Who I Help · Managed Service Providers

Fractional CISO services for managed service providers.

Your remote monitoring and management console is not one of your systems. It is the business. A single compromised laptop is a bad day. A compromised RMM console is a bad quarter, possibly a bad year.

An attacker with administrative access to your RMM does not breach one company. They inherit your trusted access into all of them at once.

Not an accusation
Independent attestation is the same principle that stops a company auditing its own financials. It is not a judgment about anyone's competence.
Exhibit A · The example that made the point

We patched last week is not the same as we are current.

N-able N-central was actively exploited across all supported versions, cloud and on-premises, including 2026.3. The first patch was incomplete, which is why CVE-2026-18556 was followed by CVE-2026-18577.

Underwriters have noticed. Management tooling is now a primary focus in MSP cyber applications rather than a footnote, and the questions are specific: who holds administrative access to the console, how quickly it is patched, and what separates your environment from your clients'.

Exhibit B · Why an independent party helps you, not just your client

The party that operates the controls should not be the party attesting to them.

The party that implements and operates security controls should not also be the party that attests to their adequacy to a third party who is pricing risk based on that attestation. It is not an accusation about anyone's competence or honesty. It is the same principle that stops a company from auditing its own financials.

A good MSP recognizes the argument immediately, because it is the argument their own insurers make about them.

The part that protects you

Having an independent party document the gaps protects the MSP too. It converts an awkward conversation about what was not done into a shared, dated record of what was recommended and what the client chose.

That record is the difference between a client asking why their policy was rescinded and a client reading a recommendation they declined, with a date on it.

Exhibit C · Two ways this works

It does not replace your MSP. Your MSP implements.

That is the job and they are set up for it. Your local IT team or MSP keeps doing what they do well. I handle the governance, strategy, and board-level translation.

You as the client
Your own environment, assessed

Risk analysis of your own environment. Privileged access to the RMM and to client tenants. Patch currency on management tooling specifically. Segmentation between your environment and client environments. And what your incident response plan says happens on the day the console is the thing that is compromised.

You as the partner
Alongside you, on your client

I come in alongside you on a client who needs governance, risk and compliance work outside your scope, or who needs someone independent to sign the attestation. You keep the relationship. I do not implement or operate infrastructure, which is the part of the relationship that renews.

Exhibit D · Questions MSPs ask

Frequently asked questions

Are you trying to take our clients?

No. I do not implement or operate infrastructure, which is the part of the relationship that renews. Where I work with your client, you keep the account and I keep the governance.

Why should we not just fill out the client's insurance application ourselves?

Because an inaccurate answer on that application can rescind the policy after a claim, and the client will ask who let it go out that way. An independent attestation removes you from that exposure.

What do you look at in an MSP's own environment?

Privileged access to the RMM and to client tenants, patch currency on management tooling specifically, segmentation between your environment and client environments, and what your own incident response plan says happens on the day the console is the thing that is compromised.

Do you work on retainer or per engagement?

Both. Partner work is usually scoped per client engagement. Direct MSP work is usually a retainer, starting at $5,000 per month.

Have a client asking for something outside your scope?

That is usually the first conversation, and it is thirty minutes rather than a partnership agreement.

Book a Free Security Clarity Session
Melissa Thornton, CISSP, C|CISO · Founder, Cybersecurity Advisory Group · White Plains, New YorkLast reviewed September 2026