← All Blogs

Who Else Can Reach Your Data? Auditing Your MSP's Subcontractors

Your IT provider almost certainly uses subcontractors, and your contract probably permits it silently. Regulatory duties attach to the data rather than to the company you signed with, so they follow it downstream. Seven questions map the chain behind your provider.

Concentric rings showing the business, its provider, subcontractors and their subcontractors
Concentric rings showing the business, its provider, subcontractors and their subcontractors
Key takeaways
  • Silence about subcontracting is permission, not prohibition.
  • HIPAA business associate status extends to subcontractors handling the data.
  • The FTC Safeguards Rule caps retention at two years after last use.
  • Get one sentence making your provider responsible for its whole chain.
  • Require notice of any change of ownership or leadership.

Who else can reach your data through your MSP?

More parties than your contract names, in most cases. A managed IT provider routinely uses a remote monitoring platform, a backup vendor, a security operations partner, an offshore night shift and a handful of independent contractors. Each one is a party you did not select, and several can reach your systems.

This is not a scandal. It is how the industry is built, and a provider with good partners delivers better service than one trying to do everything alone. The problem is only that most customers have never been told who is in the chain, so nobody has checked.

Concentric rings showing the business, its provider, subcontractors and their subcontractors
Concentric rings showing the business, its provider, subcontractors and their subcontractors

Seven questions map the chain. Ask them in one email and file the answers, because this is the audit most likely to surprise you.

Can your provider subcontract without telling you?

Usually yes, unless your agreement says otherwise, because contract law's default runs toward delegation rather than against it. The Uniform Commercial Code, which governs sales of goods rather than services, states the principle plainly: it permits a party to perform its duty through a delegate unless otherwise agreed.

A contract that says nothing about subcontracting is not a contract that forbids it
A contract that says nothing about subcontracting is not a contract that forbids it

A services agreement is not governed by that section, so the operative point is not the citation but the shape of the default. Silence is not a prohibition. If your agreement does not address subcontracting, assume it is permitted and go looking for the clause rather than assuming one exists.

There is a drafting trap here worth knowing. The same section construes a prohibition on assignment of the contract as barring only delegation of the assignor's performance, which is a reminder that assignment and delegation are different things. A clause blocking one does not automatically block the other, so a contract that forbids assignment may still leave your provider free to hand the work to somebody else.

Which of your obligations follow the data downstream?

Most of them, and this is the part businesses get wrong. Regulatory duties attach to the data, not to the company you happen to have signed with, so they keep travelling after your provider passes the work along.

HIPAA obligations follow protected health information down to subcontractors
HIPAA obligations follow protected health information down to subcontractors

HIPAA is the clearest illustration. Business associate status extends to subcontractors that create, receive, maintain, or transmit protected health information, and a business associate must ensure subcontractors agree to the same restrictions and conditions that apply to it. Your provider's subcontractor is therefore bound by the same terms as your provider, whether or not anyone has papered it.

Ask for evidence rather than assurance. The question is whether a signed agreement exists between your provider and each subcontractor carrying those terms through, and whether your provider can produce it.

Where does your data physically sit, and for how long?

Ask for the countries and the retention periods together, because the two questions have one answer. Backups replicate to regions, support desks operate from wherever staff are, and neither fact usually appears in a service description.

The FTC Safeguards Rule requires secure disposal of customer information within two years of last use
The FTC Safeguards Rule requires secure disposal of customer information within two years of last use

Retention is where quiet non-compliance accumulates. The FTC Safeguards Rule requires secure disposal of customer information no later than 2 years after its last use, and a copy sitting in a subcontractor's archive is still your customer information. HIPAA adds a harder line at the end of a relationship, requiring a business associate contract to mandate return or destruction of all protected health information at termination, with no copies retained.

The practical question is whether anybody has ever asked a subcontractor to delete anything, and whether they confirmed it in writing.

Who is answerable when a subcontractor causes the problem?

Your provider should be, and the contract should say so in those words. Without that clause you may find yourself in a dispute about whose employee made the change, at the exact moment you need somebody to fix it.

CISA's framework tells customers to obtain documentation of the MSP's responsibility for any actions performed by subcontractors or independent consultants. One sentence accepting responsibility for its whole chain is worth more than a long list of the chain's certifications.

