What Cybersecurity Should Your MSP Actually Include?
Your MSP should include managed EDR, patch management with a written SLA, enforced MFA, email filtering, tested backup, 24/7 monitoring, log retention, an incident response plan, and MFA on its own admin accounts in the base fee. Scanning, phishing simulation, and a staffed SOC are fair add-ons. Verizon found a third party in 48 percent of breaches.

- Nine controls belong in the base monthly fee. Vulnerability scanning, phishing simulation, and a staffed 24/7 SOC are fair paid add-ons.
- Owning a tool is not operating it. The median time to patch a known exploited vulnerability is 43 days, and only 26 percent get fully remediated.
- Ask for numbers, not tool names. Patch compliance, restore test times, and time to first human response are the three that expose a weak provider.
- Your MSP is your largest third party. A third party was involved in 48 percent of breaches, up 60 percent in a year.
- Charging you to enable MFA inside a license you already pay for is an overcharge, not an add-on.
What cybersecurity should your MSP actually include?
Your MSP should include nine controls inside the base monthly fee. Managed EDR, patch management with a written service level agreement, enforced multi-factor authentication, email filtering, backup with a tested restore, 24/7 monitoring, log retention, a documented incident response plan, and MFA on its own administrator accounts in your systems. Vulnerability scanning, phishing simulation, and a staffed 24/7 security operations center are fair paid add-ons. Billing you again for a feature inside a license you already own is an overcharge. The checklist below gives you a verdict on each line, the weak answer to listen for, and the one question that exposes it.
The stakes sit in the data, not in a sales deck. Verizon found extortion malware in 88 percent of breaches at small and midsize firms, against 39 percent at large ones. It also found a third party involved in 48 percent of all breaches, a 60 percent jump in one year. Your MSP is that third party. CISA, the NSA, the FBI and four allied agencies warned that attackers deliberately target managed service providers to reach their customers. The real question is not whether your provider sells security. It is which controls they operate, and how you verify it.
This guide is the evaluation half of the buying decision. Use it after you shortlist firms with How to Choose a Managed Service Provider, and read it beside Managed IT vs In-House IT, Co-Managed IT Explained, and How Much Do Managed IT Services Cost?.

Owning a security tool is not the same as operating it
Operating a control means a person reads the alert, closes the finding, and can prove both on demand. That gap is measurable. Verizon puts the median time to patch a known exploited vulnerability at 43 days, up from 32 the year before, and found only 26 percent of catalogued known exploited vulnerabilities fully remediated. Almost every one of those organizations already owns a patching tool. Owning it changed nothing. Mandiant reports a global median dwell time of 14 days, with just over half of intrusions detected internally, which means outsiders found the rest first.
Judge every line below against three verdicts.
- <strong>Included.</strong> The control is table stakes, and a standard managed plan covers it.
- <strong>Add-on.</strong> The control needs real labor or extra licenses, so a separate fee is fair.
- <strong>Overcharge.</strong> The control already sits inside a license you pay for, so a second fee is padding.
Each line gives you what good looks like, what a weak answer sounds like, and the single question that separates the two. Ask the question in the room and write down the answer. A proactive provider gives you a number. A weak one gives you a product name.
Endpoint, patching, and identity belong in the base plan
These three controls block the vectors behind most breaches, so they belong in the base plan and never on a separate invoice.
Managed EDR or MDR, not plain antivirus
Managed EDR belongs in the base plan, and plain antivirus no longer counts. EDR watches behavior on a device and can isolate it; antivirus only matches known files. Good looks like EDR on every endpoint and server, alerts triaged by a named team, and a monthly report of what was contained. Weak sounds like we deploy an agent to all your machines. Sophos traced 67 percent of incident response cases to identity-related attacks and measured a median 3.4 hours from first access to Active Directory. Nobody watches a dashboard fast enough to beat that. Verdict. Managed EDR is included, and MDR with a staffed SOC is a fair add-on. Ask who triaged your last EDR alert and how many minutes it took.
Patch management with an actual SLA
Patch management belongs in the base plan, and it needs day counts rather than adjectives. Vulnerability exploitation is now the top initial access vector at 31 percent of breaches. CISA gives federal agencies three days to fix the highest-risk vulnerabilities, a useful yardstick even though you are not a federal agency. Good looks like critical patches inside a stated window, faster handling for anything on the CISA known-exploited list, and a monthly report naming the machines that failed and why. Weak sounds like we patch monthly. Verdict. Included, with no separate fee. Ask to see last month's patch compliance report and the exception list.

MFA enforcement and conditional access
MFA enforcement belongs in the base plan and usually costs your provider nothing extra. Microsoft research found MFA cut the risk of account compromise by 99.22 percent. Sophos still found 59 percent of incident response cases had no MFA in place. Good looks like MFA enforced on every account including admin and service accounts, conditional access policies that block legacy sign-in methods and unfamiliar locations, and a quarterly review of exemptions. Weak sounds like MFA is available for users who want it. Verdict. Included, and charging you to switch on a feature inside a license you already own is an overcharge. Ask which accounts are exempt from MFA today, and why.

