The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/The Small Business Cyber Security Guy
The Small Business Cyber Security Guy artwork

If Your MSP Says ‘All Good’, Can They Prove It?

The Small Business Cyber Security Guy · 2026-06-01 · 36 min

0:00--:--

Key moments - from our scoring

Substance score

69 / 100

Five dimensions, 20 points each

Insight Density16 / 20
Originality12 / 20
Guest Caliber14 / 20
Specificity & Evidence13 / 20
Conversational Craft14 / 20

The invisibility of security work creates a dangerous buying problem: while bad IT support is immediately obvious (slow tickets, missing devices), security failures remain hidden until a breach occurs. This episode features Mitt Patel, founder of Assurerix, discussing how small business owners can distinguish between MSPs that genuinely deliver security controls and those merely claiming to. The conversation unpacks why cheap MSP quotes often hide resource gaps - patching, MFA enforcement, EDR monitoring, and backup testing aren't visible daily failures, so they're the first things under-resourced when margins are tight. Assurerix addresses this by providing live evidence integration (updating every six hours) across 64 controls: 40 cybersecurity-focused (aligned to NCSC's Cyber Assessment Framework) and 24 operational maturity metrics covering SLA delivery, onboarding, offboarding, and escalation. The framework recognizes that continuous assurance matters more than annual Cyber Essentials snapshots, since environments drift constantly. The episode also connects MSP delivery to cyber insurance claims - insurers increasingly require evidence that MFA, patching, and logging were actually in place, not just claimed. Key practical guidance includes asking for 90-day evidence trails rather than sample reports, understanding who resources proactive maintenance, and clarifying off-boarding processes and costs upfront.

Key takeaways

  • →Ask for MSP evidence over time (last 90 days of patching, backups, monitoring data), not reassurance at a single point - controls drift, so snapshots like Cyber Essentials miss ongoing gaps.
  • →Cheap MSP pricing often signals under-resourced proactive maintenance (patching, MFA coverage, alert review), not malice - the margin simply doesn't exist to fund the invisible security work.
  • →Operational maturity (fair onboarding, clear escalation, proportionate off-boarding costs, visible complaints) directly impacts security outcomes and customer protection, not just admin comfort.
  • →Before signing with an MSP, confirm they've read your cyber insurance policy requirements and can prove controls (MFA, backup restoration, EDR monitoring) are working - insurers will ask during claims.
  • →Assurerix's 64-control framework with tool integration provides continuous assurance (updated every six hours) and 30-day remediation windows, making it harder for providers to hide failures through pre-review polishing.

In this episode

  1. 1The Invisibility Problem: Why Security Gets Overlooked in MSP Decisions
  2. 2Asking for Evidence: What Good MSPs Should Be Able to Prove
  3. 3The Economics of Cheap IT: What Gets Cut When Margins Are Too Low
  4. 4Assurerix: Live Evidence and Continuous Assurance Over Time
  5. 5Operational Maturity: Fair Treatment, Clear Processes, and Proper Offboarding
  6. 6Cyber Insurance Requirements: Connecting MSP Controls to Policy Conditions
  7. 7Practical Questions for Business Owners: What to Ask Your MSP

Mentioned

AssurerixMitt PatelNational Cybersecurity CenterCyber Essentials

Guests

Mitt Patel

Topics in this episode

EDR (Endpoint Detection and Response)Patch ManagementAssurerixNCSC Cyber Assessment FrameworkCyber EssentialsMFA enforcementBackup testing and restorationCyber insurance claims requirementsMSP operational maturitySLA delivery and complaints handling

Questions this episode answers

How can a small business owner tell the difference between two MSPs quoting similar services at different prices?

Ask for 90-day evidence of specific controls: patching reports, backup restoration tests, MFA enforcement across all accounts (including exceptions), and monitoring alerts - not sample brochures or promises. Then understand who is allocated to proactive maintenance and how much time they spend on it.

Why isn't Cyber Essentials certification enough to prove an MSP is managing security properly?

Cyber Essentials is a point-in-time assessment; it shows something was in place at that moment, but environments drift constantly as users join, devices miss patches, licenses expire, and admin rights multiply. Continuous evidence over months is what matters for ongoing security health.

What should I ask about MFA to verify my MSP is actually enforcing it?

Ask whether MFA is enforced (not just available), across all users, privileged accounts, remote access, cloud services, and third-party tools - and always ask for the exceptions, who approved them, and when they'll be reviewed.

If an MSP charges significantly less than competitors, what should I suspect is missing?

