Threat data and guidance references current as of 3 September 2026.
Choosing a managed service provider is a procurement exercise disguised as a technology decision, and the two things that decide the outcome are rarely in the proposals. The first is scope: most competing offers differ from each other on what is included rather than on price, so comparing monthly figures tells you almost nothing until both providers have answered the same requirements document. The second is the provider’s own security posture, which matters because whoever you choose will hold privileged access into your environment. Verizon’s 2026 breach reporting puts third-party involvement at close to half of all breaches, a sharp rise in a single year, and current research describes managed providers as a primary attack vector rather than incidental victims, because one compromise reaches every downstream client. CISA and allied agencies have published guidance for MSP customers on exactly this. We recommend you run a process rather than a series of demos, because the demos will not surface either issue.
Overview
- Write the requirements before you take a call. Otherwise the best proposal writer defines your requirements for you.
- Compare scope documents, not monthly rates. The gap between quotes is almost always exclusions rather than margin.
- Your provider becomes a privileged access path. Assessing their own security is part of assessing them, and CISA has published guidance saying so.
- Contract terms decide the real cost. Out-of-scope rates, escalators, and offboarding matter more than the recurring fee.
- Onboarding is where value is won or lost. The first ninety days determine what the relationship becomes.
The 5 Why’s
This is written for executives, finance leaders, and IT directors at organizations between roughly one hundred and a few thousand employees who are selecting a provider for the first time or replacing one that is no longer keeping pace. Typical situations include an internal IT lead resigning, an incumbent whose service has drifted, an acquisition doubling the estate, a compliance obligation arriving through a customer contract, or a security incident that exposed gaps.
The reason this is hard is that the market is genuinely difficult to compare. Providers describe similar services in similar language while drawing the included-versus-billable line in different places, and the word “managed” has no fixed definition. Two proposals at similar prices can cover materially different services, and the difference usually surfaces in the first quarter as onboarding remediation or project work.
Sector conditions shape what you should weight. Manufacturers need providers who understand that plant networks are not office networks. Healthcare organizations need compliance evidence production as a standing capability rather than a project. Financial services firms and their vendors face third-party risk expectations that flow down to whoever they hire. Defense and aerospace suppliers need to know where a provider’s staff are located, since administrative access to environments holding export-controlled technical data by non-US persons is a compliance problem regardless of intent.
The consequence of choosing badly is a multi-year agreement that excludes the services you assumed were included, with the recurring fee still due while you buy them separately at project rates.
Run a Process, Not a Series of Demos
The order of operations matters more than the evaluation criteria, because a good process makes providers comparable and a bad one makes them persuasive.
Write the requirements first. Users, endpoints, servers, sites, applications that resist standardisation, coverage hours you genuinely need, and whichever compliance framework applies to your contracts. This document is the single highest-return hour in the whole exercise, because without it each provider answers in their own template and you end up comparing marketing rather than services.
Longlist on fit, not on proximity. Sector experience, size range, and whether they carry the specialist capabilities your environment needs. Most of the delivery is remote regardless of address, so location matters only for the hands-on portion, which should be specified as a response window rather than inferred from a map.
Send the same document to everyone and require line-item responses. Then hold a scoping call where you ask the same questions in the same order.
Take three reference calls per shortlisted provider, at organizations of similar size and sector. Ask whether communication was clear, whether problems surfaced early enough to fix, whether commitments were met, whether invoices contained surprises, and whether they would sign again. Ask for a client of similar profile rather than accepting whoever is offered, and read the published case studies as background rather than as evidence.
Run due diligence on the provider itself, covering both business stability and their own security, which is the section most buyers skip and the one covered below.
Review the contract before you negotiate the price. Term, escalators, out-of-scope rates, and exit terms determine the real cost more than the monthly figure does.
Then plan onboarding, with a named owner on each side and an agreed first-ninety-days scope. If remediation is required, agree what gets fixed, when, and at whose cost, before signing rather than after.
How Do You Compare Proposals That Are Not Comparable?
By forcing them onto the same scope, then reading the exclusions rather than the inclusions. The exclusion list is where two similarly priced proposals reveal themselves as different products.
The divergences that matter most are consistent. Security depth is the largest: one provider includes detection and response monitored overnight by a staffed operations centre, another includes managed antivirus with alerts reviewed the next business day, and both call it endpoint security. Coverage hours vary, and business hours means different things. Onsite work may be unlimited, capped, or billed. Project work is usually excluded, and what counts as a project rather than as included lifecycle work is a definition worth having in writing. Third-party application patching is frequently assumed and often absent, covering only Microsoft updates.

Two further items belong in the comparison and rarely appear in it. Onboarding remediation is the first: providers quote a steady state, and if your environment arrives with unpatched servers, undocumented backups, and shared administrator accounts, that gap gets billed in the first quarter as remediation. A provider willing to scope it before you sign is telling you something good about how they work. Response and resolution commitments are the second, and they are different things: a one-hour response target with no resolution target is a commitment to acknowledge your outage promptly. Organizations retaining internal IT should also be clear whether they are buying a full outsource or a co-managed arrangement, because the two are priced and scoped differently and blending them in an evaluation produces the wrong shortlist.
What we recommend you do about it:
- Require line-item responses to your document. A proposal in the provider’s own template is not comparable to anything.
- Read the exclusion list first. It is more informative than the inclusion list.
- Ask what the security operations capability actually is. Staffed by whom, in what hours, and what changes overnight.
- Get the out-of-scope hourly rate in the agreement. It determines what the relationship costs in practice.
- Ask for onboarding findings before signing. A provider deferring that conversation is deferring an invoice.
How Do You Assess the Provider’s Own Security?
Directly, and with the same rigour you would apply to any vendor holding privileged access, because that is exactly what a managed provider is. This is the part of the evaluation almost no buyer guide covers, including guides published by providers.
The reason it matters has changed in the past two years. Attackers have worked out that a single provider holds credentials and operational access to many client networks, so one compromise unlocks all of them without per-target effort. Verizon’s 2026 reporting puts third-party involvement at close to half of breaches, up sharply year over year, and research published in 2026 by multiple security vendors describes managed providers as a primary vector rather than collateral damage. The 2021 compromise of a widely used remote management platform, which reached dozens of providers and well over a thousand of their customers in one stroke, remains the clearest illustration of the mechanism.

