Your MSP Is a Target Too: How to Audit Its Own Security
Your IT provider holds privileged access to many businesses at once, which makes it a target. A regulator has already fined one provider over its own security. Six checks establish whether yours is defended, and how to read the evidence it offers.

- A compromise inside a provider can reach every customer it serves.
- One provider held a certification that did not cover the breached systems.
- MFA on 95 percent of an environment still let an attacker into all of it.
- Only the security category is always examined in a SOC 2.
- ISO does not certify anyone; an external body does, possibly unaccredited.
Why is your IT provider a target?
Because breaking into one provider opens many businesses at once. CISA put it plainly years ago: managed service providers generally have direct and unfettered access to their customers' networks, and a compromise in one part of an MSP's network can spread globally, affecting other customers and introducing risk.

There is an uncomfortable second half to that. Hiring a provider significantly increases an organization's virtual enterprise infrastructure footprint and its number of privileged accounts, creating a larger attack surface. Outsourcing IT is usually the right decision and it still enlarges the target.
The mechanism is well documented. In charging two members of the APT10 group, the US Department of Justice described how, after stealing administrative credentials from an MSP, the group used those credentials to move laterally through the MSP's network and its clients' networks. The credentials your provider holds are the attack path.
What does it look like when a provider is breached?
The clearest published account is not the famous one. In March 2025 the UK Information Commissioner fined Advanced Computer Software Group 3,076,320 pounds following a 2022 ransomware attack, and the penalty notice sets out exactly what a regulator found wanting in an IT provider's own security.
The finding was blunt. Advanced's measures fell short of fundamental cyber security principles, with deficiencies in vulnerability scanning, patch management and multi-factor authentication. The consequences were not abstract: 658 data controller customers were affected by product unavailability, and that unavailability ranged from 18 days to 284 days depending on the product.
One detail should change how you ask about patching. Advanced could not confirm whether the ZeroLogon vulnerability had been patched in the impacted server, because there was not an accurate record of patching at the time. Not that it was unpatched. That nobody could say either way.
Kaseya is the case everyone cites, and it is worth knowing how thin the public numbers are. US intelligence reported that as of 5 July 2021, Kaseya reported the attack affected fewer than 60 direct clients and not more than 1,500 businesses supported by those clients. Note the construction: Kaseya reported. No government produced an independent count, and the vendor's own figures shifted between its own statements.
Does a certification cover the systems that get breached?
Not necessarily, and this is the single most useful lesson in the Advanced case. The company held Cyber Essentials Plus accreditation for its corporate IT infrastructure before the incident, but the health and care environment that was breached was not accredited.
The certificate was real. The estate it covered was not the estate that failed. So the question to ask a provider is never whether they hold a certification. It is which systems the certification covers, and whether the systems touching your data are inside that boundary.

Coverage gaps behave the same way inside a control. Advanced had multi-factor authentication on the applications processing roughly 95 percent of the personal data in the affected environment, and the threat actor still gained access to the entire environment. Ninety-five percent of an estate protected is not ninety-five percent of the risk removed. The gap is the whole of it.
What does a SOC 2 report actually prove?
Less than the logo suggests, and the differences are worth ten minutes of your time. Start with scope. Under the AICPA criteria, for the security category the common criteria constitute the complete set of criteria, and those common criteria apply regardless of which category is in scope. The other four, availability, processing integrity, confidentiality and privacy, are selected.