Proactive maintenance: patching management, backup testing, alert review, documentation, and vulnerability tracking. At very low margins (e.g., £15/user/month), the time available may be only an hour or two monthly - something has to give, and it's usually the invisible security work.

How does an MSP's off-boarding process connect to security risk?

Poor off-boarding leaves tools installed, accounts active, admin access unclear, and documentation incomplete - creating post-exit security gaps. Off-boarding costs should be proportionate, written into the contract upfront, and not used as a hostage fee (e.g., £18,000 for 20 users is a red flag).

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

16 / 20

The episode delivers consistent, actionable insights about MSP selection and verification that would genuinely help a small business operator. The core framework - distinguishing visible service failures from invisible security gaps, demanding evidence over promises, and connecting economics to security outcomes - is substantive and non-obvious. However, the density moderates because significant runtime is spent on Assurerix's specific product mechanics and repetition of the main thesis.

Service is visible. Security is invisible. Until it fails. And then it becomes very visible indeed.
If the price is too low, the model breaks somewhere.

Originality

12 / 20

The episode takes a practical buyer-side perspective on MSP evaluation that is more grounded than typical vendor cheerleading, but the core arguments (cheap providers cut corners, ask for proof, operational maturity matters) are not particularly novel. The framing around invisible security vs. visible service is effective but not contrarian. The episode lacks fresh first-principles thinking or counterintuitive claims that would distinguish it from standard MSP accountability messaging.

Trust Me Bro isn't good enough anymore.
Everyone understands a bad help desk. Nobody needs a framework to know being ignored for four days is poor. But most buyers can't tell whether patching is current.

Guest Caliber

14 / 20

Mitt Patel is the founder/CEO of Assurerix, a company directly addressing the episode's core topic, giving him genuine practitioner credibility in MSP assurance. However, the other panelists (Morven, Graham, Corrine, Lucy) are not individually introduced with specific credentials, roles, or outcomes they've achieved, weakening the overall guest composition. Mitt's insight is competent but not exceptional - he's primarily validating the show's framework rather than bringing surprising operational experience.

Mitt Patel, founder and CEO of Assurerix.
Most providers don't set out to do things badly. They're not waking up saying they'll ignore MFA or not check patching. The issue is that if the price is too low, there may not be enough margin, time, resource or energy to manage everything properly.

Specificity & Evidence

13 / 20

The episode provides some concrete examples (£30 vs £50 vs £75 per user pricing, £18,000 offboarding fee, £150/month on 10 users) and specific control areas (MFA, patching, EDR, backup testing, admin access). However, most claims lack supporting data - no actual case studies showing MSPs that failed, no insurance claim statistics, no metrics on how often invisible security gaps cause breaches. The Assurerix framework mentions 64 controls, but specifics remain abstract. Discussion of what 'good looks like' is prescriptive but not evidence-based.

On 25 users, £35 per user is £875 a month, Ten and a half grand a year.
If an MSP charges £15 per user per month, including support, licensing and 24-7 cover, the numbers aren't merely tight, they're fantasy.

Conversational Craft

14 / 20

The host (Noel Bradford) asks genuinely useful follow-up questions and pushes Mitt on practical implications (e.g., 'what does proof actually mean in this context?', economics of underpricing). The panel structure creates natural checkpoints and different perspectives. However, the conversation is generally collaborative rather than challenging - Mitt is rarely pushed to defend a position or explain limitations. The host doesn't probe why Assurerix's 6-hour update frequency is the right cadence, or ask Mitt critical questions about adoption barriers or failure rates of the trust mark.

That phrase matters. Live evidence. Not a certificate from three years ago. Not a badge from a vendor conference.
Show me the last 90 days of patching, backup and monitoring evidence. Not a brochure, not a promise. Evidence.

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

evidence49security34show26customer24cyber24controls22provider19msps16prove15trust15patching15tools14proactive13service12small12price12

Episode notes

It starts with a slow ticket, a missing laptop and a printer staging yet another tiny rebellion - the kind of problems every small business sees and understands. But behind those visible slips is a quieter, far more dangerous story: patches that didn’t run, MFA that wasn’t enforced, backups that wouldn’t restore. In this episode Noel Bradford and a panel of experts follow a simple, devastating question: if your MSP says everything is fine, what can they actually prove? Through a sharp, practical conversation with Mit Patel, founder of Assurix, we peel back the sales decks and the polite reassurances to show how “managed IT” can mean very different things. Mit explains the difference between promises and live evidence - not certificates from three years ago, but ongoing proof that patching, EDR, backups and identity controls are working over time. Graham brings the arithmetic that spoils the cheap quote, Corinne maps the attacker’s path, and Lucy explores the trust problem buyers face when asked to pick a provider with almost no usable evidence.

