
Valueprops · 2026-04-08 · 17 min
Key moments - from our scoring
Substance score
58 / 100
Five dimensions, 20 points each
The traditional MSP model of 2016 focused primarily on keeping systems running and responding to tickets, but this approach no longer meets 2026 requirements. Today's buyers expect security embedded as foundational infrastructure rather than an optional add-on, compliance awareness across SOC 2, ISO, HIPAA, and PCI standards, and genuine business risk understanding - not just system management. Walid emphasizes that a single security incident can destroy brand reputation, downtime impacts globally distributed teams, and customer audit requirements now drive IT decisions. The episode walks through seven concrete vetting questions: identity governance implementation, backup testing frequency, ransomware response protocols, infrastructure documentation practices, business impact measurement beyond ticket closure, 24/7 escalation processes (follow-the-sun support), and compliance audit support. AI is framed as a force multiplier for technicians - automating repetitive work and improving response times - but human judgment remains essential. The ideal 2026 MSP combines security-first design, industry-specific compliance expertise, AI-assisted operations with human oversight, transparent reporting, proactive monitoring, and genuine business alignment. This positions MSP selection as a strategic risk decision, not a cost-center purchase.
The seven questions are: How do you handle identity governance (IGA products)? How often do you test backups and restoration? What is your ransomware response protocol? How do you document infrastructure and manage changes? How do you measure business impact beyond ticket closure? What is your escalation process for 24/7 support? How do you support compliance audits and vendor questionnaires?
Tested backups are meaningless without actual restoration testing; companies often discover during ransomware incidents that backups are incompatible, restores take days, or processes aren't documented - making untested backups a false sense of security.
Security must be baked into foundational MSP operations as a continuous daily process, not an add-on accessory or separate service; treating it as optional or project-based is a red flag in 2026.
No - AI removes repetitive work and accelerates response times through automation and better suggestions, but humans retain responsibility for judgment calls and accountability; pure AI automation without human oversight is high-risk.
It depends on business operations, but modern expectations increasingly require follow-the-sun support structures since global distributed teams experience downtime costs worldwide, even at 2 a.m. local time.
Our reviewer’s read on each dimension, with quotes from the episode.
The episode delivers a solid set of practical MSP evaluation criteria and identifies real shifts in buyer expectations (security-by-default, compliance-driven, 24/7 global support, AI-assisted operations). However, substantive density is diluted by repetition of core ideas across multiple segments and significant throat-clearing ('you know,' 'if you will,' filler phrases). The seven-question framework provides structure but each question receives minimal elaboration or nuance beyond surface-level explanation.
The biggest shock is the MSP you needed in 2016 can't protect you in 2026
Security cannot be a bullet point anymore... security is not an add of services It is a foundational part of any MSP offering today
The framing of MSP evaluation through a 2016 vs. 2026 lens is useful but not novel - the shift from reactive break-fix to proactive, security-first, compliance-aware IT support is already mainstream industry conversation in 2024-2026. The seven questions (identity governance, backup testing, ransomware protocol, documentation, business impact, escalation, compliance) are reasonable checklists but represent best-practice hygiene, not contrarian or first-principles thinking. No fresh frameworks or unexpected arguments emerge.
The traditional MSP models back were very, I would say, very reactive. You can open a ticket, they respond
Security has to be baked into the way your MSP manage the environment on your behalf
Walid, CEO of Cloud PSO, is an active MSP operator with apparent depth in security, compliance, and IT operations at scale. He speaks from practitioner experience rather than theory and references real client scenarios (ransomware, backup failures, global support needs, compliance audits). However, the episode provides minimal bio or evidence of scale - no company size, revenue, client base, or named case studies to fully establish operational credibility. The relevance is clear but depth could be deeper.