So a SOC 2 covering security alone is a complete and valid SOC 2. If you assumed availability or confidentiality had been examined, you assumed something the report may say explicitly it did not cover. The scope section names the categories, and it is the first thing to read.
Then check the type. A type 1 report does not contain an opinion on operating effectiveness, nor a description of the tests performed, nor the results of those tests. No test-results section means a type 1 structurally cannot show an exception. A clean-looking type 1 is not evidence that anything works over time.
Two vocabulary tells are worth knowing. An AICPA publication states outright that compliance is a term never used in SOC 2 examinations, so a provider advertising itself as SOC 2 compliant or certified is using language the standard-setter does not. And genuine reports are restricted to specified parties with sufficient knowledge and understanding of the service organization's system, which means a real SOC 2 cannot simply be published on a website. Ask for it under NDA and read the exceptions.
What does ISO 27001 certification actually prove?
That an external body issued a certificate, and not that ISO vouched for anything. ISO is explicit: it does not perform certification or issue certificates, and an organization cannot be certified by ISO, because certification is performed by external certification bodies.
The follow-up question is who certified them. ISO notes that accreditation of a certification body is not compulsory, and non-accreditation does not necessarily mean the body is not reputable. Both halves matter. An unaccredited certifier is not automatically a bad one, and an accredited-looking certificate is not automatically vetted.
What the standard certifies is a management system, a way of running security decisions, rather than a security score. The document that says what the provider actually does is the Statement of Applicability, which lists the controls judged necessary and the justification for anything excluded. Ask for the Statement of Applicability version referenced on the certificate, and read the exclusions.
Is a certificate of insurance evidence of anything?
It is evidence that a policy existed on the day it was issued, and the form says so itself. The standard certificate states that it is issued as a matter of information only and confers no rights upon the certificate holder.
One line on that form is almost never quoted and changes how you read the numbers: limits shown may have been reduced by paid claims. A certificate showing two million dollars of cover does not mean two million dollars remains available.

Holding cover is also not the same as being paid. Across the US cyber market in 2024, the number of claims closed without payment was 28,555, nearly three times the 9,941 closed with a payment.
So the useful move is not to collect your provider's certificate. It is to check your own policy. The FTC, working with the state insurance regulators, advises businesses to ensure their own cover includes cyber attacks on their data held by vendors and other third parties.
Worth noticing what the governments do not say. The seven-nation advisory on auditing your provider does not mention insurance at all. What it asks for is contractual.
What should you actually ask?
Two governments have published the question list, which spares you writing one. The Australian Cyber Security Centre sets out five questions to ask a managed service provider, covering their own better-practice security, secure administration, monitoring, regular assessment and incident readiness. Every one is about the provider's own estate.

