ITSP in the Mirror: Do You Manage Your Security the Same You Do Your Clients?

By Paul Stanyer

Jun 16, 2025

Share this post

Man looking in a hand-held mirror

I would guess that the vast majority of ITSP owners are, in fact, accidental entrepreneurs. Falling into the role of a leader, employing a team and keeping things running smoothly is probably not what many of us envisioned for ourselves.

The fact is, we all love to help others. That’s why we are in this business. The warm sense of satisfaction from restoring a customer’s data from a failing PC, or the excitement of unboxing the latest flatscreen to replace an old CRT monitor. These small experiences 10, 20 or even 30+ years ago have led you to where you are now—in charge of people, keeping a sales funnel full, other businesses’ IT service uptimes and regularly reviewing compliance questionnaires and assessment results. Living the dream?

With so much to do, and with so much responsibility for others, it can be easy to take our eye off what is important—our own IT security and compliance. In reality, we probably don’t have the time. The organic growth of our business has led to lots of little things that have either been missed or procrastinated over.

The Credibility Factor: Why Internal Operations Matter

Why should we have our own security on the radar? One word: Credibility. Your clients assume that your own IT environment is a gold standard. When a business chooses your ITSP to protect their systems, they are naturally assuming that you practice what you preach. You do, right?

A failure from our own neglect of something simple could have catastrophic ramifications for not just one of our customers, but all of them. Then the trust you have spent years to build and embellish is gone in an instant.

There are also the other negative ramifications for lax security: Things such as cost, worry, stress. But trust is the one thing that will take years to restore again if you survive a security incident.

So, let’s touch on three high-level strategies to consider when keeping our own businesses secure, which in turn will benefit your clients too.

1. Get the Basics Right

I’d like to take a page from the UK Cyber Essentials playbook. Get the basics right. It can help you achieve some big wins in improving your own ITSP security. There are statistics quoted by NCSC and IASME that show the effectiveness of this strategy.

My personal view is that Cyber Essentials is not the be all and end all. There are many areas that Cyber Essentials does not touch. But it forces you to look at some key fundamental controls that will keep you and your clients safe.

One of the best things about Cyber Essentials is how it makes you record what assets you are protecting: endpoints, servers, firewalls, applications and other infrastructure. If you don’t know what you are protecting, how can you even get started understanding what controls you need to put in place?

2. Audit Thyself: Take Stock Like You Would a Client

You probably already know some of the gaps or areas of improvement needed in your own security. But there may be some things you don’t know. Never be so proud that you assume you’ve got it all covered. You don’t know what you don’t know.

Perform regular internal assessments against the same frameworks you would measure one of your clients against. In fact, use the same tools and processes, and involve others in your business. This will nurture the security culture that should run through the veins of everyone in your business. Be thorough and don’t skip over anything. Be honest and transparent with your findings.

3. Look in the Mirror: What Do You See?

Cyber incidents don’t just happen. It takes effort on the part of bad actors to effectively launch an attack that will be successful.

How do they know where to start? Taking a look in the mirror will help you to see your organisation's virtual footprint. It’s amazing what you will find when you look. Your domain DNS records are a good place to start looking. They contain a treasure trove of publicly viewable information. For instance:

  • - What email platform are you using?
  • - Are you open to spoofing? Do you have SPF, DKIM and DMARC configured and enforced?
  • - What CRM are you using which will contain records of your leads and customers?
  • - Do you publish a VPN, or other server-based services to the outside world?
  • - Is your firewall open to administration from the internet?
  •  

Your DNS records are effectively a big neon sign on the internet, pointing hackers to your front or even back doors.

What about your people? Who can a bad actor manipulate to gain access to some system? Search engines, social media or GitHub could provide invaluable information on key people in your organisation. There are publicly and freely available tools that you can use to perform the same reconnaissance on your organisation, that a bad actor would. Looking in the virtual mirror will provide valuable insights to your exposure.

