Most companies I walk into have an IT vendor they like. The MSP answers tickets, the phones get fixed, the server hums in the closet. Then I ask one question and the room goes quiet: when was the last time you verified any of it?
Nobody's auditing the auditor. The MSP reports on its own performance, marks its own homework, and sends you the bill with a smile. That's not a criticism of MSPs. Most of them do honest work. It's a structural problem. You wouldn't let your accounting firm approve its own invoices, so why does your IT provider get to grade itself?
The green dashboard problem
Open any MSP client portal and you'll see the same thing: green checkmarks everywhere. Patches applied. Backups completed. Firewall online. Everything green, all the time.
Here's what that dashboard doesn't tell you. Whether patches were applied to all systems or just the easy ones. Whether those "completed" backups were ever tested with an actual restore. Whether the firewall rules were reviewed after the last three projects piled changes on top of changes. Green means the monitor didn't alert. It doesn't mean you're safe.
I once found a client paying for full endpoint protection on 40 machines. The dashboard said "protected." Fourteen of those machines hadn't checked in for months. They were dead, replaced, or repurposed, but the billing kept marching. The green light wasn't lying exactly. It just wasn't telling the whole truth.
Accountability starts with a contract, not a handshake
The biggest gap I see isn't technical. It's contractual. The typical MSP agreement promises "best efforts" and "response times." Response times. Not resolution times. Not outcomes. Just how fast someone picks up the phone.
When I help companies renegotiate these agreements, we rewrite them around outcomes. Patch compliance above 95 percent, measured independently. Backup restores tested quarterly, with a report you can read. A security review every year from someone who doesn't cash your MSP's checks. Quarterly business reviews where they show up with a roadmap, not just a ticket count.
Most good MSPs will agree to this without a fight. The ones who push back are telling you something important.
The quarterly review that isn't a sales pitch
Ask your MSP for a quarterly business review this week. Not a ticket recap, an actual review: what's our risk posture, what's changing in our industry, what should we budget for next year, where are we falling behind peers our size.
If that meeting turns into a product pitch within ten minutes, you don't have a technology partner. You have a vendor with a quota. A real partner shows up with hard truths: the system you need to replace, the policy you're missing, the risk you're carrying that you haven't priced in. Uncomfortable conversations are the ones worth having.
Trust, but verify
None of this means firing your MSP. If they're good, they'll welcome the scrutiny. The point is ownership. Technology risk belongs to your business, not to the company you outsource it to. When something breaks at 2 AM, or when a regulator comes asking questions, it's your name on the door.
So verify. Run a separate backup test once in a while. Ask for the raw patching report, not the summary. Get an independent security assessment every couple of years. Keep a relationship with someone who understands your environment but doesn't invoice you monthly. Call it a fractional CIO if you like. The title doesn't matter. The second opinion does.
Your MSP works for you. Make sure the structure of the relationship says so.
Not sure where your IT really stands? Start with a Clarity Audit: a focused assessment of your backups, security, vendors, and AI readiness. It's the first step in every engagement I take on.
About the author: Chris McGlasson is a fractional CIO and the founder of ClearStack Advisory, where he helps mid-market companies build AI governance, IT strategy, and technology roadmaps without the overhead of a full-time CIO. He previously built and sold LANPRO Systems, an IT services firm serving 350+ enterprise clients.