The UK NCSC, in guidance published in November 2025, states the principle in a sentence: check that MSPs also protect their own access to your systems, and that they have two-step verification on those credentials. It also tells you to establish what happens if the MSP is itself impacted by an incident.
Six checks cover the provider itself. Send them as a request rather than a conversation, because each one names an artefact.
- Their own MFA. Enforced on every account that can reach your systems, with no exceptions.
- Credential separation. Written confirmation that admin credentials are not reused across customers.
- Certification scope. Which systems the certificate covers, and whether yours are inside that boundary.
- Report type and findings. For a SOC 2, which categories, type 1 or type 2, and what the exceptions were.
- Their own incident notification. A clause covering events on the provider's infrastructure, not only yours.
- Their own recovery. What happens to your service if the provider is the one that gets hit.
Three requirements from the joint advisory belong in your contract rather than in a conversation. Providers should not reuse admin credentials across multiple customers, and customers should ensure contractual agreements specify this. Providers should implement MFA on all accounts with access to customer environments and treat those accounts as privileged. And contracts should require notification of confirmed or suspected security events occurring on the provider's own infrastructure and administrative networks, not only events that reach you.
How do you run this audit?
Ask for the artefacts and then read the boundaries rather than the badges. For any certification, ask which systems are in scope. For a SOC 2, ask which trust services categories were examined, whether it is type 1 or type 2, and what the exceptions were. For an ISO certificate, ask for the Statement of Applicability and the exclusions.
Treat this as recurring rather than one-off. CISA's performance goals expect that the risks posed by a managed service provider are identified, recorded, assessed, prioritized, monitored and updated over the course of the relationship. Over the course of, not at signing.
Judge the answers the way the Advanced case suggests. The failures a regulator named were patching records, vulnerability scanning and an MFA gap, all of which a customer could have asked about beforehand and none of which required technical expertise to ask.
And keep the proportion right. None of this assumes your provider is careless. It assumes your provider is a target, which it is, and that the evidence it offers means something narrower than it appears.
FAQ
Why would an attacker target my IT provider rather than me?
Because one provider is a route into many businesses. CISA states that managed service providers generally have direct and unfettered access to their customers' networks and that a compromise in one part of an MSP's network can spread globally. The US Department of Justice, charging members of the APT10 group, described attackers stealing administrative credentials from a provider and using them to move laterally through both the provider's network and its clients' networks.
Does a SOC 2 report mean a provider is secure?
It means an examination happened, over a defined scope. Only the security category is always examined; availability, processing integrity, confidentiality and privacy are selected. A type 1 report contains no opinion on operating effectiveness, no description of the tests performed and no test results, so it cannot show an exception. An AICPA publication also notes that compliance is a term never used in SOC 2 examinations, so a provider claiming to be SOC 2 compliant or certified is not using the standard-setter's vocabulary.
Does ISO 27001 certification prove a provider is secure?
It proves an external body issued a certificate. ISO states plainly that it does not perform certification or issue certificates and that an organisation cannot be certified by ISO. It also notes that accreditation of the certifying body is not compulsory. The standard certifies a management system rather than a security outcome, so the document worth reading is the Statement of Applicability, which lists the controls judged necessary and justifies any exclusions.
Is my provider's certificate of insurance worth collecting?
Only as a point-in-time record. The standard certificate states that it is issued as a matter of information only and confers no rights on the certificate holder, and that limits shown may have been reduced by paid claims. Holding cover is also not the same as being paid: across the US cyber market in 2024, 28,555 claims closed without payment against 9,941 closed with one. The FTC, with the state insurance regulators, advises checking that your own policy covers attacks on data held by vendors.
What should be in the contract rather than just discussed?
Three things from the joint advisory by CISA, the NSA, the FBI and four partner cyber authorities. That the provider will not reuse admin credentials across multiple customers. That MFA is enforced on all accounts with access to your environment, with those accounts treated as privileged. And that the provider will notify you of confirmed or suspected security events on its own infrastructure and administrative networks, not only incidents that visibly reach you.
Sources
- CISA Technical Alert TA18-276B, Advanced Persistent Threat Activity Exploiting Managed Service Providers
- UK Information Commissioner's Office, Monetary Penalty Notice, Advanced Computer Software Group Ltd (26 March 2025)
- CISA, NSA, FBI, NCSC-UK, ACSC, CCCS and NZ NCSC, Joint Cybersecurity Advisory AA22-131A (11 May 2022)
- US Department of Justice, Two Chinese Hackers Associated With the Ministry of State Security Charged (20 December 2018)
- Office of the Director of National Intelligence, NCSC, Kaseya VSA Supply Chain Ransomware Attack (10 August 2021)
- Australian Cyber Security Centre, Questions to ask managed service providers
- UK National Cyber Security Centre, Choosing a managed service provider (24 November 2025)
- AICPA Trust Services Criteria, TSP section 100 (2017), paragraphs .07, .08 and .11
- Journal of Accountancy (AICPA), Promises of 'fast and easy' threaten SOC credibility (1 February 2026)
- ISO, Certification, and ISO/IEC 27001:2022
- New York Department of Financial Services, approved ACORD 25 (2025/12) Certificate of Liability Insurance
- National Association of Insurance Commissioners, Report on the Cybersecurity Insurance Market (2025, data year 2024)
- Federal Trade Commission, Cyber Insurance, developed with the National Association of Insurance Commissioners
- CISA, Cross-Sector Cybersecurity Performance Goals 2.0
Best IT MSP is an independent directory of managed IT providers across the US and Canada. We rank on verified rating and firmographic data, we label paid placement, and we do not sell IT services.