Your managed service provider keeps the lights on. They run your systems, fix problems and roll out the changes. That is invaluable. But independently assessing and testing your security is a different job, and they are not the right ones to do it. This is not a dig at good MSPs, it is about how assurance works.
1. It is marking their own homework
If your MSP built and manages your network, asking them whether it is secure is asking them to grade their own work. Even an excellent team has a blind spot for the decisions they made themselves. Independence is the entire point of a security assessment: a fresh, adversarial pair of eyes with no stake in the answer.
2. IT support and security testing are different crafts
You would not take a supercar to a general garage to be tuned. Keeping systems running and deliberately attacking them to find flaws are different skills, tools and mindsets. Too often what gets offered as a “test” by an IT provider is an automated scan with a clever label, which is not the same as a human trying to break in.
3. Independence is what everyone else values
Clients, insurers, tenders and auditors want assurance from an independent, accredited specialist, not from the provider who runs the systems being assessed. A CREST-accredited third party carries a weight that an internal or MSP sign-off simply does not, because it removes the conflict of interest.
This is not us versus your MSP
The best setup is your MSP and an independent specialist working together. We test and assess, and find the issues; they are often the ones who implement the fixes. You get the benefit of both, and a clearer, more honest picture of where you actually stand.
What to ask
Is your tester genuinely independent of whoever manages your systems? Are they CREST-accredited? Can they show a verifiable track record rather than a marketing claim? If the answer to any of those is no, it is worth getting a second, independent opinion.
Common questions
Can our IT company just do our penetration test?
They can run tools, but a test by the people who manage your systems lacks independence, which is exactly what clients, insurers and auditors want. An accredited third party removes the conflict of interest.
Do you work alongside our MSP?
Yes. We complement your IT provider rather than replace them: we test and assess, and they typically implement the fixes we identify.
Related
Solusec
Typically replies within one business day
Had an incident, or need a penetration test or Cyber Essentials at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day