Most companies that get compromised were paying somebody for security at the time. That is the uncomfortable part. There was a contract, there were invoices, there was a quarterly report with green indicators on it.
An MSP delivers services: helpdesk, laptop builds, patching, backup, and often a security bundle on top. That is a real and useful thing to buy. What it is not is a security program. A security program is the layer that decides what the services must achieve, and then checks that they do. Almost nobody buys that layer, because from the outside everything looks handled.
The gap has a specific shape
I ran the investigation on a business email compromise. They were not negligent. They had an MSP and, separately, an MSSP. On paper the division was sensible: the MSP deployed and maintained the security tooling on the endpoints, the MSSP consumed the telemetry and watched for trouble.
The MSP had not installed the software on all of the machines.
So the MSSP was monitoring a subset of the estate and reporting on what it could see, which looked fine, because the part it could see was fine. Nobody in either organization owned the sentence "every device that connects has working endpoint protection." The MSP thought it was a deployment task that had been done. The MSSP could only report on what reported to it. Neither was lying. There was simply no one whose job was the join between them.
This is the same structural gap that leaves penetration test findings unclosed: plenty of parties with adjacent responsibilities, none holding the specific one.
We ended up bringing in a third firm with proper forensic tooling to establish what had actually happened, because neither incumbent could.
Thirty days of logs
The constraint that hurt most during that investigation was retention. The system logs went back 30 days.
We were able to establish roughly when the compromise began, and we got there by a margin of a few days. A slightly longer dwell time and the honest answer to "when did this start and what did they reach" would have been that we could not say.
Think about what that means in practice. Notification obligations, client communications, insurance claims, and the question every customer will ask all depend on scope. Scope depends on the logs. Thirty days is a default, not a decision, and it is routinely shorter than the incident it needs to cover.
Disk is cheap. The retention setting is one of the highest-value things you can change this week, and it costs a conversation and a config change.
The question that exposes the gap in one meeting
Ask your provider this, exactly:
"How do you ensure that every one of the company's devices has endpoint protection installed and current?"
A bad answer sounds reassuring. "We have processes in place." "It is part of our standard build." "It is included in your package." Every one of those describes an intention.
A good answer describes enforcement. Something close to: "Devices enroll in Intune, compliance policy requires the agent to be present and healthy, and a non-compliant device is blocked from connecting to your systems through conditional access. Here is this month's compliance report and here are the four devices currently failing it."
The difference is that the second answer cannot be true while machines sit unprotected. It makes the gap structurally impossible rather than merely unintended. It usually needs a higher Microsoft license tier than the one you are on, which is precisely why it often gets skipped, and it is worth the money.
Then ask for the report. Not the assurance, the report.
Purchased is not deployed
If there is one belief I would remove from the market it is this one: we bought the contract, so we are covered.
MSPs sell themselves as a single point of accountability, and clients hear that as a transfer of risk. It is not. It is a transfer of activity. The risk stays exactly where it was, on the company whose data it is, whose customers will ask, and whose regulator will write.
The gap between purchased and deployed is where nearly everything I have investigated actually lived. A tool on the invoice that never made it to a third of the fleet. A backup job that runs and has never been restored from. A policy that applies to the group everyone was supposed to be in.
None of that is visible from a ticket queue. Much of it is visible in a penetration test report, which is a more expensive way to learn it. All of it is visible in ten minutes to someone who asks for evidence instead of status.
Who watches the watchers
This is the part I feel strongly about, because it is so easy to walk into while doing everything else right.
A company decides it needs independent oversight of its managed provider. It agrees with the principle, and then hires that same provider to supply the virtual CISO.
Consider what that role is supposed to do. It sets the security requirements the MSP must meet. It reviews the MSP's reports skeptically. It decides whether the MSP is performing and escalates when it is not. Handing that to the MSP means the organization's only security oversight function reports to the entity it exists to oversee.
Nobody involved is acting in bad faith. The failure is quieter than that: the questions that would surface the provider's own gaps are simply never the ones that get asked, because no one in the room benefits from asking them.
Oversight has to come from outside the thing being overseen. That is the whole idea.
What the good version looks like
I am not anti-MSP. I have no interest in imaging laptops, and neither should your senior technical people. A good MSP with good tooling, run properly, is the right answer for helpdesk, device management, patching, and backup at almost every company under a few hundred people.
The good version has three properties:
Defined outcomes, not activities. The contract says what must be true, not what tasks will be performed. Every connecting device is managed and compliant. Logs are retained for a stated period. Offboarding completes within one business day. Backups are restore-tested on a stated cadence.
Evidence on a schedule. Compliance reports, restore-test results, and retention settings arrive without being requested, and somebody reads them.
Someone outside the MSP holding the line. Fractional is fine. This is not a full-time job at most companies. It is a few hours a month of somebody who knows what good looks like, asks for the evidence, and has the standing to be believed when they say the provider is not delivering.
That third one is the stage most companies skip, and it is the one that turns a set of purchased services into an actual program.