MSP Responsibility Matrix
Purpose
Use this matrix to define which cybersecurity responsibilities belong to the company and which are performed by its Managed Service Provider or outsourced IT provider.
Using an MSP does not remove the company’s responsibility for understanding and managing cybersecurity risk.
The objective is to avoid dangerous assumptions such as:
“We thought the MSP handled backups.”
“We thought the MSP monitored those alerts.”
“We thought the MSP patched the firewall.”
Parties
Company: ____________________
MSP: ____________________
Internal MSP owner: ____________________
MSP account manager: ____________________
MSP technical escalation contact: ____________________
MSP security incident contact: ____________________
Contract start: ____________________
Contract renewal: ____________________
Responsibility Definitions
Use:
-
Company — Company performs and owns the task.
-
MSP — MSP performs the task.
-
Shared — Both parties have responsibilities.
-
Not Covered — The service is not currently provided.
For shared responsibilities, identify exactly what each side must do.
Responsibility Matrix
Critical Questions to Resolve
The company should be able to answer:
-
Who monitors security alerts after business hours?
-
Who responds if endpoint protection reports ransomware?
-
Who checks failed backups?
-
Who performs restore tests?
-
Who patches firewalls and VPN appliances?
-
Who checks internet-facing vulnerabilities?
-
Who disables a compromised account?
-
Who can isolate a device?
-
Who preserves logs after an incident?
-
Who contacts the incident response provider?
-
Who manages Microsoft 365 or Google Workspace security settings?
-
Who reviews administrator access?
-
Who removes vendor and former employee access?
-
Who owns the cybersecurity risk when the MSP identifies a problem?
Alert Escalation
For critical alerts:
MSP contact method: ____________________
Company contact: ____________________
Backup company contact: ____________________
Expected response time: ____________________
After-hours process: ____________________
Incident Response
Clarify whether the MSP provides:
-
Initial triage: Yes / No
-
Endpoint containment: Yes / No
-
Account containment: Yes / No
-
Forensics: Yes / No
-
Evidence collection: Yes / No
-
Ransomware response: Yes / No
-
Recovery assistance: Yes / No
-
24/7 response: Yes / No
If not, identify an alternative provider:
Reports and Evidence
Define reports the MSP should provide, such as:
- Patch reports
- Endpoint protection status
- Backup status
- Restore test results
- Security incidents
- Vulnerability findings
- Device inventory
- User/account reports
- MFA coverage
- Licensing/security coverage gaps
Reports required: ____________________
Frequency: ____________________
Gaps
Services not currently covered:
Risk created:
Owner:
Required action:
Due date:
Review
The responsibility matrix should be reviewed:
- At contract renewal
- After major service changes
- After significant incidents
- When cybersecurity tools change
- When important responsibilities move between providers
- At least annually
Last review: ____________________
Next review: ____________________
Company approval: ____________________
MSP acknowledgement: ____________________
Practical Rule
Never assume the MSP handles something because it sounds like “IT.”
Write down exactly who performs each cybersecurity responsibility, who checks that it happened, and who responds when it fails.