Full transcript

36 min

Transcribed and scored by The B2B Podcast Index.

Here is the problem with IT support. Bad service is visible. You notice the slow ticket, the missing laptop and the printer staging another small rebellion. But security is invisible.

You don't know where the patches ran, MFA is enforced, EDR is healthy or backups would actually restore. Which means two quotes can both say managed IT support and hide completely different levels of risk. So today we're asking one question. If your MSP says everything is fine, what can they prove?

Because trust me isn't an assurance framework. Welcome back to the Small Business Cybersecurity Guy. I'm Noel Bradford. Today we're following up on our recent episode about cheap IT support, hidden risk and the dangerous fantasy that every managed service provider is basically selling the same thing.

More than. This whole thing started with a cheap quote and a very simple question. What's missing? Usually the boring useful stuff.

The quiet work. The things nobody notices until the business is on fire and someone starts asking for reports that don't exist. Graham's here as well, because somebody has to bring the maths and spoil the sales brochure. Happy to help?

Basic back of an envelope maths tends to survive contact with the sales deck. Karine's here to look at the controls, the threat path, and what attackers actually care about. Which is simple. They don't care whether your MSP sounds confident.

They care whether the door opens. And Lucy's here for the trust problem, because buyers get asked to make high-risk decisions with very little usable evidence. Exactly. Most small businesses don't need more jargon.

They need proof they can understand. And joining us today is Mitt Patel, founder and CEO of Assurerix. Mitt, welcome. Thanks, Noel.

It's great to be here. For listeners who don't know Assurerix, give us the plain English version. What does it do? Assurerix is a live evidence trust mark for MSPs.

It helps good MSPs prove they're doing the right things. There are providers doing strong work, but customers can't always see it. As Shurek turns that work into evidence. That phrase matters.

Live evidence. Not a certificate from three years ago. Not a badge from a vendor conference. Not a framed award from a hotel ballroom where the judging criteria involved a sponsorship check and a keynote slot.

Cybersecurity by Buffet Chicken. I've been to enough of those dinners to know what you mean. The important part is trust. Most small businesses aren't choosing an MSP with deep technical knowledge.

They're choosing from quotes, meetings, reputation, and whatever they can make sense of. And when you can't understand the difference, price becomes the comparison tool. Which is how security controls become invisible until something fails. In our conversation, you made a point that should sit at the center of this episode.

You said service is visible, but security is invisible. Can you unpack that? Yes. If an MSP doesn't respond to your ticket, doesn't pick up the phone, or doesn't set up a new user when needed, the customer feels that pain.

That's visible. But security is different. The customer doesn't always know whether patching is happening, whether MFA is enforced, or whether the tools installed to protect them are actually working. Annoyingly neat.

Isn't it just…. Everyone understands a bad help desk. Nobody needs a framework to know being ignored for four days is poor. But most buyers can't tell whether patching is current, whether backups restore, whether MFA exceptions exist, or whether alerts are being reviewed.

Attackers exploit the invisible part. They don't care whether your MSP has good phone manners. They care whether the door opens. The invoice can be charming.

The attack surface doesn't care. That's today's episode. We're not here to say all cheap MSPs are evil. We're not here to say every expensive MSP is good.

That would be lazy and plainly rubbish. I agree. A lot of providers are trying to do the right thing. The problem is often that the buyer can't tell who's genuinely doing it and who's just saying the right words.

So we're here to ask a better question. What can your MSP prove? Let's start with the buyer problem. So Mitt, when a small business owner is looking at two or three MSP quotes, what makes that decision hard?

The issue is that many SMEs don't know all the things that need to be done. They rely on the IT provider for advice. But if three providers say similar things, the buyer often can't tell the difference. So it can come down to price.

Which isn't really buying. It's guessing with a purchase order. Guessing, but with payment terms. And this is where economics and risk collide.

If one provider is much cheaper, the buyer sees the saving today. They don't see the work that may have been removed. They also don't see the future incident path. Missing patching, weak MFA, poor alerting, failed backups, or unmanaged admin access may sit quietly for months.

Until they don't. Exactly. You said in the interview that customers can see bad service, but the security side is hidden. How should an owner spot the difference without becoming a cyber expert?

Great question. They should ask for evidence. If the MSP says they patch machines regularly, ask what they show to prove that. If they say controls are in place, ask how those controls are monitored.

