4 things MSPs should test right now

Every experienced MSP knows the first rule of a new prospect: trust nothing, test everything.

Bob Jenner, President and CEO of The Network Doctor, put that rule to work when he walked into a law firm that had six years of clean backup reports and every reason to feel secure. Then he tried to restore the data.

“They thought they were getting backups, but they hadn’t had any backups,” Jenner said.

Six years, zero recoverable data, all because their previous provider never verified what the reports claimed. When Jenner showed them the truth, they finally understood how exposed they had been.

Like this law firm, most businesses believe they’re protected because the tools are in place, and the policies are signed. Nothing has gone wrong yet, so everything must be fine. The gap between what clients assume and what’s been verified is where MSPs step in, win new business and save the day.

Here are four critical things your MSP should test long before a client ever needs them.

1. Data backup systems

The backup light is green and the reports look clean, so the client has no reason to question whether any of it would hold up when they need it. That’s not their job; it’s yours.

MSPs that keep their clients prepared know that checking backups means more than just confirming the process appears to have worked. It means verifying the data is recoverable and browsable, which requires restoring data from the client’s backup.

“Once a month, we mount the backup of [client] systems,” Jenner explained. “We verify that it is there, mountable, and browsable, so we are sure we can restore from it.”

Ask yourself: when did you last restore actual data from this client’s backup, not just review the report, but pull real data back?

2. The disaster recovery plan

Most clients have a disaster recovery plan on file, but a document describing what should happen when everything fails is only as useful as the people expected to execute it. Employees who have never practiced a procedure are far less likely to perform well under pressure.

“You can have a disaster recovery tabletop exercise,” Jenner said. “This is, essentially, when you get employees from different departments sitting around a table and you propose a scenario and define that process. Ask, how do we respond?”

A tabletop exercise gives employees a safe, controlled environment to practice the plan, ask questions, clarify steps and work through mistakes before the stakes are real. Running this exercise costs a fraction of what errors during an actual incident would.

After the exercise, every employee should be able to answer the following: What do I do during the incident? Who do I contact, and how? What is the overall process, and how should the team respond?

3. Cyber insurance policy

“What people don’t know is 46% of cyber insurance claims are denied,” Jenner said. “They get denied because businesses are not doing what they said they were when they filled out the questionnaires.”

Most clients have limited visibility into the specific cybersecurity measures you’ve put in place, which means they can unknowingly misrepresent their security posture when filling out insurance paperwork. That knowledge gap can cost them thousands of dollars in denied claims. Testing the cyber insurance policy means ensuring clients understand what their policy requires, what coverage you provide and that the two align.

4. Overall cybersecurity posture

One area clients and MSPs rarely think to test is access. If an attacker tried to get into a client’s system, what would they find? Could they slip through undetected, and if so, what data could they get their hands on or lock up?

This test involves the MSP actively playing the role of the attacker, scanning for holes in security: passwords cached in the browsers, accessible saved credentials, unencrypted PII or financial data, and any vulnerabilities visible to someone who knows where to look.

“We run this test monthly,” Jenner said. “We’re bringing those risks to the front, talking to the customer about them before they have a problem.”

Assumptions are not proof.

Businesses assume they are covered when it comes to cybersecurity. They trust their current provider to protect them and never ask for proof. It isn’t until an incident occurs that businesses realize assumptions don’t keep them protected.

As an MSP, your job is to test the systems your clients depend on long before those systems are put to the test for real. Having the right tools in place is the baseline; proving they work is what builds lasting trust.

The Network Doctor has been in business for 46 years, and only one client has experienced a ransomware event. That client recovered fully and quickly, not by luck, but because nothing had been left to assumption.

Your clients can’t afford to find out the hard way. Get more disaster preparedness tips in our latest campaign, Test Your Safety Net Before You Need It, on the MSP Success Portal or click here to learn more about MSP Success.