Why your MSP is not the best judge of your cyber security estate

Your IT provider is invaluable, but they are not the right party to independently assess or test your security. Here is why, and it is not a criticism of them.

Insights · 7 September 2026

Your managed service provider keeps the lights on. They run your systems, fix problems and roll out the changes. That is invaluable. But independently assessing and testing your security is a different job, and they are not the right ones to do it. This is not a dig at good MSPs, it is about how assurance works.

1. It is marking their own homework

If your MSP built and manages your network, asking them whether it is secure is asking them to grade their own work. Even an excellent team has a blind spot for the decisions they made themselves. Independence is the entire point of a security assessment: a fresh, adversarial pair of eyes with no stake in the answer.

2. IT support and security testing are different crafts

You would not take a supercar to a general garage to be tuned. Keeping systems running and deliberately attacking them to find flaws are different skills, tools and mindsets. Too often what gets offered as a “test” by an IT provider is an automated scan with a clever label, which is not the same as a human trying to break in.

3. Independence is what everyone else values

Clients, insurers, tenders and auditors want assurance from an independent, accredited specialist, not from the provider who runs the systems being assessed. A CREST-accredited third party carries a weight that an internal or MSP sign-off simply does not, because it removes the conflict of interest.

This is not us versus your MSP

The best setup is your MSP and an independent specialist working together. We test and assess, and find the issues; they are often the ones who implement the fixes. You get the benefit of both, and a clearer, more honest picture of where you actually stand.

What to ask

Is your tester genuinely independent of whoever manages your systems? Are they CREST-accredited? Can they show a verifiable track record rather than a marketing claim? If the answer to any of those is no, it is worth getting a second, independent opinion.

Common questions

Can our IT company just do our penetration test?

They can run tools, but a test by the people who manage your systems lacks independence, which is exactly what clients, insurers and auditors want. An accredited third party removes the conflict of interest.

Do you work alongside our MSP?

Yes. We complement your IT provider rather than replace them: we test and assess, and they typically implement the fixes we identify.

Related

Get an independent view

Honest, independent, CREST-accredited advice. No sales team, no obligation.