Email, backup, and monitoring are where SMB plans quietly thin out
These three controls appear on almost every proposal and fail most often in practice, because each one depends on a person doing something after the tool runs.
Email filtering and phishing simulation
Email filtering belongs in the base plan, and phishing simulation is a fair add-on. Verizon found the human element in 62 percent of breaches and social engineering behind 16 percent. Good looks like filtering that quarantines suspicious mail, a review queue a technician actually works, and quarterly simulations reported by department so you can aim the training. Weak sounds like the built-in filter handles it. Verdict. Filtering is included, and phishing simulation is a fair add-on because someone has to build, send, and review the campaigns. Ask how many quarantined messages the team reviewed last month, and who released them.
Immutable backup with a tested restore
Backup belongs in the base plan, and the restore test is the part that earns the fee. Sophos found backups recovered the data in 66 percent of encrypted-data cases, at an average recovery cost of $1.7 million. It also found organizations with compromised backups paid a median $3 million to recover, against $375,000 with backups intact, roughly eight times more. Good looks like immutable copies an attacker cannot delete, one copy held off-site, and a documented restore test at least quarterly that records how long the restore took. Weak sounds like backups run nightly and we get success emails. Verdict. Included. Ask what your provider restored last quarter and how many minutes it took.

24/7 monitoring and who answers at 2am
24/7 monitoring only belongs in the base plan when a human answers, and that is the whole distinction. Sophos found 88 percent of ransomware payloads were deployed outside business hours, with 79 percent of data theft also happening off-hours. Attackers pick the night shift on purpose. Good looks like a named escalation path, an after-hours number that reaches a person, a written rule for who escalates and when, and a target time to first human response in the service level agreement. Weak sounds like we monitor 24/7, backed by an engineer who checks email in the morning. Verdict. Automated monitoring is included, and a staffed 24/7 SOC is a fair add-on. Call the after-hours number during the sales process and see who picks up.

Scanning, training, and logs are the lines you will be quoted for
Expect a separate price on these three, and negotiate the scope rather than the principle.
Vulnerability scanning
Vulnerability scanning is a fair add-on, and the report is worth nothing without the fix. Only 26 percent of known exploited vulnerabilities get fully remediated, so the failure is almost never the scan itself. Good looks like authenticated scans of servers, firewalls, and network gear at a stated frequency, findings ranked by real-world exploitability rather than raw severity score, and every finding tracked to closure in a ticket you can see. Weak sounds like a 400-page PDF nobody opens. Verdict. Add-on, usually priced by asset count. Ask how often they scan internet-facing systems, how many findings from the last run are still open, and who owns them.
Security awareness training
Security awareness training is a fair add-on, and the measure is behavior rather than completion. Verizon found 45 percent of employees now use AI tools on corporate devices, and 67 percent of them do so through non-corporate accounts, a brand new way to leak data that last year's video does not cover. Good looks like short monthly modules, role-specific content for finance and payroll staff, and completion plus phishing-test results reported to you. Weak sounds like an annual compliance video. Verdict. Add-on. Ask which department failed the last phishing test and what changed afterwards.
Log retention and how long
Log retention belongs in the base plan, and twelve months is a fair benchmark, though the allied agencies stop short of naming a number. CISA, the FBI, the NSA and international partners say default log retention periods are often insufficient and that retention should be informed by an assessment of the risks to a given system, and warn that it can take up to 18 months to discover an incident, with some malware dwelling for 70 to 200 days first. The concrete year comes from the federal standard instead: OMB Memorandum M-26-14 requires agency logs to be actively searchable for at least six months and retrievable for a year after creation. That split is the sharper question to ask a provider, because twelve months of storage says nothing about how much of it is searchable today. Sophos reported that cases hampered by missing logs doubled year over year. Good looks like centralized logs from endpoints, firewall, and Microsoft 365, retained for twelve months, and searchable by your provider in minutes. Weak sounds like the logs are on the device. Verdict. Ninety days is included, and twelve months is a fair add-on because storage costs money. Ask them to pull one user's sign-in history from eight months ago while you watch.

Incident response and vendor risk are the two lines buyers skip
Skip these two and you find the gap during an incident, which is the most expensive moment to find anything. A good provider responds in hours, not days.
Incident response with a named RTO and RPO
Incident response belongs in the base plan as a written plan, and the retainer for hands-on forensics is the add-on. IBM measured a mean 247 days to identify and contain a breach, the first rise after five years of improvement. Good looks like a plan naming who declares an incident, a recovery time objective and recovery point objective agreed per system, a contact tree with out-of-hours numbers, and one tabletop exercise a year. RTO is how long you can be down. RPO is how much data you can afford to lose. Weak sounds like we would get on it right away. Verdict. The plan is included, and an incident response retainer is a fair add-on. Ask for the RTO on your accounting system and the date it was last tested.

