depends on later.

MSP Selection Checklist

Ten questions worth a straight answer before you sign anything.

Will our business retain ownership of root/administrative credentials?This is the exact failure behind Chapter 1’s opening case study.
Does their standard SLA commit to response times that meet or beat our own targets—for example, account deactivation in under 60 minutes?If their contract is slower than your KPI, the KPI was never really achievable.
Can they provide monthly reporting that maps to our five Pragmatic KPIs, not just a generic status email?
Will they name a specific point of contact who can join our Monthly GRC Heartbeat™?
Do they carry their own cyber liability insurance, and can they provide proof?
Will they sign a confidentiality or data processing agreement covering our specific data?
Can they provide references from businesses closer to our size, not just their largest client?
Do they have a documented offboarding process if we ever switch providers?A vendor who can’t describe how the relationship ends is telling you something.
Do they support an independent security review of their own work, rather than resisting it?
Is patch validation a standard part of their process, or a paid add-on?This is Metric 2 from Chapter 6—know before you sign whether it’s included.

After You Sign: Structuring the Relationship

A good MSP contract doesn’t end the work—it just tells you what the MSP is actually responsible for once the Pragmatic GRC Methodology™ is running. Most SMBs split ownership of the five KPIs between internal staff and their MSP roughly like this:

KPITypically Owned By
Account Lifecycle Closure TimeShared — HR initiates, MSP executes
Critical Patch Validation RateMSP
Vulnerability Resolution TimeMSP, with business owner sign-off
Backup & Recovery VerificationMSP
Incident Response ReadinessShared — business owner leads, MSP supports

Put this ownership split in writing, even informally, before your first Monthly Heartbeat. The single most common breakdown isn’t a technical failure—it’s both sides assuming the other one was watching a metric that neither one actually was.

Want Help With This Conversation?

Vetting or resetting an MSP relationship is exactly the kind of conversation that benefits from someone who’s sat through it before—on both sides of a good outcome and a bad one.

Bring This Checklist to Your Next MSP Conversation

Whether you’re choosing a new provider or resetting expectations with your current one, this is exactly the kind of engagement the Pragmatic GRC Methodology™ was built to support.

Get the Book → Talk to an Advisor →