Walid is here with me CEO of Cloud PSO working with companies that are really heavily on technology and can't afford downtown or security blind spots
So we see companies who say they're safe. Then ⁓ during ⁓ a ransomware, ransomware scare, they realized that the backups are not working or incompatible or restore takes days
The episode lacks specific data, metrics, timelines, and named examples to anchor claims. References to ransomware incidents and backup failures are anecdotal ('we see companies') rather than quantified. One vendor mention (Zio Test for identity governance) is included but without context. No dollar figures, failure rates, response time benchmarks, or survey data provided. The seven-question framework is concrete but questions themselves are generic - 'how do you handle X' without follow-up on what good looks like numerically or chronologically.
we see companies who say they're safe. Then ⁓ during ⁓ a ransomware, ransomware scare, they realized that the backups are not working or incompatible or restore takes days
we are partnered with Zio Test that handles all that for our customer
The host asks competent, structured questions that progress logically through MSP evaluation criteria and surface the seven-question checklist. However, follow-ups are infrequent and rarely push back or challenge claims. When Walid asserts 'AI won't replace MSPs,' the host accepts this without probing for concrete examples or trade-offs. Questions tend to confirm rather than interrogate - 'So if your MSP treats security as a separate upscale, that's a red flag' (host) is leading, not exploratory. Walid is rarely pressed on contradictions or asked to defend positions with specificity.
So let's start with the old world, know. ⁓ What was the traditional MSP models most people are, you know, still familiar with?
So a modern buyer should expect MSP to be using AI but not handling everything over it
Computed from the transcript - who did the talking, and the words that came up most.
If you are hiring a Managed Service Provider in 2026 the expectations have completely changed since 2016. CEOs CFOs and IT leaders are no longer satisfied with uptime alone. They now expect security built-in compliance handled AI-assisted intelligence and strategic alignment with business risks. In this episode we sit down with Walid CEO of Cloudpso to break down the evolving landscape of MSPs. We cover what modern buyers expect how traditional reactive MSP models fail today and how to identify if your MSP is truly modern. Topics discussed include: Why the MSP you relied on in 2016 may not protect you today Security compliance and AI as foundational requirements How downtime impacts global teams and business risk The importance of tested backups and disaster recovery Compliance and customer-driven IT requirements How AI can assist without replacing human judgment What a modern MSP looks like in 2026 Cloudpso helps organizations transform their IT operations with services including cloud management cybersecurity compliance support AI-assisted IT operations and risk management. Learn more about our services and how we help businesses thrive in 2026 by visiting
Transcribed and scored by The B2B Podcast Index.
speaker-0: If you hire an MSP in 2026 the same way you hired in 2016, you're probably taking a risk you don't even see yet. Today we are breaking down what wires actually expect now from managed service providers not the marketing buzzwords. The real ⁓ tick box for CEOs, CFOs and IT leaders are using 2026. So Walid is here with me CEO of Cloud PSO working with companies that are really heavily on technology and can't afford downtown or security blind spots.
Walid if someone hired an MSP 5 years ago and hired today What exactly the difference? speaker-1: The biggest shock is the MSP you needed in 2016 can't protect you in 2026. And this is very, ⁓ it's not surprising, right? Back then, ⁓ if your servers were up and tickets were answered, eventually people were happy, right?
Today, buyers expect security by default, compliance support, AI-driven. ⁓ responsiveness and real intelligence alignment in business ⁓ risk assessment. Not just ⁓ keeping the lights on. So any MSP that you work today or you're looking at, that's what most companies are expecting them to have today.
speaker-0: So let's start with the old world, know. ⁓ What was the traditional MSP models most people are, you know, still familiar with? speaker-1: Yeah, the traditional MSP models back were very, I would say, very reactive. You can open a ticket, they respond.
⁓ They focused on uptime, not business outcomes. There's almost no strategic alignment with your goals. Security is the basic at best. And IT is treated as a cost center, not a lever for growing.
So in that model, an MSP could disappear for weeks and still look good, visibly broken. speaker-0: Yeah that mouse sounds pretty stable on the surface and why doesn't that work anymore in tournament 6? speaker-1: Because the risk profile change a lot because of all the changes in technology and so on. A single security incident can wipe out years of brand quality, for example.
Downtime now hits globally. Distributed teams not just, you know, one off. Everybody's touched by that when there's downtime compliance and customer expectations drive your IT. decisions as well now, especially now with all this technology.
So I would say, so if you're, if your MSP only talks about, let's just say we only going to step in when something is broken. They're not your partner at that point because they're not taking into consideration what's going on in 2026. It's not just about help desk and answering tickets anymore. It's about, you know, how do you keep my business going without any disruption?
speaker-0: Yeah, yeah, that's a strong line if your MSP only talks when you you know talks to you when something breaks They're not really your partners like check it. So in 2026 buyer they're expecting more than that So, you know fix my stuff when it's speaker-1: Yeah, exactly. They expect someone to understand their business risks, not just their ticket and system. They want someone to understand their business risk from A to B, for example, or A to C.
