Skip to content

Security

Why we will not sell you security as a tier on your support contract

Your MSP already holds every credential in the building, so letting them own security too looks like the obvious efficiency. Three things go wrong, and none of them is about competence.

8 min readComputing America

In short

  • A team assessing work it configured inherits the assumptions it made while configuring it. That is a blind spot rather than dishonesty, and no amount of skill removes it.
  • Security folded into a per-seat monthly fee is unbounded work against a fixed price, so what actually gets delivered is what fits the margin: an agent, a dashboard and a monthly report. The hours-consuming part (reading the anomaly, chasing it down, being wrong twice first) is exactly what the pricing punishes.
  • The most valuable sentence in a real incident is “stop, this is worse than it looks, take it offline”, and it is about the estate the provider built. A firm that renews annually is the worst-placed party to say it about its own work.
  • Patching, endpoint protection, tested restores, MFA and joiners-movers-leavers are operational hygiene and belong to whoever runs the estate. Adversarial testing, compliance evidence and incident response are a separate practice with separate people.
  • For a thirty-person company with no regulated customer and no compliance obligation, one vendor doing both is probably the right answer. The threshold is not headcount; it is the first time somebody outside the company asks you to prove something.

Every managed IT provider now has a security tier. It is usually the same engineers with a different line on the invoice, and the pitch for it is genuinely reasonable: we already hold every administrative credential in your building, we already see every endpoint, and adding a second vendor means paying somebody to learn what we already know. Efficiency is a real argument and that one is not a bad version of it.

We still will not sell it that way, and the reasons are worth writing down rather than asserting, because a firm declining revenue should have to show its working. None of the three is a claim about competence, the same people who patch an estate well are frequently excellent at attacking one. All three are about the position they are standing in when they do it.

One: the assessor is the assessed

The team that segmented your network decided where the boundaries go. Asked six months later to test whether the segmentation holds, they test the boundaries they drew. They are not being lazy; they are being human. Every assumption made while building a thing is invisible from inside it, which is precisely why it survived the build.

This firm applies the same rule to itself in the other direction and publishes it: our hardware engineers write device firmware, and our security practice tests it, because a team should not be the independent assessor of its own build. It would be strange to hold that line internally and then offer a managed IT client the arrangement we refuse for ourselves.

The practical version of the blind spot is duller than the principle and more common. An assessment produced by the incumbent tends to find the things the incumbent already has a fix for, because those are the things they are looking at. It rarely finds the ancient rule in the firewall that has been there since before they took over, the service account with a password set in 2019, or the third-party integration nobody has owned since the person who requested it left. Those are the findings that come from somebody with no history in the estate reading it cold.

Two: the pricing decides what gets delivered

Bundled security is nearly always priced per seat per month, alongside the helpdesk. That structure is right for support, where the work is roughly proportional to headcount and the distribution is stable: a hundred people generate about the same number of tickets this month as last.

Security work does not have that shape. Most months it is nearly nothing. Then one month it is an alert that looks wrong, and answering it properly means three engineers, a day and a half, two dead ends and a conversation with a vendor. Unbounded work against a fixed monthly fee has exactly one equilibrium, and everyone in the industry knows what it is: deliver the part that scales, and hope the other part does not arrive.

Fits the priceDoes not fit the priceWhy the second list is the one you were buying
An EDR agent deployed to every endpointSomebody reading what it flagged, on the day it flagged itThe agent is the cheap half. Alerts nobody triages are a product you own rather than a service you receive.
A monthly posture report generated from a consoleThe judgment about which two of its forty findings actually matter hereA report is generated. A recommendation is written, by a person who understands your operation and can be argued with.
An annual vulnerability scanChaining three medium findings into the thing that would actually workScanners enumerate. An attacker composes, and so does anyone testing the way one does.
A policy pack, adapted from a templateEvidence that the policies describe what the estate doesThe gap between a written control and an operating one is the entire finding in most audits.
What survives a per-seat bundle, and what does not

Read that last column and you have the reason bundled security so often disappoints without anyone breaking a promise. Everything in the left column was delivered. It is just that the left column was never the thing worth buying.

Three: somebody has to be able to say stop

The moment that decides what a security arrangement was worth is short and it is verbal. Something is wrong, the picture is incomplete, and the responsible advice is to take a production system off the network now and work out what happened afterwards. NIST SP 800-61r3 (opens in a new tab) frames response as a set of defined roles with stated authority, agreed before an incident rather than during one, and containment as a decision somebody is empowered to make. The word empowered is doing real work there: the plan has to name who can call it.

