The NCSC Checklist
Choosing a Managed Service Provider (MSP)
Under UK regulation, accountability for your cyber security remains with you - even if a Managed Service Provider (MSP) handles your IT infrastructure.
The National Cyber Security Centre (NCSC) provides clear guidance on what organisations should look for when appointing a MSP.
Use the checklist below to assess your requirements, and your current provider.
If you’re unsure how they measure up, it may be time for a review.
1. Security Credentials & Proven Capability
Optimising IT:
- Cyber Essentials Plus
- ISO 27001
- ISO 9001
- NCSC Assured Service Provider
- Cyber Essentials Certification Body
All these certifications are publicly verifiable.
Optimising IT has operated since 2013 and maintains:
- An ISO27001-certified Information Security Management System
- An ISO9001-certified Quality Management System
- Publicly available live service statistics
We provide case studies and direct introductions to existing SME customers.
2. Transparency & Measurable Service
- Our response times and escalation pathways are documented in contract.
- Customers have real-time visibility of SLA attainment via our portal.
- If you cannot see your MSP’s performance data, you cannot measure it.
We provide transparency regarding:
- Where your data is stored
- How access is controlled
- Our audit results (internal and external)
- Our own security posture
3. Security Controls That Meet NCSC Expectations
The NCSC recommends specific baseline protections.
High and Critical patches deployed within 14 days (Cyber Essentials baseline).
Microsoft 365 backup stored in AWS with restore testing governed under ISO27001.
- Managed Detection & Response
- Microsoft 365 Identity Threat Detection
- SIEM-backed Security Operations Centre
- Advanced email protection
- External attack surface monitoring
Single Sign-On, conditional access and least-privilege controls applied by default.
Certified ISO27001 incident management framework.
Aligned to Cyber Resilience Bill proposals:
- Notification within 24 hours
- Full reporting within 72 hours
4. Clear Accountability & Governance
Cyber risk cannot be transferred contractually.
We use formal “boundaries” to document:
- MSP responsibilities
- Customer responsibilities
- Shared responsibilities
All risks are:
- Recorded
- Accompanied by mitigation recommendations
- Subject to formal risk acceptance if not addressed
5. Supply Chain & Resilience
Supply chain management forms part of our ISO27001-certified ISMS.
We provide transparency regarding:
- Data storage locations
- Access controls
- Third-party suppliers
We welcome any independent review.
Beyond Just Compliance
Meeting the NCSC checklist is just the baseline., with Optimising IT, you also receive:
- Business & Risk Reviews (vCIO-led)
- Strategic IT roadmap alignment
- Board-level cyber briefing during onboarding
- Staff cyber awareness training and social engineering testing
- Clearly documented contract review and renewal processes
The Most Important Questions
If your current MSP were independently assessed against the NCSC framework:
- Could they evidence every control?
- Could they demonstrate governance maturity?
- Could they clearly define liability boundaries?
- Could they show you audit results?
If your answer is “I’m not sure” - that uncertainty represents risk.
Book an MSP Governance Review
We offer a structured review of your current MSP arrangements against NCSC guidance and regulatory expectations.
You will leave with:
- A clear risk position
- Identified governance gaps
- Practical recommendations
- No obligation to move to Optimising IT









