CyberzSOC

Publication detail
← Back to advisories & guidance

Choosing a managed service provider (MSP) ↗ source

November 24, 2025 NCSC Guidance

Summary

An SME’s guide to selecting and working with managed service providers. Many small to medium-sized enterprises (SMEs) use managed service providers (MSPs) to deliver IT products and services, manage important data, and to provide cyber security. This guidance describes how to select and work effectively with MSPs, and includes a checklist you can use when sourcing MSPs. If you’re part of an IT team responsible for working with MSPs within larger organisations (over 250 people), you should refer to the NCSC’s more detailed Cloud Security Introduction: SMEs are at risk UK organisations are increasingly targeted by cyber criminals. This can can result in financial loss, service disruption, and damage to organisations' reputations. Since MSPs will have access to your systems and data (which could include your customers' details), it’s important to ensure that MSPs take cyber security seriously, and that you understand the measures they have in place.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.