Now put that decision inside a bundled contract. The advice is expensive, disruptive, might be wrong, and it is about an estate the same firm configured, so it is close to saying we think we may have got something wrong and it is going to cost you a day of production to find out. That sentence is hard for anyone. It is hardest for the party whose agreement renews in March.

We are not suggesting providers consciously trade a client’s safety against a renewal. Almost nobody does. The point is subtler and worse: under that pressure the honest reading of an ambiguous signal drifts, slowly and invisibly, towards the interpretation that requires no disruption. A separate practice with separate people has no such gradient, and that is the entire value of the separation. It costs nothing on the good days and it is the whole product on the bad one.

Where the line actually sits

None of this means an IT provider should have no security responsibilities. Most of what keeps an ordinary business safe is operational hygiene performed by whoever runs the estate, and handing it to a specialist would make it worse, not better, because the specialist does not hold the keys or watch the queue.

Ours, because we run the estateTheirs, because assurance is the productWhy the line is here
Patching, on a schedule you can seeTesting whether the patching actually happened everywhereOne is a process. The other is a check on the process, and a process should not grade itself.
Endpoint protection deployed, updated and monitoredAdversary emulation that tries to get past itDeploying a control and defeating one are different skills and, more importantly, different incentives.
Backups running, and restores tested and evidencedWhether the backups survive an attacker who has your credentialsOperational reliability and attack resistance are not the same property, and a tested restore proves only the first.
Identity hygiene: MFA, least privilege, joiners, movers, leaversIdentity attack paths, what the third account can reach through the secondAdministering identity is a queue of requests. Attacking it is a graph problem.
Answering the security questionnaire about how the estate is runProducing the evidence a regulated customer or an auditor will testWe can describe what we do. Somebody who did not do it should be the one attesting that it happened.
Being first to notice, and containing what we canIncident response, forensics and the written findingNoticing is a byproduct of running the estate. Establishing what happened is a discipline with its own evidentiary standards.
The seam, stated the same way on both sides of it

What the separation costs you, honestly

Two vendors is two relationships, two invoices and a coordination problem that is genuinely ours to solve rather than yours. The failure mode is the one everybody has seen: a finding is delivered to you, you forward it, and it lands in a queue with no owner, no date and no way of telling six months later whether anything happened. Two parties both loosely responsible for a fix is worse than one party clearly responsible for it.

  • Findings arrive as tickets in the queue that already runs your estate, with a named owner and a date, not as a PDF you are expected to route.
  • The quarterly review has both practices in the room and the risk register on the screen, so what was found and what was fixed are read against each other rather than in two documents.
  • Anything we disagree about, you hear both sides of. A finding we think is wrong gets argued in front of you rather than quietly downgraded, which is a thing that can only happen when the two parties are not the same party.
  • Access is separate and stays separate. The security practice does not inherit our administrative credentials because we have them; it gets scoped access for scoped work, which is also the arrangement that makes its findings defensible to a third party.

When one vendor is the right answer

The argument against bundling security has a floor, and pretending otherwise would be the same overreach it is objecting to. A thirty-person company with no regulated customers, no compliance obligation and no contractual security requirements does not need two providers. It needs patching, MFA, backups that restore and somebody competent answering the phone, and paying a second firm to formally assess an estate that simple is spending assurance money before there is anything to assure.

The threshold is not headcount. It is the first time somebody outside your company asks you to prove something: a customer sends a security questionnaire with contractual weight behind it, an insurer asks what your controls actually are, a prime contractor flows down a requirement, or you have an incident and discover that what you need is not a fix but a defensible account of what happened. At that point the grade has to come from somebody who did not do the work, and the arrangement that was correct at thirty people is quietly the wrong shape.

Three questions for a provider offering both

If you are being sold a bundled security tier, by us or by anyone, these are the questions that separate a practice from a SKU. They are answerable on a first call by anyone who has one.

  1. 1.Are the people doing the security work the same people who administer our estate? If yes, what stops an assessment from testing only the parts they built?
  2. 2.Show me a finding you raised about your own configuration. Not a vulnerability in a vendor’s product, something you had got wrong and reported anyway.
  3. 3.In an incident, who decides to take a production system offline, and is that authority written down anywhere before the incident?

The second one is the tell. Every provider has a story about a serious finding; almost none has one where the finding was about their own work, and the ones that do tell it immediately, because it is the best thing they have to say about themselves.

Sources

  1. 1.SP 800-61r3: Incident Response Recommendations and Considerations for Cybersecurity Risk Management (opens in a new tab), NIST

Next step

Send us the tier sheet.

Send the page where your provider lists what each tier includes. We will mark which lines are support work, which are security claims, and which ones describe a result nobody is named against.

Reply
A person replies, not a sequence: within one business day, from someone who would be on the engagement.