⁓ They just want someone to be well informed about all the business risks, all their systems. speaker-0: So let's talk about security verse again. In 2026, is cyber security now a part of MSP by default or should companies treat it like a separate thing? speaker-1: Security cannot be a bullet point anymore.
I don't think that could be the case in 2026 security is not an ad of services It is a foundational part of any MSP offering today. That's what I would look at Identity is the new perimeter your users and accounts or At the entry point you would say MFA alone. It's not enough anymore. You need endpoint visibility ⁓ log monitoring tested backups, if you will.
⁓ And all of this has to be part of your day-to-day operation today in 2026. This is what I believe, not once a year or not on a project basis. It needs to be continuous. It's a continuous processes or a continuous process within your organization and your MSB partner today.
speaker-0: You said something important there, tested backup. So what do you mean by that? speaker-1: Well, having backups is meaningless if you never tested a restore. So we see companies who say they're safe.
Then ⁓ during ⁓ a ransomware, ransomware scare, they, I would say they, they realized that the backups are not working or incompatible or restore takes days or the process isn't documented. 2026, that's not acceptable anymore. ⁓ especially with the way things are happening around the world right now, you speaker-0: Yeah, so for buyers listing this today, if your MSP treats security as a separate upscale, that's a red flag. speaker-1: Yeah, security has to be baked into the way your MSP manage the environment on your behalf.
⁓ an optional accessory. It's not an add-on anymore. It needs to be part of the services that you're getting. speaker-0: So let's move to compliance.
Sometimes people's like feels like it's overhyped or they are overreacting or companies are overreacting to... Is overreacting to compliance? speaker-1: all these No, not really. No, no, no, In most cases, no.
They're reacting to, I would say, pressure of the chain. That would be the first kind of step. ⁓ Vendor risk questionnaires from their own customers. A lot of their own customers, they want to make sure that they satisfy certain requirements.
Cyber insurance is another requirement. SOC 2, ISO, HIPAA, PCI, dependent on the industry that you're in. ⁓ What we're seeing is your I would say your customer audit requirements become your IT requirements as well, if you will, if you wanna look at like this. So that's what we're seeing here.
speaker-0: That's a big shift. speaker-1: Well, for example, a SaaS company might, I would say a SaaS company might be under five million annual recurring revenue, but their enterprise, their enterprise customers expect SOC to controls. example, Hellscare, Fintech, SaaS, they're all pushed by their customer and at end of the day, they have these compliance. The MSP has to be able to support that as well on a documentation level, evidence level, I would say policies as well and technical controls as well.
So it's not just, you know, it's not just, it's not, the customer is not alone anymore. The MSP and the customer becomes kind of a unit to support all these requirements. speaker-0: Yeah. They're kind of connected, you know?
speaker-1: Yeah, 100%. 100%. speaker-0: Yes, we can't ignore AI. So is AI is going to replace technicians inside the MSPs?
speaker-1: ⁓ I don't think so. AI won't replace MSPs. ⁓ it will expose the ones who don't evolve. Meaning that, for example, let's just talk about real use case, ⁓ AI triggers tickets.
⁓ it opens a ticket and monitor it and at certain point it automatically responds to it with a knowledge base. For example, also AI will help you improve and automate documentations for, ⁓ on your ha- on behalf of your customers. And so forth. Also, it helps monitor system pattern.
⁓ That could be a really good thing when it comes to security as well. Reduce response time by giving text ⁓ better suggestions on what's going on with a ticket and so forth. But humans still make the judgment calls at the end of the day. AI removes ⁓ repetitive work.
not responsibility if you will. I mean, at end of the day, humans still are responsible for these tickets, you know, or so forth. So doesn't really replace, yeah. speaker-0: So a modern buyer should expect MSP to be using AI but not handling everything over it.
speaker-1: ⁓ exactly. If your MSP is not using AI anywhere, ⁓ they, they'll probably be slower and less, I would say less, ⁓ less effective than the ones who are. But, ⁓ if they're relying entirely on AI with, ⁓ with, I would say with no human, ⁓ no human oversight, that's, that's alone. I would say that's.
high risk, you know, you still need the human element to to. speaker-0: Yeah, there should be always ⁓ a human touch or human element for everything. So let's talk about like, know, ours. Do compliance really, you know, need 24-7 support or is that overkill?
speaker-1: Well, it always comes down to, it depends on your business. ⁓ But ⁓ here's the reality. I would say many, so many teams are global now. So that kind of solves that.