It doesn't mean the customer has to become technical. It means the provider needs to explain and prove it clearly. That's the core. The burden shouldn't sit entirely with the customer.

Exactly. A good provider should make the evidence usable, Not dump a technical export on the customer and hope they go away. Ah, the classic transparency by exhaustion model. It happens.

Here is a dashboard. Here are 16 tabs. Here are 400 lines of device data. Good luck.

Evidence has to be clear enough to support decisions. The customer needs to know what's healthy, what's not healthy, what's accepted risk, and what needs action. That's right. The goal isn't to overwhelm the customer.

The goal is to show what good looks like and whether it's happening. Let's make this painfully practical. A business gets three quotes. One is £30 per user.

One is £50. One is £75. All say managed IT support. All say cyber security.

All say proactive. What should the owner ask? Ask what's included in the price and what's excluded. Ask how much proactive work is resourced.

Ask who does it. Ask whether MFA is enforced, whether patching is reported, whether backups are tested, and whether EDR is monitored. Ask what happens when something goes wrong. Who escalates?

Who owns the problem? Who talks to leadership? What's written down? Ask to see something from the last 90 days, not a sample report from a pretend customer called Contoso Plumbing.

Ask for proof over time. A single moment can look fine. What matters is whether the provider can show that controls are being managed continuously. That's the first takeaway.

Don't compare MSPs by label. Compare them by evidence. Okay, Mitt, in your marketing material, Assurrix uses the phrase proof, not promises. It's a good phrase because it cuts through the fog.

What does proof actually mean in this context? It means the MSP can show evidence that the work is being done. If they say patching is happening, there should be patching evidence. If they say SLAs are being met, there should be service data.

If they say security controls are in place, there should be live evidence from the tools they use. A statement isn't evidence. A proposal isn't evidence. A policy isn't evidence unless it connects to real activity.

Evidence should show whether a control exists, whether it's working, and whether someone responds when it fails. And it should be understandable enough for a business owner to use. If it looks like it was designed to make the reader surrender, it's not good evidence. Nothing says trust like a 300-page export called Final Report v7, really final.

With 15 columns named status. And one says unknown. Cyber essentials came up when we spoke. We like cyber essentials.

We talk about it a lot, but you made a fair point about point-in-time assurance. Cyber essentials is a good thing. It's useful for businesses. The limitation is that it tells you something was in place at the time of assessment.

It doesn't prove those controls are still in place next week, next month, or three months later. That's a key operational reality. Environments drift. Users join.

Users leave. Devices miss patches. Backup agents fail. Licenses expire.

Tools break. Exceptions get created. Admin rights multiply in cupboards. They do.

So the buyer needs ongoing assurance, not a once a year reassurance ritual. Let's put examples on this. If an MSP says MFA is covered, what does proof look like? It should show enforcement, not availability.

Coverage across users, privileged accounts, remote access, cloud services, third-party tools. It should show exceptions, who approved them and when they'll be reviewed. Patching. Patch compliance over time.

Critical missing patches. Failed installations. Devices not checking in. Servers excluded from normal patch cycles.

Remediation activity. Age of outstanding issues. Operational evidence. Escalation paths.

SLA performance. Complaint handling Onboarding process Offboarding process Named responsibility Customer visibility Not just We're lovely people, trust us The nice people defence remains popular And good MSPs are often doing many of these things already The issue is that they don't always explain it well Or have a simple way to prove it to the customer Which Matters commercially Because if you can't show why your service costs more The buyer sees only the price difference And The cheaper provider benefits from the customer not knowing what has been omitted.

That's the second takeaway. Ask for evidence over time, not reassurance at a single point in time. Mitt, let's talk about Asurix itself. You've 64 controls.

What are they covering? Yes, there are 64 controls in total. 40 focus on cybersecurity. 24 cover operational maturity and delivering good outcomes for SMEs.

The cybersecurity side aligns to the National Cybersecurity Center's Cyber Assessment Framework. The operational maturity side looks at things like SLA delivery, onboarding, offboarding, escalation and complaints. On the cyber side, what kind of areas are we talking about? As you would expect, governance, managing security risk, protecting against cyber attack, detecting cyber security events and minimizing impact.

That includes identity and access control, data security, incident response, recovery planning and similar areas. And you're not just asking MSPs to tick a box. No, we integrate into the tools they use, for example, remote management tools, patching and vulnerability management tools, service platforms, and other systems. That gives live evidence rather than only self-reported answers.

We update the status every six hours. So it is a real living and breathing thing. That's the bit that makes this different from another badge. The channel does enjoy a badge, especially one that can sit on a website footer next to six others nobody understands.

