Operational advisorySix chapters · vendor-neutral

Reviewing your MSP relationship

A practical, vendor-neutral guide to operational clarity, continuity and technology governance for Australian businesses.

Not every MSP review begins because something has gone wrong. Many reviews are simply a responsible governance exercise as the business grows. The goal of this page is clarity, not pressure.

Documented environment review

Written, retained by the business

Identity, backup and governance

Mapped against Essential Eight ML1

Useful even if nothing changes

Strengthens any provider relationship

01

The acknowledgement

Reviewing your MSP does not mean blaming your MSP.

Many reviews are simply a responsible governance exercise.

A review is not a complaint

For many businesses, the hardest part of reviewing a provider is emotional, not technical.

The current provider may have helped the business for years. They may know the staff, understand the history and have supported the organisation through outages, projects, office moves, growth and difficult moments. That matters and deserves acknowledgement.

A provider review does not need to dismiss that history. It does not need to assume poor service. It does not need to become confrontational. Sometimes a review simply means the business has changed and the operating model needs to be checked against where the organisation is now. That is responsible leadership, not criticism.

A measured review separates the things that often get lumped together as "the MSP isn't working":

Service issues

Specific, recent, evidenced

Documentation gaps

Often inherited, often fixable

Contractual obligations

Read the agreement carefully

Inherited technical debt

Decisions made before either party

New compliance expectations

Insurance, OAIC, board reporting

Business growth

The shape of the business has changed

Changing support requirements

Operating model, not provider quality

Genuine provider performance

Sometimes real, often the smallest factor

On transparency

A strong MSP relationship should not depend on mystery. It should depend on clarity, process and mutual accountability. A mature provider is generally comfortable with transparency, because it protects everyone, reduces confusion during incidents and makes renewals easier.

Why businesses actually open a review

None of these signals automatically mean the current provider has done anything wrong. They generally mean the business has reached a point where operational visibility, documentation and governance need to mature alongside it.

Common operational signals

01

Growth across multiple locations

The service model that worked at 25 staff is rarely the same shape at 80.

02

Microsoft 365 has become central

Identity, files, Teams and security policies now live in one tenant.

03

Cyber insurance has tightened

Underwriters now expect evidence, not assurances, at renewal.

04

Documentation is hard to produce

Asset registers, network diagrams and identity baselines feel incomplete.

05

Internal teams have changed

New CIO, new operations leader, new finance leader, new expectations.

06

Incident readiness is unclear

Leadership cannot easily describe what would happen in the first hour.

07

Board reporting has matured

Quarterly governance now expects risk registers and improvement roadmaps.

08

Quarterly reviews have stopped

Service is reactive rather than scheduled, even when everyone is working hard.

09

Contracts are coming up for renewal

A renewal is a natural moment to confirm scope, inclusions and governance rhythm.

10

A move toward co-managed IT

Internal IT has grown enough that responsibilities need redefining.

A note on tone

A healthy review does not start with blame. Technology environments are living systems built through decisions made over years. Even well-managed environments accumulate documentation gaps as they evolve faster than the governance around them. The best reviews are calm, factual and constructive.

02

Operating principles

A competent review looks the same, regardless of provider.

Six operating principles for any provider review.

01

Continuity comes before transformation

The first objective of any transition is that the business continues to operate. Improvement programmes and security uplifts are sequenced after operational stability is established, not bundled into cutover weekend.

02

Documentation belongs to the business

Asset registers, network diagrams, identity baselines and runbooks are operational artefacts the business should retain in its own systems. A provider holds copies, not originals.

03

Identity is the centre of gravity

In a Microsoft 365 environment, identity controls who can do what, from where, on which device. Conditional Access, MFA coverage, privileged role assignments and break-glass accounts are reviewed before anything else.

04

Backups are only real once restored

A backup that has never been restored is a hypothesis. A verified restore inside the first 30 days is part of how recoverability is confirmed, not an optional extra.

05

Outgoing providers are part of the process

Most providers behave professionally when a client moves on. The handover is treated as a structured operational exercise between two technology teams, not a confrontation.

06

Governance survives staff turnover

A mature operating model is one a new CIO, finance leader or operations manager can pick up and understand quickly. Documentation, review cadence and ownership clarity exist for the business, not the provider.