Practice What You Preach

“Turn on MFA, patch your software, keep your anti-virus up to date.” Your customers are probably tired of hearing this messaging regularly. Are you? Here are some more questions to ask yourself:

  • - When was the last time you reviewed your own MFA deployment, across all your apps? In fact, when did you last review what accounts sit in your tools? 
  •  
  • - Have previous employee or contractor accounts been disabled/deleted? Have test accounts been disposed of? 
  •  
  • - When was the last time you performed a simple vulnerability scan against your own infrastructure to make sure patches are being installed, and not just for key line of business apps?
  •  
  • - When was the last time you reviewed your EDR/MDR agent deployed base and status?
  •  
  • - Who has admin rights to their device, and is it their day-to-day account? Is it you? That’s very naughty. Put yourself on the naughty step for 10 minutes.
  •  
  • - Have default settings and passwords been changed on infrastructure? Including innocuous devices such as printers and IoT devices? Do you have these on a separate network?
  •  
  • - When did you last review your BYOD and remote access policies?
  •  

Yes, the list goes on, but we should be caring for our own environment as we should our customers.

What Your Team Doesn’t Know Will Hurt You

We all tell customers that training employees about security awareness as well as making them aware of process and policy is fundamental to keeping the bad guys out. What about our own house? Are we doing the same for our employees?

I remember talking to a director at one of our customers. His team were the digital creative guys for their business. They all used Macs. When justifying why his whole team needed admin rights to their devices, he summarised by saying, “We are Apple users. We’re not stupid.” If I told you his password was an anti-security phrase, with some colourful language, would that surprise you too?

The thing is that our businesses are made up of people. These people all have different strengths and weaknesses. They all have things they are dealing with at home. They all come from different backgrounds. They all have different personality types.

Sometimes we are hyper-focused on the technical people in our organisation. The ones we grant serious levels of access to our customer environments. It can be easy to take our eye off the rest of our staff in accounts, sales, marketing, even the leadership team— especially the leadership team.

Are we making sure all these people are receiving the right training? Are they aware of the risks? Do they know how to spot scams? Are they aware of your processes to protect the business against spoofing attacks? Do they understand what data protection even means?

You should be arranging for regular internal training that includes security awareness sessions. This will help to build a culture of security accountability. If employees or contractors are not following your instructions to attend training sessions, or complete online training courses, then you need to understand why.

It is important that training is:

  • - Regular
  • - Bite-sized and focused
  • - Fun
  • - Relatable
  • - Led from the top
  • - Continuously improved
  •  

By focusing on these key points, you can create a more engaging, effective and well-received security awareness training program that encourages wide participation and completion.

Your security culture will be strengthened by publicly rewarding individuals who are your security champions. For example, publicly commending individuals who detect and report a phishing attempt will only encourage others to try and achieve the same level of excellence.

You are a critical part of a complex supply chain for your customer base. Your team needs to take that as seriously as you do. You need to enable that.

Disaster Recovery Isn’t Just for Clients: You’re a Business Too

This article would not be complete if we did not briefly touch on business continuity and disaster recovery (BCDR). We are deeply reliant on our tools, such as the PSA, RMM and documentation tools. These are different from the tools we supply to our customers, so this means we need a plan for operating without them.

We may also be very dependent on key people in our business. If there is a crisis when they are not available, who knows where the DR plan is and how to access it offline? What happens if a senior technical person or lead is unavailable during an incident? Disasters are not always what we expect. Who had pandemic as a heading in their BC plan in 2020? Have you considered long-term illness of a key person? Our business relies on tech and tools. But have you thought about access to funds if the bank was not available?

I don’t need to tell you how to set up an effective backup strategy, but make sure you have considered the following points:

  • - Run recovery drills for loss of your ITSP tools
  • - Include non-technical people in any exercises
  • - Document and store recovery plans offline
  • - Airgap your backups
  • - Plan for key people to be unavailable
  • - Ensure you can raise invoices if billing app is unavailable
  •  

A good tip is to use your ITSP as a living case study. You can then use that to strengthen client confidence and sales conversations. You deliver BCDR solutions daily—are you delivering them to yourself with the same precision and discipline you do with your clients? Your resilience matters just as much as your clients.

