## Purpose

Use this matrix to define which cybersecurity responsibilities belong to the company and which are performed by its Managed Service Provider or outsourced IT provider.

Using an MSP does not remove the company’s responsibility for understanding and managing cybersecurity risk.

The objective is to avoid dangerous assumptions such as:

“We thought the MSP handled backups.”

“We thought the MSP monitored those alerts.”

“We thought the MSP patched the firewall.”

## Parties

Company: ____________________

MSP: ____________________

Internal MSP owner: ____________________

MSP account manager: ____________________

MSP technical escalation contact: ____________________

MSP security incident contact: ____________________

Contract start: ____________________

Contract renewal: ____________________

## Responsibility Definitions

Use:

- **Company** — Company performs and owns the task.

- **MSP** — MSP performs the task.

- **Shared** — Both parties have responsibilities.

- **Not Covered** — The service is not currently provided.

For shared responsibilities, identify exactly what each side must do.

## Responsibility Matrix

|Cybersecurity Area|Company|MSP|Shared / Detail|Evidence or Report|Review Frequency|
|---|---|---|---|---|---|
|Asset inventory||||||
|Device deployment||||||
|Endpoint protection||||||
|Operating system patching||||||
|Third-party application patching||||||
|Server patching||||||
|Firewall patching||||||
|Network device patching||||||
|MFA configuration||||||
|User account administration||||||
|Administrator account management||||||
|Joiner access||||||
|Offboarding access removal||||||
|Access reviews||||||
|Backup configuration||||||
|Backup monitoring||||||
|Backup failure response||||||
|Restore testing||||||
|Email security||||||
|Spam/phishing protection||||||
|DNS security||||||
|Vulnerability scanning||||||
|Internet exposure monitoring||||||
|Security logging||||||
|SIEM/security alert monitoring||||||
|Alert triage||||||
|Endpoint incident containment||||||
|Incident response coordination||||||
|Evidence preservation||||||
|Forensic investigation||||||
|Ransomware response||||||
|Cloud security||||||
|SaaS security||||||
|Vendor access administration||||||
|Security awareness training||||||
|Recovery support||||||
|Business continuity||||||
|Cyber insurance coordination||||||
|Regulatory/customer reporting||||||

## Critical Questions to Resolve

**The company should be able to answer:**

- Who monitors security alerts after business hours?

- Who responds if endpoint protection reports ransomware?

- Who checks failed backups?

- Who performs restore tests?

- Who patches firewalls and VPN appliances?

- Who checks internet-facing vulnerabilities?

- Who disables a compromised account?

- Who can isolate a device?

- Who preserves logs after an incident?

- Who contacts the incident response provider?

- Who manages Microsoft 365 or Google Workspace security settings?

- Who reviews administrator access?

- Who removes vendor and former employee access?

- Who owns the cybersecurity risk when the MSP identifies a problem?

## Alert Escalation

**For critical alerts:**

MSP contact method: ____________________

Company contact: ____________________

Backup company contact: ____________________

Expected response time: ____________________

After-hours process: ____________________

## Incident Response

**Clarify whether the MSP provides:**

- Initial triage: Yes / No

- Endpoint containment: Yes / No

- Account containment: Yes / No

- Forensics: Yes / No

- Evidence collection: Yes / No

- Ransomware response: Yes / No

- Recovery assistance: Yes / No

- 24/7 response: Yes / No

If not, identify an alternative provider:

---

## Reports and Evidence

**Define reports the MSP should provide, such as:**

- Patch reports
- Endpoint protection status
- Backup status
- Restore test results
- Security incidents
- Vulnerability findings
- Device inventory
- User/account reports
- MFA coverage
- Licensing/security coverage gaps

Reports required: ____________________

Frequency: ____________________

## Gaps

Services not currently covered:

---

Risk created:

---

Owner:

---

Required action:

---

Due date:

---

## Review

**The responsibility matrix should be reviewed:**

- At contract renewal
- After major service changes
- After significant incidents
- When cybersecurity tools change
- When important responsibilities move between providers
- At least annually

Last review: ____________________

Next review: ____________________

Company approval: ____________________

MSP acknowledgement: ____________________

## Practical Rule

Never assume the MSP handles something because it sounds like “IT.”

Write down exactly who performs each cybersecurity responsibility, who checks that it happened, and who responds when it fails.