03

The governance view

Microsoft 365 has quietly changed what an MSP is for.

Two lenses every leadership team should use.

Part one · Microsoft 365 governance

Microsoft 365 has quietly changed what an MSP is for

For most Australian businesses, Microsoft 365 now holds email, files, identity, Teams content, device policies and a meaningful slice of compliance evidence. It is the centre of operations rather than one application among many.

That shift has changed the modern MSP role. Helpdesk and infrastructure still matter, but identity governance, Conditional Access, privileged role management and tenant backup are now where operational risk concentrates. A provider that was a strong fit for break-fix support five years ago may simply need a broader operating model today.

The questions on the right are the ones we ask first in any environment review. None are designed to catch a provider out. They are designed to help the business understand its own posture.

Q01

Who holds Global Administrator access today?

Including any third-party vendors with persistent admin rights.

Q02

Is MFA enforced across every active user?

With Conditional Access policies documented and reviewed.

Q03

Are privileged role assignments reviewed quarterly?

Privileged Identity Management or equivalent governance in place.

Q04

Are break-glass accounts configured and tested?

Documented, monitored, with credentials stored independently.

Q05

Is legacy authentication still permitted?

Basic auth, IMAP and POP turned off unless explicitly required.

Q06

Is Microsoft 365 data backed up independently?

Mailboxes, OneDrive, SharePoint and Teams content recoverable outside the tenant.

A business that can answer each of the six questions in writing within an hour is generally well governed. A business that cannot is not failing. It simply has documentation work to do.

Part two · The executive view

Executives do not need every technical detail. They do need confidence the right questions have been answered.

Business owners, directors and executives do not need to understand firewall rules, Conditional Access policies or backup retention schedules. That is engineering work.

What leadership does need is a clear, written answer to a small set of plain-English questions. If those answers exist, the business is in operational governance. If they do not, the business is in hope.

None of these are technical micromanagement. They are operational governance, expressed in the language a board can read.

Operational governance · executive view

01

Who owns the key systems and who has administrative access today

02

Whether multi-factor authentication is enforced across every user

03

Whether backups can actually be restored and when that was last tested

04

Whether users are removed properly from systems when they leave

05

Whether the documentation needed during an incident actually exists

06

Whether cyber insurance questions can be answered accurately and quickly

07

Whether there is a plan, in writing, if something significant goes wrong

08

Whether the current provider relationship still matches what the business needs

A leadership team that can answer this list in writing within an afternoon is well governed, regardless of provider.

04

Concerns & impact

Most leaders are not afraid of change. They are concerned about disruption.

A well-considered approach has a minimal effect on risk and cost.

Part one · The practical concerns

Most leaders are not afraid of change. They are concerned about disruption.

These are the practical questions that come up in the first conversation, in roughly the order they arrive. Naming them in advance is part of how anxiety is reduced. Planning replaces uncertainty with process.

Will staff lose access to email?

Mailboxes, calendars and Teams data remain inside the same Microsoft 365 tenant throughout. No mailbox is moved or recreated.

Will files disappear?

SharePoint, OneDrive and Teams files are not touched at cutover. A verified, independent backup is taken before any administrative change is executed.

Will support tickets get missed?

Open tickets are reviewed individually with both providers, formally transferred, and tracked through to closure during the hypercare window.

Will the outgoing provider become difficult?

Most providers behave professionally when expectations are written and respectful. Where cooperation is poor, contractual and regulatory paths exist.

Will this take more time than we have?

Leadership is typically needed for four to six short conversations. The technical work happens in the background.

Will something break on Monday morning?

Cutover is scheduled outside business hours, runbooks include rollback triggers, and engineers are available through the first business day.

Will there be double billing?

Notice periods are read carefully against the existing agreement before transition is scheduled. Overlap windows are agreed in writing.

Will historical knowledge be lost?

Asset registers, runbooks and contextual notes are exported, structured and retained by the business before handover begins.

On planning

The purpose of planning is not to make a transition sound easy. The purpose is to make the risks visible, owned and controlled in advance, so leadership can sign off on a process they understand rather than approve a black box.

Part two · Internal load

A well-run review should reduce internal effort, not add to it

The people involved are usually already running operations, finance, HR, compliance and service delivery. The process should carry the technical work, not push it back onto the business. Leadership stays informed and in control. Staff barely notice.