Quarterly Isn’t Just for Clients: Review Yourself Too

There’s a good phrase I learned recently, “If it’s not reviewed, it’s not improving.” We should regularly be internally reviewing:

  • - Key internal performance metrics
  • - Coverage of security monitoring
  • - Access control
  • - Security posture
  • - Stack usage and consolidation
  • - Internal project progress
  • - Training adoption and completeness
  •  

When we review performance metrics such as ticket performance, project delivery, uptime, etc., we can start to formulate a view on what is working, or not. This then enables us to understand what decisions are needed for our roadmap/strategy.

Our security monitoring (e.g. EDR/MDR) is a service we should be leveraging in-house as well providing to our customers. Is our monitoring coverage still complete or has there been some creep in what needs to be monitored? IaaS/SaaS/PaaS are so easily set up by anyone, it could be easy to have gaps in our monitoring. It goes back to knowing what you are protecting, getting the basics right.

Some recent high-profile hacks have been attributed to poor housekeeping on access control. Test accounts, previous employee accounts and too many assigned privileges. These are early Christmas presents for hackers. Review what accounts you have, delete what’s no longer needed and review privileges. Don’t be afraid to introduce friction.

Our security posture is constantly changing. Just as the shadow of a tree changes through the day as the sun moves around it, so our posture changes as threats continuously evolve. Review your patching, check your firewall configuration, continuously monitor MFA adoption, make sure all endpoints stay protected and regularly check your backup logs. These basics will reduce risk and give you the needed tools and options when things go south.

Our stack should be one we trust. It’s what we sell, so if we are not confident in it, address it straight away. Are the tools in your stack still fit for purpose? Do they still provide value? Do you have old products in your stack that you never finished migrating customers off? Get those projects finished and consolidate your stack. That in turn improves your posture.

And what about those internal projects that either never get finished, or worse, never get started? If we have previously identified a needed change, then get on with making it. Procrastination is literally a killer, a business killer.

Turn Insights into Action: Secure Your House Today

Today is the time to start looking at our own house, not tomorrow. Tomorrow never comes. Start with manageable tasks, focused on getting the basics right. Delegate where possible. Getting your team involved will only strengthen their understanding and desire to be on this journey with you. Their enthusiasm for security will be noticed by your customers and may motivate them to adopt a similar culture in their organisation.

Excellence in cybersecurity starts with getting the basics right.

Learn about GTIA Cybersecurity Programs.

Paul Stanyer is the founder and director at PS Tech and a member of the GTIA UK & Ireland Community executive council.

Related Posts:

Customers want providers to have real-time insights into cyber threats encompassing ransomware, social engineering, malware releases and other attacks.
By Carolyn April / Oct 26, 2023

State of Cybersecurity 2024: Filling Skills Gap Should Be Priority for MSPs

Ten days. That’s how long the computer systems were down at MGM Resorts in Las Vegas recently after a ransomware attack crippled operations at the casino and hotel giant. Around the same time, MGM’s competitor in the desert, Caesar’s, reportedly paid millions in ransom money to mitigate a similar malicious hit to its systems and data.
Street sign
By Haines Eason / Oct 21, 2025

Cybersecurity’s Main Street Problem: The Small Business Disconnect

Ann Westerheim is blunt about the disconnect she sees every day. As founder of Ekaru, a cybersecurity-focused MSP in Boston, she spends much of her time trying—and sometimes failing—to convince small business owners that they’re at risk. “People only see headlines for what’s happening with big business and they’re not seeing the headlines for what’s happening with small business,” she said. That perception gap runs deep. When a Fortune 500 company gets breached, it makes national news. But when a ten-person accounting firm loses its client data in a phishing scam, no one outside the victims and their clients will ever hear about it. For the business owner, though, the damage is existential. Small businesses are hardly a niche: They account for roughly half of the U.S. economy, 40% of private payroll and a quarter of government contract work. Yet their cyber defenses can be shockingly weak, and their owners may also shockingly believe they are “under the radar.” That illusion is costly. In Massachusetts alone, Westerheim points to half-million-dollar losses at Arlington schools and the town of Franklin due to simple business email compromise scams.