How to manage risk with managed service providers
Managed service providers (MSPs) help organisations manage and maintain their systems. This can reduce the need for large in-house teams. To deliver these services, MSPs need broad access to your IT systems, including privileged access across multiple systems.
This level of access creates risk. Because MSPs have trusted and privileged access, they can act as a gateway into your organisation. If an MSP is compromised, or if credentials are stolen, attackers may gain privileged access to your systems. The compromise of a single MSP can affect multiple organisations. This guidance helps MSPs and their customers manage cyber security risk in these engagements.