Security maturity comes from consistently operating a sensible baseline—not buying the longest list of tools.
Protect identities first
Require multifactor authentication, remove shared accounts, protect administrators, review access regularly, and make employee departures prompt and complete.
Manage every endpoint
Keep an inventory, enforce secure configuration, patch operating systems and applications, encrypt storage, deploy managed protection, and isolate devices that fall out of compliance.
Make recovery real
Back up critical systems and cloud data where needed, protect backup administration, define recovery priorities, and test that important information can actually be restored.
Prepare for an incident
Document who investigates, who makes business decisions, how legal and insurance contacts are engaged, how employees communicate, and how access can be contained quickly.
Organize the work and assign owners
NIST CSF 2.0 groups outcomes into Govern, Identify, Protect, Detect, Respond, and Recover. Use those headings to ask where responsibilities are missing. The framework is voluntary guidance, not a certificate proving an MSP is secure. Create a working register with a business owner, operational owner, next action, due date, and evidence for each priority.
Ask for evidence of coverage, not just deployment
A tool installation count does not tell you whether every active device is reporting or whether someone investigates alerts. Request the exception list: unmanaged devices, unsupported systems, accounts without the required authentication, and failed protection jobs. For each exception, record the reason, interim control, and remediation date. Keep sensitive reports in an approved location.
Test the people and process together
Run a discussion exercise using a fictitious lost laptop or compromised mailbox. Ask who can contain it, how employees reach help, what records are preserved, and who approves external communication. Capture unanswered questions as actions. The purpose is to find gaps without creating an actual incident or exposing real credentials.
Working checklist
✓Multifactor authentication
✓Managed endpoint protection
✓Consistent patching
✓Protected and tested backups
✓Email security
✓Security awareness training
✓Incident-response contacts
Sources and further reading
Primary references for the topics identified below. Examples, checklists, and purchasing recommendations are editorial guidance.
- NIST: Cybersecurity Framework 2.0 for small businesses ↗
A framework for organizing cybersecurity outcomes; it is not a provider certification.
Published by Bay Area Managed IT. Examples are illustrative; they are not provider quotes, audited results, or local market survey findings. Read our editorial approach →
Bring these questions to your next provider conversation.
Use a common scope and keep the evidence beside each answer.
Prepare your RFP →