What leadership is needed for

A few short conversations

  • Explaining business priorities and known constraints
  • Confirming the critical systems the business cannot operate without
  • Identifying key staff, sites and operational rhythms
  • Approving access requests against the existing agreement
  • Reviewing findings and signing off on commercial decisions
  • Agreeing the timing and tone of staff communications
  • Confirming what level of operational risk is acceptable

Leadership should be informed and involved, not buried in technical coordination.

What staff actually notice

Usually very little

  • A new support contact and updated helpdesk instructions
  • Possibly a re-authentication prompt during cutover weekend
  • A new monitoring or endpoint protection agent appearing on devices
  • Clearer escalation paths if a ticket is taking too long
  • Improved communication on open tickets through the changeover
  • A short, plain-English explanation of what is changing and why
  • Generally, very little visible disruption to day-to-day work

The objective is not to make IT change visible for its own sake. It is to make support clearer while keeping normal business activity stable.

Part three · Standing still is also a decision

Doing nothing carries its own operational risk

Changing providers carries risk. So does standing still. If documentation is incomplete, backups are untested, privileged access is informal or incident procedures live in someone's head, the business is already carrying operational risk. That risk rarely appears during normal weeks.

It usually appears under pressure, on the worst possible day. A review does not create those risks. It surfaces them early enough that they can be managed calmly, in writing, before they become incidents.

Where unmanaged risk tends to surface

01

A key staff member leaves and admin credentials become unclear

02

A cyber insurance renewal arrives and questions cannot be answered

03

A director asks for a written risk report on short notice

04

A backup needs to be restored for the first time in years

05

An administrator account is locked out at 5pm on a Friday

06

A domain renewal is missed and a public-facing service goes down

07

A breach or suspected breach occurs and the first hour is unclear

08

A provider relationship changes unexpectedly through merger or sale

None of these scenarios are unusual. They are the moments when the absence of documentation, backup verification or governance becomes expensive. A structured review brings them forward into a calm conversation rather than an incident response.

05

Transition methodology

Maturity is built incrementally, contextually and intentionally.

Five stages. A written deliverable at every stage.

Five stages · written deliverable at every stage

What happens in this stage

Scoped operational conversation with leadership to confirm priorities, obligations and known constraints

Read-only review of Microsoft 365, Entra ID, backup platform and network where access is available

Inventory of users, devices, licences, domains, certificates and key SaaS dependencies

Identity posture review: Global Administrator accounts, Conditional Access, MFA coverage, break-glass account status

Mapping against ASD Essential Eight Maturity Level 1 and SMB1001 baseline expectations

Written summary of operational risks, dependencies and documentation gaps

Deliverable

Environment review document. Retained by the business.

Note

A business can stop here. The review is useful regardless of what comes next.

Operational maturity

Maturity is built incrementally, not transformationally

Many businesses assume mature IT means large transformation projects. In practice, operational maturity is the result of small, consistent improvements over time. None of the rungs below are dramatic individually. Collectively, they significantly improve resilience and reduce operational friction.

00

Documentation written down

Asset register, network diagram and identity baseline exist on paper, even if imperfect.

01

MFA enforced and monitored

Multi-factor authentication is on for every user, with reporting in place. Exclusions are documented and reviewed.

02

Verified backup with restore tested

Critical systems are backed up to an independent location and a restore has actually been performed inside the last 90 days.

03

Endpoint detection and response

EDR is deployed on every endpoint and server, alerting goes somewhere a human reads, and incident process is documented.

04

Documented incident response plan

Plain-English playbook with named owners, communication tree and OAIC notification path. Tested at least annually.

05

Quarterly governance cadence

Scheduled reviews of risk, posture, licensing and roadmap with attendees, inputs and outputs all documented.

The rungs broadly align with ASD Essential Eight Maturity Level 1 baseline controls and the SMB1001 starter tier. A business at rung 03 or above is generally well placed for cyber insurance renewal in 2026.

Documentation the business retains

Seven operational artefacts. Held by the business.

A common operational risk in long-running provider relationships is that documentation accrues only on the provider's side. If the business ever needs to change provider, recover from an incident, or onboard new leadership, it effectively starts from zero.

