Security maturity comes from consistently operating a sensible baseline—not buying the longest list of tools.

Protect identities first

Require multifactor authentication, remove shared accounts, protect administrators, review access regularly, and make employee departures prompt and complete.

Manage every endpoint

Keep an inventory, enforce secure configuration, patch operating systems and applications, encrypt storage, deploy managed protection, and isolate devices that fall out of compliance.

Make recovery real

Back up critical systems and cloud data where needed, protect backup administration, define recovery priorities, and test that important information can actually be restored.

Prepare for an incident

Document who investigates, who makes business decisions, how legal and insurance contacts are engaged, how employees communicate, and how access can be contained quickly.

Organize the work and assign owners

NIST CSF 2.0 groups outcomes into Govern, Identify, Protect, Detect, Respond, and Recover. Use those headings to ask where responsibilities are missing. The framework is voluntary guidance, not a certificate proving an MSP is secure. Create a working register with a business owner, operational owner, next action, due date, and evidence for each priority.

Ask for evidence of coverage, not just deployment

A tool installation count does not tell you whether every active device is reporting or whether someone investigates alerts. Request the exception list: unmanaged devices, unsupported systems, accounts without the required authentication, and failed protection jobs. For each exception, record the reason, interim control, and remediation date. Keep sensitive reports in an approved location.

Test the people and process together

Run a discussion exercise using a fictitious lost laptop or compromised mailbox. Ask who can contain it, how employees reach help, what records are preserved, and who approves external communication. Capture unanswered questions as actions. The purpose is to find gaps without creating an actual incident or exposing real credentials.

Working checklist

Multifactor authentication

Managed endpoint protection

Consistent patching

Protected and tested backups

Email security

Security awareness training

Incident-response contacts

Sources and further reading

Primary references for the topics identified below. Examples, checklists, and purchasing recommendations are editorial guidance.

About this guidance

Published by Bay Area Managed IT. Examples are illustrative; they are not provider quotes, audited results, or local market survey findings. Read our editorial approach →

Continue the research

PRICING GUIDEManaged IT pricing in the Bay Area: what drives the monthly costBUYER TOOLA practical MSP RFP checklist for small and midsize businessesTRANSITION GUIDEHow to switch managed service providers without losing control

Bring these questions to your next provider conversation.

Use a common scope and keep the evidence beside each answer.

Prepare your RFP →