Site icon Roundbox Consulting

Is your Managed Service Provider effectively managing your cybersecurity?

Managed Service Provider

How do you know if your current Managed Service Provider (MSP) is effectively managing your cybersecurity? Most Not for Profits have outsourced their IT services, but not many consider their cybersecurity risks after the contracts have been signed.

Even if someone else is responsible for managing and delivering these services, the accountability still remains with the organisation. In fact, the Australian Institute of Company Directors made it very clear with their advice:

“While it is not the role of the board to directly manage cyber risk, it is the board that has ultimate accountability for how risks are governed and addressed. This includes being satisfied there are appropriate processes and delegations in place that provide directors with comprehensive oversight of the actions of management.”

So, how would you give confidence to your Board that your Managed Service Provider is effectively managing your cybersecurity? Here are a few indicators:

Simple indicators to know if your Managed Service Provider is effectively managing your cybersecurity:

These are only indicators, obviously. So, if you want to really understand how they are doing, you should require your IT Service Provider to provide you with a regular report that demonstrates their performance.

Ideally, you should already have this built into your service contract. If not, there are other ways.

Essential Eight Report

The Australian Signals Directorate created a cybersecurity risk baseline framework called the Essential Eight. It’s primarily aimed at organisations that use Microsoft but can be applied beyond that.

The Essential Eight covers:

An Essential Eight report will NOT mitigate all cybersecurity risks in the organisation, but it will cover a lot of it if your organisation relies heavily on Microsoft. There’s enough free information available online for this framework that your Managed Service Provider should be able to prepare the report (for an additional fee). If they can’t, I’d suggest looking for a new provider as soon as possible.

As for other frameworks, there are many available, but I often find them to be overkill for most Not for Profits. For my clients, I create custom evaluations depending on their size, risk profile and other needs.

I regularly help Not for Profits with strategic IT decisions, including identifying cybersecurity risks.  Let me know if you need some help.

P.S. If you found this article helpful, you might want to read these ones too:

 

Tammy Ven Dange is a former charity CEO, Association President, Not for Profit Board Member and IT Executive. Today she helps NFPs with strategic IT decisions, especially around investments.

 

 

Exit mobile version