True, but the point here is that the badge should mean something. It should be backed by evidence. Tool integration matters because security quality loves and behavior over time. Explain that.

A single green report doesn't prove much. A pattern over weeks and months is stronger. It shows whether controls remain healthy. It shows whether the MSP notices failures.

It shows whether issues are remediated. It also shows operational discipline. Anyone can tidy up before a review. Continuous evidence makes the tidy-up fear harder.

The ceremonial polishing of the compliance crockery. And that matters for buyers. If an MSP can show a history, the customer doesn't have to rely only on sales confidence. What happens if an MSP falls below the standard?

If they don't deliver on required controls, we give them 30 days to remediate. If they don't remediate, we suspend the trust mark. That's the accountability piece. And it recognises reality.

Good providers can have issues. Tools fail. Processes drift. The important question is whether they detect and fix the issue.

Perfection isn't the standard. In fact, Noel often says perfection is the enemy of good security. Visibility, control, and response are the standard. Everyone drops plates.

Good providers notice before the floor becomes crockery gravel. You've been waiting to use that line. I keep a list on my phone. For a good MSP, how does this help them defend premium pricing without sounding defensive?

It helps them show what they're already doing. If an MSP is doing the right things, independent evidence makes that easier to explain. It turns the conversation away from price alone and toward outcomes, controls and trust. That's important.

Mature delivery costs money. If a provider can't show why, the buyer sees only the gap between quotes. And the cheapest provider wins the confusion. Third takeaway, a badge without evidence is decoration.

Evidence over time is what matters. Let's do the bit everyone likes to avoid. The economics. Nothing makes a room sparkle like gross margin.

It matters. If the price is too low, the model breaks somewhere. In the previous episode, we talked about MSPs being £30 to £40 per user per month cheaper than a security-focused provider. On 25 users, £35 per user is £875 a month, Ten and a half grand a year.

The saving is visible. The removed control isn't. To Met, you made a generous point when we spoke. You didn't say low-cost providers wake up wanting to fail.

What did you mean? Most providers don't set out to do things badly. They're not waking up saying they'll ignore MFA or not check patching. The issue is that if the price is too low, there may not be enough margin, time, resource or energy to manage everything properly.

That's the line. Arithmetic, the cruelest auditor. If an MSP charges £15 per user per month, including support, licensing and 24-7 cover, the numbers aren't merely tight, they're fantasy. Tolkien with a ticketing system.

Suppose a 10-user business pays £150 a month. If the fully burdened cost of engineering time is around £50 an hour, that buys three hours before the provider makes no margin. If the provider aims for a normal margin, the time available may be closer to an hour and a half a month. To support 10 users, answer tickets, set up users, patch machines, check backups, review alerts, manage change, maintain documentation, give advice, and somehow remain sane.

Exactly. Something has to give. And what gives is usually proactive work. Because reactive work screams.

Incidents scream. New starters scream. You also talked about how resource should split inside an MSP. Talk us through that.

Usually, you've got people dealing with incidents, people dealing with change requests, and then a third area for proactive maintenance. In smaller or lower margin MSPs, that proactive area can be the easiest one not to resource properly because customers notice incidents and change requests first. And that proactive bucket is where a lot of the security value sits. Agent health, patch failures, backup errors, MFA coverage, risky sign-ins, privileged access, documentation, vulnerability trends.

It's also the part the customer doesn't see. Invisible security meet invisible staffing. For an SME buyer, what should they ask here? Ask who does proactive maintenance.

Is it a dedicated role? Is it part of someone's role? How much time is allocated? And what evidence do they provide that is happening?

That should be in every MSP selection meeting. It also moves the conversation away from monthly price and toward actual delivery capacity. Which is where it should have been all along. Fourth takeaway, cheap IT is often not malicious.

It's under-resourced and under-resourced security is still dangerous. If this episode is already making you slightly uncomfortable, good. Not because panic helps, it doesn't. But better questions do help.

Ask your MSP what they can prove. If they answer clearly, lovely. If they start fogging the room, open a window. Subscribe to the Small Business Cybersecurity Guide for practical cybersecurity without vendor doom, compliance theatre or men in hoodies staring at glowing laptops.

The hoodies are innocent. It's the glowing laptops I don't trust. Let's move into insurance because this is where the invisible work can become very visible very quickly. Cyber insurance isn't a magic recovery fund.

It comes with conditions. The monthly payment leaving your bank account isn't the same as being claim ready. Exactly. If your policy says MFA must be in place and MFA isn't enforced, you may have a problem.

