درباره این اپیزود
Description
Search for IT companies near you and every website makes the same four promises: proactive monitoring, fast response, security built in, and local support. Those words can't tell you which managed service provider is actually good. Evidence can.
Jason Russell founded Harmony MSP, the firm that sponsors this show, so he says up front that he has a stake in how you choose. Then he walks through the seven-step vetting process he'd want you to run on his own company. It starts with the one-page requirements list you write before any sales call and ends with the scorecard you use to pick a winner.
Along the way:
- Why Verizon's 2026 Data Breach Investigations Report found a third party involved in 48% of breaches, and why that number is easy to misread
- What federal cyber agencies told MSP customers to require
- The difference between response time and resolution time
- The contract terms that decide whether you can ever cleanly leave
Florida listeners get three local specifics: hurricane planning, the state's 10-day breach-notice clock for IT providers, and the cybersecurity safe harbor Florida still doesn't have.
In this episode
00:00 Every IT company makes the same promises
00:43 A disclosure, and a promise
02:11 Step 1: Write down what you need before you call anyone
03:41 Step 2: Build your shortlist on fit, not ad spend
05:12 Step 3: Ask for documents, not demos
08:08 Step 4: Check references like an investigator
09:16 Step 5: Treat the sales process as a preview
09:59 Step 6: Read the contract for the exit
11:30 Step 7: Score your finalists on evidence
12:25 For Florida listeners: hurricanes, breach notice, and a myth
14:41 What vetting can't tell you
15:32 The short version, and how to reach us
Key takeaways
- Write a one-page requirements list before any sales call: headcount and locations, critical software, regulated data, hours, onsite needs, and last year's cyber insurance application.
- Ask for documents, not demos:
- a sample MSA and SLA
- a real monthly report
- a written description of how they secure their own access
- certificates of insurance
- the date of their last full restore test
- a written breach-notice commitment
- Response time means someone acknowledged your ticket. Resolution time means it's fixed. Check which one the SLA actually promises.
- Your domain, Microsoft 365 or Google Workspace tenant, firewall, and backups should be in your company's name, with your own people holding top-level access.
- Score finalists only on what they showed you, not what they told you.
Resources
- Full written guide, with the weighted scorecard: https://harmony-msp.com/it-companies-in-orlando-how-to-vet-an-msp/
- Episode 1 companion, on cyber insurance applications: https://harmony-msp.com/how-to-answer-cyber-insurance-renewal-questions-without-voiding-your-policy/
Sources referenced in this episode
- Verizon, 2026 Data Breach Investigations Report: https://www.verizon.com/business/resources/reports/dbir/
- CISA, NSA, FBI, and international partners, Protecting Against Cyber Threats to Managed Service Providers and their Customers (AA22-131A): https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-131a
- HHS Office for Civil Rights, Business Associates: https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
- FTC Safeguards Rule, 16 CFR 314.4: https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C/part-314/section-314.4
- The Florida Bar, Ethics Opinion 12-3: https://www.floridabar.org/etopinions/etopinion-12-3/
- Florida Information Protection Act, s. 501.171, Florida Statutes: https://www.flsenate.gov/Laws/Statutes/2025/501.171
- Florida CS/CS/HB 473 (2024), vetoed: https://www.flsenate.gov/Session/Bill/2024/473
- Florida CS/SB 692 (2026), died in committee: https://www.flsenate.gov/Session/Bill/2026/692
- Florida Division of Corporations (Sunbiz) business search: https://dos.fl.gov/sunbiz/search/
- Davis Wright Tremaine, on state cybersecurity safe harbor laws: https://www.dwt.com/blogs/privacy--security-law-blog/2023/07/iowa-cybersecurity-breaches-safe-harbor
Want a second set of eyes?
If you have IT proposals on your desk and want someone to go through them with you, call (407) 720-6540 or email Jason directly at jason@harmony-msp.com.
About the host
Jason Russell is the founder and CEO of Harmony MSP, a managed IT and cybersecurity firm in Lake Mary, Florida. A former Navy cryptologic technician and NSA network security consultant, he's spent more than two decades translating security problems into decisions business owners can actually act on. He's the author of Secured: The Cybersecurity Survival Guide.
Sponsor
Ctrl+Alt+Protect is brought to you by Harmony MSP: managed IT, network security, and compliance for small businesses, law firms, medical and dental practices, and accounting firms across Central Florida. https://harmony-msp.com
Tags
managed service provider, MSP, how to choose an IT company, how to vet an MSP, managed IT services, IT support contract, service level agreement, SLA, third-party risk, vendor risk, cyber insurance, HIPAA business associate agreement, FTC Safeguards Rule, Florida Information Protection Act, hurricane preparedness, small business cybersecurity, Orlando IT support, Central Florida, Ctrl+Alt+Protect