The advisory explains why the chain matters at all. Threat actors can use a vulnerable provider as an initial access vector to multiple victim networks, with globally cascading effects, and it asks providers to understand their own supply chain risk and manage the cascading risks it poses to customers. Cascading is the operative word. Risk arrives through the chain, so accountability has to travel back along it.

How do you find out who is actually in the chain?

Ask, in writing, and use a standard question set rather than inventing one. CISA notes that the ICT Supply Chain Risk Management Task Force published a Vendor Supply Chain Risk Management Template offering standardized questions for vendors and customers, which spares you drafting and spares your provider a bespoke questionnaire.

Two artefacts turn the answers into something checkable. Customers should obtain a Software Bill of Materials or similar verification of the security of any software the MSP will use to provide its services, and organisations can require self-attestations from MSPs to validate the use of industry standards and best practices, maintained by continuous monitoring processes and tools.

Then set the standing expectation. Customers should set clear network security expectations with their MSPs and understand the access their MSP has to their network and the data it houses, which is the sentence to quote if anyone suggests this is an unusual request.

What changes if your provider is acquired?

Potentially everything, and you may not be told. Managed IT is a consolidating industry, and acquisition changes who employs your engineers, which platforms your account runs on, and which subcontractors appear in the chain.

CISA asks customers to secure notice in advance. Obtain confirmation that the individual signing for the MSP is responsible for the product's security or service, and a requirement to notify the customer of any change of MSP ownership or leadership. That notification clause is cheap to add and almost never present.

The same framework points at the quieter version of this risk. Organisations must account for risks to the vendors themselves, as vendors' financial health and other attributes can serve as indicators of potential future service disruptions. A provider in difficulty degrades before it fails, usually by losing the engineers who knew your estate.

How do you close the gap in your contract?

Four clauses cover it, and none of them is controversial to a provider that is already running its chain properly. Ask for a current list of subcontractors, prior notice before a new one is added, an express statement that your provider is responsible for their acts, and notice of any change of ownership or leadership.

Seven questions to ask about your provider's subcontractors
Seven questions to ask about your provider's subcontractors

Treat this as governance rather than security alone. CISA advises that all organisations proactively manage ICT supply chain risk across security, legal and procurement groups, using risk assessments to identify and prioritize the allocation of resources. The legal and procurement halves are what turn the findings into clauses.

Then repeat it on a schedule. Customers should understand the supply chain risk associated with their MSP, including risk associated with third-party vendors or subcontractors, and that chain changes without anybody telling you. Once a year, and again whenever your provider announces something.

FAQ

Can your MSP use subcontractors without telling you?

Usually yes, unless the agreement says otherwise. Contract law's default permits a party to perform its duty through a delegate unless otherwise agreed, so silence in your contract is permission rather than prohibition. Note also that assignment and delegation are separate concepts, so a clause forbidding assignment of the contract does not necessarily stop your provider handing the work to somebody else.

Do HIPAA obligations apply to your MSP's subcontractors?

Yes. Business associate status extends to subcontractors that create, receive, maintain or transmit protected health information, and a business associate must ensure its subcontractors agree to the same restrictions and conditions that apply to it. The duties attach to the data rather than to the company you signed with, so they continue to travel each time the work is passed along.

How long can a subcontractor keep your data?

Under the FTC Safeguards Rule, covered businesses must securely dispose of customer information no later than two years after its last use, and a copy held in a subcontractor's archive is still your customer information. HIPAA is stricter at the end of a relationship, requiring business associate contracts to mandate return or destruction of all protected health information at termination with no copies retained.

What should you ask your MSP about its supply chain?

Seven things: the list of subcontractors and platforms touching your account, whether the contract permits adding more without notice, which regulatory obligations follow the data downstream, what each party can actually reach, where the data physically sits, who is answerable when a subcontractor causes an incident, and what you are told if your provider is acquired. CISA's ICT Supply Chain Risk Management Task Force publishes a standard vendor question template you can use instead of drafting your own.

Should you be worried that your MSP uses subcontractors?

Not by itself. Specialist partners for monitoring, backup and security operations usually mean better service than a provider attempting everything in-house. The risk is unexamined rather than inherent. What matters is that you know who is in the chain, that your provider accepts written responsibility for their actions, and that your regulatory obligations have been carried through to them in signed agreements.

Sources

Compare managed IT providers in your city

Best IT MSP is an independent directory of managed IT providers across the US and Canada. We rank on verified rating and firmographic data, we label paid placement, and we do not sell IT services.

Browse Vetted Providers

← All Blogs