If your policy expects patching evidence, vague reassurance won't help. If you said controls existed when they didn't, that can become an ugly conversation. And that conversation happens when the business is already under pressure. Which is the worst possible time to discover your evidence doesn't exist.

Are insurers becoming more interested in MSP evidence? Yes. Insurers are becoming stricter about evidence. With insurance, the devil is in the detail.

If the insurer asks for MFA to be on all the time and it's not in the event of a claim, you know what can happen. And as claims rise, scrutiny rises. That's normal market behaviour. MSP delivery and cyber insurance are joined together.

Conjoined paperwork twins. Business owners need to stop treating insurance and IT as separate purchases. Your MSP should understand what your cyber insurance requires. They should map policy requirements to controls, MFA.

Backup, patching, logging, EDR, incident reporting, asset management, admin access. They should also know incident notification windows. Some policies require notification inside a fixed period. If detection is slow, the business may already be behind.

You mentioned continuous assurance in relation to insurance. Why does that matter? The market is moving toward continuous assurance. If the MSP can show evidence that controls were in place and working, that helps demonstrate that they were doing what they said they were doing.

That can matter during underwriting and during a claim. Nobody should want a claim process based on memory, screenshots taken after the fact, and a director trying to remember which meeting covered MFA. The official minutes say someone nodded near a spreadsheet. Evidence reduces ambiguity.

And ambiguity is expensive. Fifth takeaway, ask your MSP whether they've read your cyber insurance requirements. Then ask what evidence they can provide if you need to make a claim. This could have been a pure cyber controls episode.

MFA, patching, backups, EDR, logging, all the usual suspects. Cyber security bingo. But Assurex also looks at operational maturity. Which matters because a good MSP isn't just secure.

It should be fair, clear, accountable and professionally run. What does operational maturity mean in your framework? It's about good outcomes for SMEs. we look at things like complaints being visible at board level, fair onboarding and offboarding, escalation processes, SLA delivery, and making sure the customer knows who to go to when there's a problem.

That's not boring. That's customer protection. It's also security relevant. Bad offboarding can leave tools installed, accounts active, admin access unclear, and documentation incomplete.

Bad operations create bad security outcomes. And sometimes a hostage situation with a ticket number. You gave an example when we spoke about an MSP trying to charge a fairly ridiculous off-boarding fee. Yes, I heard of an MSP trying to charge £18,000 to off-board a 20-user customer.

That's not fair or proportionate. There's work involved in off-boarding, but it shouldn't be that amount for that size of customer. £18,000 to off-board 20 users. That's not an exit process.

That's a hostage note with VAT. Probably called professional services. Almost certainly. Let's be fair.

Offboarding is real work. Access must be transferred. Tools removed. Documentation handed over.

Passwords reset. Admin roles reviewed. But the process should be written down, proportionate, and known before the contract is signed. Transition is a security risk.

Domain access, DNS, tenant admin rights, backup ownership, EDR tools, RMM tools, firewalls, mail security, and identity roles all need clean handling. And if the MSP uses off-boarding as punishment, that tells you a lot about their maturity. That's the point. A small number of poor behaviours can damage trust in the whole industry.

Good MSPs shouldn't be dragged down by that. Complaints matter too. If complaints never reach leadership, the provider can't learn. If escalation paths are unclear, the customer ends up shouting into a shared mailbox.

The shared mailbox. Where urgency goes to become archaeology. You also talked about why customers switch MSPs. What are the common reasons?

Often it's service issues, not getting the right advice, not seeing value for money, confusing bills or some type of incident. They lose trust and then need to find a new provider without ending up in the same position again. That's the real buyer question. How do I avoid making the same mistake again?

Not who has the prettiest proposal. Not who says proactive most often. Not who's cheapest. Who can prove they're mature enough to protect the business?

Sixth takeaway, operational maturity is an admin fluff. It's part of whether the customer gets protected, treated fairly, and supported properly. business owner listening to this, you don't need to become a cyber security expert by Friday. Nobody wants that.

Cyber security experts barely want that. True, but you do need to ask better questions. And ask them calmly. This isn't about storming into a meeting and accusing your provider of being useless.

Tempting though that maybe in some cases. It's about saying, we're reviewing our risk and we want to understand what evidence we have. So let's go round the table. One question each.

Morven. Who owns proactive maintenance in your business? And how much time do they spend on it? If the answer is everyone keeps an eye on it, I'd start twitching.