Systems rarely sleep. Downtime at 2 a.m. still costs ⁓ money somewhere, ⁓ somewhere in the world, right?
So that's kind of like my sink in here. If your business runs 24 by 7, your IT protection must do as well. 24 by 7, you still need 24 by 7 protection. That doesn't always mean a huge on-call team locally.
⁓ It might mean follows the sun support, at least that's what I call it. Structure, also build structure escalation. around that follow the Sun support and also have, I would say a clear response plans as well, especially if you're to follow that global model. speaker-0: Even if you are not a huge enterprise, you might still see 24x7 expectations from the customers.
speaker-1: Yes, customers expect support based on where they are obviously not where your ⁓ not where your I would say not where your office is speaker-0: So this is the part CEOs and IT leaders are going to want to replay if I'm about to hire an MSP in 2026. What questions should I ask? speaker-1: ⁓ okay. If you ask these seven questions, let's just say seven questions, or maybe five, let's just stick with seven.
Let me say, you'll know very quickly if your MSP is modern or not. So I would say the one thing that comes to my mind right away, how do you handle identity governance? That is very important. You need an IGA product in place.
to manage your identity governance. And we have, we are partnered with Zio Test that handles all that for our customer. Great product, great service, great CEO, great team. The second question is, how often do you test your backups?
That's one thing that I have seen people fail on, you know? So that's another question you need to ask. Third question, what is your, that's a big one, what is your ransomware response policy? or protocol, you know, what's your resume, where policy and protocol that's a search question.
Force question would be, you know, I always say documentation is another one. So how do you document infrastructure and change management? That's crucial as well. Number five, how do you measure?
Yeah. How do you measure your business impact? Not just tickets that are closed. I mean, it's easy to measure tickets that are closed, you know, how do you measure the impact?
⁓ another one. What is your escalation look like at 2 a.m. in the morning?
Especially if you have this global footprint of support. Lastly, get compliance. Like say, how do you support compliance and audits and customers questionnaire? know, those are seven questions that I think you should ask ⁓ all your MSB when working with an MSB.
speaker-0: So if your current or potential MSPs can't answer those questions, that's a signal. speaker-1: I would say exactly yes, say no. You're not just buying fixes. You're really buying a peace of mind.
You don't want to go to all these issues without having peace of mind. speaker-0: So to close this out, what does the ideal MSP looks like nowadays, in 2026? speaker-1: Hmm, that's a great question. So again, I'm going to hit on the security first.
Not, not an add on. Make sure your MSP has the security included. Compliance aware. They understand your industry really well.
Whether it's fintech, healthcare, AI assisted with humans. Don't take humans out. We need the AI assisted, faster, sharper, more proactive AI assistant, if you will. Transparent is another one.
Make sure your MSP is transparent. Clear reporting, clear documentation is one that I would say is very important. Proactive, you know, if your MSP is proactive on issues, not just reactive to them, then that's a great thing to have. And also make sure your MSP is business, your business is aligned with your MSP as well.
⁓ They care about your risk. They care about your revenue, your reputation. I would say the best MSB in 2026 won't be the cheapest. It will be the one that understands, I would say, understand your business, understand your risk, and also understand your customers too, by the way.
speaker-0: Yeah, that's really reframes how people should think about MSP. It's not just about ⁓ who can manage your systems at the cheapest rates. It's about who actually understand the ⁓ risk behind every, you know, businesses. speaker-1: 100 % if your MSP understands that then you have a great one.
So you have a good MSP if they don't understand that then Yeah speaker-0: Yeah, 100 % So if you are listening and want a simple way to evaluate your current or next future programming MSPs We put together a free one page checklist with those seven questions and few extra prompts So the link is in the description It's called the seven MSP questions every CEO should ask in 2026. Please go to your next MSP conversation and let us know how does it go? So Waddy, thank you so much for breaking this down.
⁓ If you found this helpful, guys, please subscribe to Cloud PSO and share this with founders or IT leaders who think about their next MSP scene. speaker-1: Seek your smart.
Other episodes covering the same guests and topics, from across The B2B Podcast Index.