MSP Responsibility Matrix

Purpose

Use this matrix to define which cybersecurity responsibilities belong to the company and which are performed by its Managed Service Provider or outsourced IT provider.

Using an MSP does not remove the company’s responsibility for understanding and managing cybersecurity risk.

The objective is to avoid dangerous assumptions such as:

“We thought the MSP handled backups.”

“We thought the MSP monitored those alerts.”

“We thought the MSP patched the firewall.”

Parties

Company: ____________________

MSP: ____________________

Internal MSP owner: ____________________

MSP account manager: ____________________

MSP technical escalation contact: ____________________

MSP security incident contact: ____________________

Contract start: ____________________

Contract renewal: ____________________

Responsibility Definitions

Use:

  • Company — Company performs and owns the task.

  • MSP — MSP performs the task.

  • Shared — Both parties have responsibilities.

  • Not Covered — The service is not currently provided.

For shared responsibilities, identify exactly what each side must do.

Responsibility Matrix

Cybersecurity Area Company MSP Shared / Detail Evidence or Report Review Frequency
Asset inventory          
Device deployment          
Endpoint protection          
Operating system patching          
Third-party application patching          
Server patching          
Firewall patching          
Network device patching          
MFA configuration          
User account administration          
Administrator account management          
Joiner access          
Offboarding access removal          
Access reviews          
Backup configuration          
Backup monitoring          
Backup failure response          
Restore testing          
Email security          
Spam/phishing protection          
DNS security          
Vulnerability scanning          
Internet exposure monitoring          
Security logging          
SIEM/security alert monitoring          
Alert triage          
Endpoint incident containment          
Incident response coordination          
Evidence preservation          
Forensic investigation          
Ransomware response          
Cloud security          
SaaS security          
Vendor access administration          
Security awareness training          
Recovery support          
Business continuity          
Cyber insurance coordination          
Regulatory/customer reporting          

Critical Questions to Resolve

The company should be able to answer:

  • Who monitors security alerts after business hours?

  • Who responds if endpoint protection reports ransomware?

  • Who checks failed backups?

  • Who performs restore tests?

  • Who patches firewalls and VPN appliances?

  • Who checks internet-facing vulnerabilities?

  • Who disables a compromised account?

  • Who can isolate a device?

  • Who preserves logs after an incident?

  • Who contacts the incident response provider?

  • Who manages Microsoft 365 or Google Workspace security settings?

  • Who reviews administrator access?

  • Who removes vendor and former employee access?

  • Who owns the cybersecurity risk when the MSP identifies a problem?

Alert Escalation

For critical alerts:

MSP contact method: ____________________

Company contact: ____________________

Backup company contact: ____________________

Expected response time: ____________________

After-hours process: ____________________

Incident Response

Clarify whether the MSP provides:

  • Initial triage: Yes / No

  • Endpoint containment: Yes / No

  • Account containment: Yes / No

  • Forensics: Yes / No

  • Evidence collection: Yes / No

  • Ransomware response: Yes / No

  • Recovery assistance: Yes / No

  • 24/7 response: Yes / No

If not, identify an alternative provider:


Reports and Evidence

Define reports the MSP should provide, such as:

  • Patch reports
  • Endpoint protection status
  • Backup status
  • Restore test results
  • Security incidents
  • Vulnerability findings
  • Device inventory
  • User/account reports
  • MFA coverage
  • Licensing/security coverage gaps

Reports required: ____________________

Frequency: ____________________

Gaps

Services not currently covered:


Risk created:


Owner:


Required action:


Due date:


Review

The responsibility matrix should be reviewed:

  • At contract renewal
  • After major service changes
  • After significant incidents
  • When cybersecurity tools change
  • When important responsibilities move between providers
  • At least annually

Last review: ____________________

Next review: ____________________

Company approval: ____________________

MSP acknowledgement: ____________________

Practical Rule

Never assume the MSP handles something because it sounds like “IT.”

Write down exactly who performs each cybersecurity responsibility, who checks that it happened, and who responds when it fails.