Graham. Show me the last 90 days of patching, backup and monitoring evidence. Not a brochure, not a promise. Evidence.

Corinne. Is MFA enforced everywhere, especially for admin accounts, remote access, cloud services, and third-party tools? Also, show me the exceptions. Always ask for the exceptions.

That's where optimism goes to die. Lucy. If we leave, what's the off-boarding process? What will it cost?

What will be handed over? And where's that written down? And the guest of honor, Mitt. Ask what proof the MSP can show that they're doing what they say they're doing.

If they say they patched systems, ask for the evidence. If they say controls are in place, ask how those controls are checked over time. Mine is simple. What can you prove?

That's it. Not what can you promise. Not what can you imply. Not what looks good in the sales deck.

Not what the account manager says with a confident smile and a nice fleece. The fleece isn't an assurance framework. Correct. The fleece isn't an assurance framework.

I'd add one commercial question. How does the provider make enough margin to deliver the service properly? That's a strong question. If the price is far below market, ask what's included, what's not included, and how proactive work is resourced.

Because underpriced security becomes under-maintained security. For MSPs listening who are tired of losing to cheaper providers, what should they do? Show evidence, educate the customer on why it matters. If you're doing the right things, make that visible.

That gives the customer a better basis for trust than price alone. Don't expect buyers to understand your value if you hide the work. Quiet competence is lovely. Quiet evidence is less useful.

Mature MSPs need to explain the operating model. Tooling, people, process, governance, reporting, remediation. And they need to show control health in a way the customer can use. That's the market gap.

Good MSPs need a way to prove good work. SMEs need a way to know who to trust. Insurers increasingly want evidence and cyber security is no longer something you can handle with a handshake and a hopeful invoice. I feel hopeful invoice should be a recognised accounting category.

It's not. Shame. Let's finish the main discussion by describing what good looks like. Because the answer isn't panic.

It's not sack your MSP this afternoon. It's not buy the most expensive quote and assume the cyber gods will behave. They'll not. They're famously moody.

Good looks like clear scope. The customer understands what's included, what's excluded, what's optional and what remains their responsibility. Good looks like enough margin to deliver the service. The provider has the people, tools, and process to do reactive work and proactive work.

Good looks like enforced controls. MFA. Patching. EDR.

Backup testing. Logging. Alert response. Vulnerability management.

Admin access control. Good looks like evidence that normal people can read without needing a nap and a biscuit. Good looks like accountability. Escalations are named.

Complaints are seen by leadership. SLAs are reported. Offboarding is fair. Good looks like trend data.

Not just one green report, but a pattern over time. Good looks like exceptions being managed, not hidden, managed. Mitt, anything you'd add? Good looks like the MSP being able to show the outcome.

If they're delivering patching, security controls, SLA performance, and good operational practice, they should be able to show that. It's about making good work visible. That's what small businesses should expect. Not perfection.

Visibility. Not magic. Evidence. Not blind trust.

Accountability. From a threat perspective, that's what makes the difference between a minor incident and a business crisis. From a financial perspective, it's the difference between controlled spend and uncontrolled loss. From a governance perspective, it's the difference between informed decision making and hoping the nice IT people have it covered.

Hope remains a terrible control. Always has been. So, if you're an SME, ask the questions, who owns proactive maintenance? What evidence can you show?

Is MFA enforced? Are backups tested? Are patches reported? Have you read our cyber insurance requirements?

What happens if we leave? What does the escalation path look like? How do you prove this over time? If the provider welcomes those questions, that's a good sign.

If they become defensive, vague or patronising, That's also useful information. Not useful in a comforting way, but useful. Good providers shouldn't fear evidence. They should already be using it to run the service.

The aim is to back good MSPs to win. If they're doing the right things, they should be able to show customers what good looks like. And will give customers old and new some extra confidence. And that's probably the fairest place to land.

So, let's land this. Cheap IT isn't always malicious. Sometimes it's just under-resourced. But under-resourced security can still hurt you.

A provider can't deliver unlimited support, strong cyber security, proactive maintenance, proper documentation, backup testing, monitoring, evidence, and mature governance from a fantasy price. If the controls are missing, attackers don't care whether the saving looked good on a spreadsheet. And if the evidence is missing, insurers, regulators, boards and customers may not be especially sympathetic later. The important question is always, what can you prove?

An MSP might say they patch monthly, monitor continuously, test backups regularly, document incidents properly. Fine. Show the logs, show the test results, show the ticket history. Because if it isn't recorded, auditable and repeatable, it didn't happen in any way that protects the customer when something goes wrong.