CISA, the NSA, the FBI and allied agencies in the UK, Australia, Canada and New Zealand issued a joint advisory on protecting managed providers and their customers, and CISA published separate guidance written for customers, structured for board, procurement, and technical audiences. The recommendations that matter most in a selection process are worth using verbatim as questions. Define the provider’s required privilege and access levels before contract award rather than granting broad access and narrowing later. Apply least privilege to the provider and to any subcontractor, for the shortest necessary duration, and re-evaluate periodically. Require contractual incident response and recovery provisions that meet your own resilience requirements, and test them at intervals. Understand exactly what access the provider holds to your network and your data, and understand their own supply chain, including subcontractors.
Beyond that, three questions surface real differences. How are client environments isolated from one another, and what is the blast radius if another client is compromised, answered with specific technical controls rather than policy language. How is privileged access to your environment protected on their side, including multi-factor enforcement on their own administrative accounts and how their remote management tooling is secured. And what independent attestation do they hold about their own controls, since a provider selling you security evidence should be able to produce some of its own. Ask where the service desk and operations centre are staffed while you are there, since that answer is a compliance question in some environments and a service question in all of them. Our own view on this sits with the rest of our cybersecurity practice, and it applies to us as much as to anyone you are evaluating.
What we recommend you do about it:
- Define required privilege levels before contract award. CISA’s own guidance, and the single most useful item on this list.
- Ask about tenant isolation and blast radius. Specific controls, not policy statements.
- Ask how their administrative access is protected. Multi-factor on their side, and how their management tooling is secured.
- Require incident response provisions in the contract. Including what happens if the incident is theirs rather than yours.
- Ask for their own attestations and their subcontractor list. A security provider should be able to evidence its own posture.
Which Contract Terms Actually Matter?
Five, and none of them are the monthly rate. These determine what the relationship costs across its life and how easily you can leave it.
Term and escalators. Multi-year agreements with annual increases produce a total cost meaningfully different from the headline figure. Model the full term rather than the first month.
Out-of-scope rates. The hourly rate for anything outside the agreement, in writing. Combined with the exclusion list, this is your actual cost exposure.
Data and documentation portability. Network diagrams, configurations, licence records, runbooks, and administrative credentials should be yours, in a usable format, at any point and without a project attached. When documentation lives only in a provider’s platform you have a dependency unrelated to service quality, and you will discover it at the worst moment.
Termination and offboarding. Notice periods, any offboarding fees, and what transition assistance is included. Ask this during the sales process, because it is easiest to get answered before you are a customer.
Assignment on acquisition. This market is consolidating steadily, and the provider you select may be owned by someone else within your contract term. Ask who owns them now, whether they have been acquired recently, and what happens to your terms and your data if they are acquired again.

One further term deserves attention where it applies. If nobody in the agreement owns your technology roadmap, you have bought support rather than an IT function, and that gap is invisible because nothing appears broken. Some providers include advisory capacity at higher tiers, some sell it separately as retained virtual CIO capacity, and some do not offer it. Name it during evaluation rather than discovering it in year two. Organizations with compliance obligations should also confirm that evidence production is a standing deliverable with a cadence rather than an annual scramble, since that is recurring labour and frequently sits outside a standard agreement.
What we recommend you do about it:
- Model the full term with escalators. The first-month figure is not the price.
- Get portability in writing while you have leverage. Before signing, not during a transition.
- Ask how you would leave. A provider confident in their work will not mind the question.
- Ask who owns them and whether that could change. Consolidation is routine in this market.
- Confirm who owns the roadmap. If the answer has no name attached, it is nobody.
Provider Selection Expertise from Matt Rosenthal
In 30 years of both buying and selling technology services, I have watched more relationships fail over scope than over price, and I have watched buyers spend weeks on feature comparisons without once asking the provider about its own security. What I have seen firsthand is a company selecting on the lowest monthly figure and then spending eighteen months buying back everything the quote excluded at project rates, finishing above the proposal it rejected. Our team quotes from an assessment rather than a headcount and puts the exclusions in writing before anyone signs, and we expect prospects to ask us the same due diligence questions this page recommends. Send every provider the same document. Everything gets easier after that. See our managed IT services and cybersecurity services.
The First Ninety Days
Selection is half the exercise. The onboarding period determines what the relationship actually becomes, and it is the part nobody negotiates.
Agree the scope of the first ninety days before signing: documentation and discovery, tooling deployment, remediation of anything found during assessment, and the point at which the provider takes full operational responsibility. Name an owner on each side, someone accountable rather than a shared mailbox. Agree what remediation costs and when it happens, so the first quarter’s invoices contain nothing you have not already discussed.
Then set the review cadence early. Monthly operational reporting in terms your leadership recognises, and a quarterly conversation about direction rather than tickets. Providers who resist a defined onboarding scope or a review cadence are telling you something about how the next three years will go.
If you are evaluating providers now and do not have a requirements document, build that first. It costs an hour, it makes every proposal comparable, and it prevents the most expensive mistake in this category, which is letting the best-written proposal define what you needed. Schedule a consultation if you want help building one, whoever you end up selecting.