Vendor and supply chain risk
Vendor risk is the line buyers skip and attackers use most. Verizon found a third party involved in 48 percent of breaches, up 60 percent in a year, and that only 23 percent of third-party organizations fully remediated missing or misconfigured MFA. Your MSP holds administrator credentials into your systems, which makes it your largest single supply chain risk. Good looks like MFA on every provider account that touches your tenant, named individual technician accounts instead of one shared login, and an independent attestation such as SOC 2, ISO 27001, or a completed CIS Implementation Group 1 self-assessment covering 56 foundational safeguards. Weak sounds like a shared admin account used by whoever is on shift. Verdict. Included, because this is their own hygiene. Ask for a list of every account their staff hold in your environment.
A provider who can tell you the date and duration of your last tested restore is operating the control. A provider who names the backup product is only selling it.
What to get in writing
Get eight things into the contract rather than the proposal deck, because a proposal is marketing and a contract is enforceable.
- <strong>Name</strong> every control included in the base fee, line by line.
- <strong>Set</strong> patch deadlines in days, split by severity.
- <strong>State</strong> the RPO and RTO for each critical system, plus how often restores are tested.
- <strong>Define</strong> after-hours response, including target time to a human and the escalation path.
- <strong>Fix</strong> log retention in months and name who can search the logs.
- <strong>List</strong> every provider account in your environment and require MFA on each.
- <strong>Require</strong> monthly reporting on patch compliance, alerts, restore tests, and training.
- <strong>Agree</strong> exit terms returning your data, documentation, and admin credentials inside a set window.
Map that list to an external standard so you are not inventing one. CIS Implementation Group 1 gives smaller organizations 56 safeguards written for exactly this situation, and NIST's Cybersecurity Framework 2.0 supplies the language most auditors and insurers already use. Regulated buyers should read our Cybersecurity Compliance Guide next, then check the sector notes across our industries pages, including managed IT for finance and managed IT for manufacturing.
Red flags that mean walk away
Six answers should end the conversation, because each one marks a provider who sells tools and does not operate them.
- Refusing to share patch compliance figures or restore test results.
- Billing a setup fee to enforce MFA inside a license you already own.
- Using one shared administrator account across multiple clients.
- Failing to name the date of your last tested restore.
- Listing products instead of outcomes when you ask what they detect.
- Blocking any independent review of their own access to your systems.
None of this buys perfect security, and no honest provider promises that. It buys measurable, contractual coverage and a partner who can prove what they operate. Take the eleven lines above to three vetted firms, ask the same questions, and compare the answers side by side. The one who gives you numbers is usually the one doing the work.
FAQ
What cybersecurity should be included in a standard managed IT plan?
A standard managed plan should include managed EDR, patch management with a written SLA, enforced multi-factor authentication, email filtering, backup with tested restores, 24/7 monitoring, log retention, a documented incident response plan, and MFA on the provider's own admin accounts. Verizon found vulnerability exploitation behind 31 percent of breaches, so patching and endpoint coverage are not optional extras.
What cybersecurity is a fair add-on versus an overcharge?
Vulnerability scanning, phishing simulation, a staffed 24/7 SOC, extended log retention, and an incident response retainer are fair add-ons, because each needs extra labor or licenses. Charging separately to enforce multi-factor authentication is an overcharge, since Microsoft research shows MFA cut account compromise risk by 99.22 percent using licenses you already pay for.
How do I know if my MSP actually operates a security tool?
Ask for last month's numbers, not product names. Request the patch compliance report, the date and duration of the last tested restore, and who triaged the most recent EDR alert. Verizon found only 26 percent of known exploited vulnerabilities fully remediated, which shows most organizations own the tool and skip the operating.
Does my MSP need to answer the phone at 2am?
Yes, if your business cannot absorb a night of downtime. Sophos found 88 percent of ransomware payloads were deployed outside business hours. Automated 24/7 monitoring belongs in the base plan, while a staffed security operations center is a fair add-on. Test the after-hours number before you sign, not during an incident.
How long should my MSP keep security logs?
Twelve months is the benchmark. CISA and allied agencies advise storing logs for one year and note incidents can take up to 18 months to discover. Ninety days belongs in the base plan, and twelve months is a reasonable paid add-on because storage costs money. Confirm who can search the logs and how fast.
Sources
- Verizon, 2026 Data Breach Investigations Report (DBIR)
- CISA, NSA, FBI and international partners, Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A)
- Google Cloud / Mandiant, M-Trends 2026
- Sophos, Active Adversary Report 2026
- CISA, Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk (June 2026)
- Microsoft Research, How effective is multifactor authentication at deterring cyberattacks?
- Sophos, The State of Ransomware 2026
- Sophos, The State of Ransomware 2024
- ASD's ACSC, CISA, FBI and NSA, Best Practices for Event Logging and Threat Detection (2024)
- IBM, Cost of a Data Breach Report 2026
- Center for Internet Security, CIS Critical Security Controls Implementation Group 1
- NIST, Cybersecurity Framework 2.0
- US Office of Management and Budget, Memorandum M-26-14, Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats (22 May 2026)
Best IT MSP is the independent directory of vetted managed IT and cybersecurity providers across North America. Organic ranking is earned on rating and verified data, and paid placement is always labelled. Take this checklist to three merit-ranked firms in your city and compare the answers side by side.