Good MSPs don't fear that question. They build systems around answering it. And small businesses should stop accepting reassurance as a substitute for evidence. That's the episode.

Service is visible. Security is invisible. Until it fails. And then it becomes very visible indeed.

If you run a small business, ask your MSP what they can prove. Not what they believe. Not what they assume. Not what the sales proposal said.

Not what Dave from IT reckons is probably fine. Remember Trust Me Bro isn't good enough anymore Poor Dave. He has had a difficult series He Brings it on himself, ask for evidence Ask. For the last 90 days Ask For the exceptions Ask for the exit process Ask How the work is proven over time Ask who owns the quiet work And if you're an MSP doing the work properly, show it Because good providers shouldn't be losing to cheap quotes That remove the very controls customers need most Mitt, thank you for joining us.

Thanks for having me. It has been a great conversation. Been listening from close to the beginning. And thanks to Morven, Graham, Corrine and Lucy.

Always a pleasure to ruin someone's cheap quote. With arithmetic. And control evidence. And a basic sense of fairness.

That feels like a complete framework. I think it does. If this episode helped, share it with a business owner who thinks all MSPs are basically the same. Share it with an MSP who's tired of proving value to buyers who have only been taught to compare price.

And share it with anyone who still thinks cyber security can be handled by hope. a help desk, and a monthly invoice. I'm Noel Bradford. This has been the Small Business Cyber Security Guy.

Ask better questions, demand better evidence, and don't buy IT support like its own brand beans. Especially not the value range. See you next time. Right, before we let you go completely, let's have a quick chat about the boring but necessary legal bits.

Don't worry, I'll make this as painless as possible. First up, and this is important, everything we've said represents our own personal opinions and experiences. These views are ours alone and don't represent any organisation we work for, any employers, advertisers, sponsors or anyone else who might be connected to the show. When we're giving you advice or sharing our thoughts, that's coming from us as individuals, not speaking on behalf of anyone else.

Everything we've talked about today is for general guidance. It's meant to point you in the right direction, but it absolutely shouldn't be treated as professional advice tailored specifically to your business. Your situation is unique. What works brilliantly for a Birmingham bakery might be completely useless for a Manchester marketing agency.

We do our very best to keep everything accurate and current, but let's be honest here. The cyber security world moves faster than a caffeinated squirrel being chased up a tree by Marvin's Jack Russell. Things can change between when we record and when you're listening, so always double-check critical, technical details with qualified professionals before you go making major changes to your systems. If we've mentioned any websites, products or services, we're giving you information, not necessarily giving them our seal of approval.

We can't be responsible for what happens on their end or if things go sideways when you use them. Some things we recommend might involve affiliate partnerships. We'll always flag those when they come up because transparency matters. Now, if you're dealing with serious cybersecurity incidents, actual data breaches or gnarly legal compliance issues, please talk to proper professionals rather than just relying on podcast advice.

We're here to educate and help you understand the landscape, not to replace your security consultant, solicitor or IT team. This has been a Small Business Cybersecurity Guy production, Copyright 2025, all rights reserved.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • How Danny Jenkins Bootstrapped ThreatLocker From $150K Debt to $200MThe SaaS Podcast · on EDR (Endpoint Detection and Response)87 / 100
  • Decoding the Cybercriminal Mindset, with Ryan ChapmanThe Cyber Insider · on EDR (Endpoint Detection and Response)85 / 100
  • Episode 125: Origins of MITRE ATT&CKThe Azure Security Podcast · on EDR (Endpoint Detection and Response)84 / 100
  • Rethinking Security Analytics with In-Place Intelligence, CEO of Vega, Shay SandlerShift AI Podcast · on EDR (Endpoint Detection and Response)82 / 100
  • Stop 90% of Ransomware Attacks with Basic Cyber HygieneThe Backup Wrap-Up · on Patch Management82 / 100
  • Anthropic’s Mythos and the Future of Vulnerability Management | Interview with Thom LangfordSecure & Simple · on Patch Management78 / 100

More from The Small Business Cyber Security Guy

All episodes →
  • The Open Book Problem 5: Closing it with Practical Defences for Small Businesses75 / 100
  • The Open Book Problem 1: How Your Public Records Become an Attackers' Roadmap90 / 100
  • The Firewall Fallacy: Fortinet, KEVs and the Cost of Complacency79 / 100
  • Erased from the Web: The Fight Over a Child's Moment58 / 100
  • Birthday Audit: Brutal Lessons for Small Business Cybersecurity64 / 100
All The Small Business Cyber Security Guy episodes →