The set below is the minimum documentation footprint any business of meaningful size should hold in its own systems, refreshed at least annually. Strong operational transparency generally creates stronger long-term partnerships, not weaker ones.

Broadly the documentation set the OAIC and most Australian cyber insurers expect a business to be able to produce within 48 hours of a notifiable event.

Operational artefact

01

Asset register

Users, devices, licences, domains and certificates with documented owners and renewal dates.

Finance · operations · audit

02

Network diagram

Sites, links, firewalls, switches, access points and core services. PDF with editable source files retained.

IT · auditors · incoming engineers

03

Identity baseline

Entra ID groups, Conditional Access policies, MFA coverage, privileged role assignments and break-glass account documentation.

Security · cyber insurance · auditors

04

Backup runbook

What is protected, where it is stored, how long it is retained, and the date of the most recent verified restore.

Operations · cyber insurance · IT

05

Vendor matrix

Third-party SaaS platforms, hardware vendors and telecommunications carriers with contract dates and administrative contacts.

Finance · procurement · IT

06

Incident response plan

Plain-English procedure covering who to contact, what is communicated, and the steps an engineer takes in the first hour.

Leadership · security · OAIC readiness

07

Governance schedule

Cadence of operational reviews, security reviews and licensing reviews, with documented attendees and inputs.

Leadership · IT · finance

06

Outcomes & next step

Staying, sharing, or moving. All three are legitimate.

The purpose of a structured review is clarity, not provider change.

Three valid outcomes

Stay with the current provider

Sometimes the existing relationship just needs structure

  • Updated documentation requested from the provider
  • Quarterly review cadence formalised
  • Service expectations clarified in writing
  • Backup and identity reporting improved
  • Microsoft 365 governance uplifted alongside the existing provider

Often the best result is giving a capable provider the structure, authority and expectations they need to support the business properly.

Move to a co-managed model

Internal IT and an external partner sharing accountability

  • Internal IT focuses on strategy, proximity and project work
  • External partner delivers helpdesk, after-hours and security operations
  • Roles, escalation paths and ownership documented end to end
  • Often the right model between roughly 80 and 200 staff
  • Reduces single-person dependency without losing institutional knowledge

The maths usually flips in this band: a single senior IT hire cannot deliver helpdesk, security operations and strategy simultaneously.

Transition to a new provider

Where the operating model genuinely no longer fits

  • Reporting and governance expectations have outgrown the relationship
  • Documentation is not available and cannot be produced
  • Security expectations have moved beyond the current service model
  • Multi-site or compliance obligations require broader coverage
  • There is a persistent gap between expectations and delivery

A provider can be capable and still not be the right fit for the next stage of the business. Fit matters.

A note on contracts

The starting point is usually reading the existing agreement carefully

Most contractual concerns dissolve once the document itself has been read end-to-end. The patterns below appear in the majority of Australian managed services agreements we see.

Notice and handover clauses

Most Australian managed services agreements contain a defined notice period and a documented handover process. The first practical step in any review is reading the existing agreement to understand notice obligations, handover clauses and any remaining payment terms.

Where multi-year obligations sit

Where genuine multi-year obligations exist, they are typically tied to hardware finance, licensing commitments or telecommunications contracts rather than the managed services agreement itself. Those obligations generally remain with the business regardless of who manages them, and can usually be transitioned smoothly.

When to take legal advice

Where any aspect of the agreement is unclear, a short review with a commercial lawyer before formal notice is given is a sensible step. This page is operational guidance based on patterns seen across the Australian MSP market and is not legal advice.

+Questions that come up

Practical questions from leadership teams considering a review

Answers reflect patterns from environment reviews completed across Queensland, NSW and Victoria. Click any question to expand.

Start with understanding

A documented environment review is a low-risk first step

Before discussing platforms, projects or provider changes, most businesses benefit from understanding how their environment is structured today, where operational dependencies sit, how identity is governed, and how recoverability is validated.

That understanding alone usually improves operational decision-making, regardless of which provider holds the relationship at the end of it. The review is documented, retained by the business, and useful even if nothing else changes.

Calls and reviews are advisory. There is no obligation to proceed, no high-pressure follow-up, and the documentation is yours to keep regardless of the outcome.