The NCSC Checklist

20250521_optimising_it_0580

Choosing a Managed Service Provider (MSP)

Under UK regulation, accountability for your cyber security remains with you - even if a Managed Service Provider (MSP) handles your IT infrastructure.

The National Cyber Security Centre (NCSC) provides clear guidance on what organisations should look for when appointing a MSP.

Use the checklist below to assess your requirements, and your current provider.

If you’re unsure how they measure up, it may be time for a review.

Book a MSP Governance Review

1. Security Credentials & Proven Capability

Does your MSP hold recognised, independently verifiable security certifications?

Optimising IT:

  • Cyber Essentials Plus
  • ISO 27001
  • ISO 9001
  • NCSC Assured Service Provider
  • Cyber Essentials Certification Body

 

All these certifications are publicly verifiable.

Can they demonstrate a proven security track record?

Optimising IT has operated since 2013 and maintains:

 

  • An ISO27001-certified Information Security Management System
  • An ISO9001-certified Quality Management System
  • Publicly available live service statistics

Will they provide references?

We provide case studies and direct introductions to existing SME customers.

2. Transparency & Measurable Service

Are SLAs clearly defined - and visible in real time?

  • Our response times and escalation pathways are documented in contract.
  • Customers have real-time visibility of SLA attainment via our portal.
  • If you cannot see your MSP’s performance data, you cannot measure it.

Are they open about how your service is delivered?

We provide transparency regarding:

 

  • Where your data is stored
  • How access is controlled
  • Our audit results (internal and external)
  • Our own security posture
OIT_Ticket

3. Security Controls That Meet NCSC Expectations

The NCSC recommends specific baseline protections.

Timely Patch Management

High and Critical patches deployed within 14 days (Cyber Essentials baseline).

Automated, Off-Site Backup

Microsoft 365 backup stored in AWS with restore testing governed under ISO27001.

24×7×365 Monitoring

  • Managed Detection & Response
  • Microsoft 365 Identity Threat Detection
  • SIEM-backed Security Operations Centre
  • Advanced email protection
  • External attack surface monitoring

Mandatory Multi-Factor Authentication

Single Sign-On, conditional access and least-privilege controls applied by default.

Documented Incident Response

Certified ISO27001 incident management framework.

Clear Incident Reporting Timelines

Aligned to Cyber Resilience Bill proposals:

 

  • Notification within 24 hours
  • Full reporting within 72 hours

4. Clear Accountability & Governance

Cyber risk cannot be transferred contractually.

Are responsibilities clearly defined?

We use formal “boundaries” to document:

 

  • MSP responsibilities
  • Customer responsibilities
  • Shared responsibilities

Are identified risks formally documented?

All risks are:

 

  • Recorded
  • Accompanied by mitigation recommendations
  • Subject to formal risk acceptance if not addressed
20250521_optimising_it_1010

5. Supply Chain & Resilience

Has your MSP assessed its own supply chain risk?

Supply chain management forms part of our ISO27001-certified ISMS.

We provide transparency regarding:

  • Data storage locations
  • Access controls
  • Third-party suppliers

We welcome any independent review.

Beyond Just Compliance

Meeting the NCSC checklist is just the baseline., with Optimising IT, you also receive:

 

  • Business & Risk Reviews (vCIO-led)
  • Strategic IT roadmap alignment
  • Board-level cyber briefing during onboarding
  • Staff cyber awareness training and social engineering testing
  • Clearly documented contract review and renewal processes
20250521_optimising_it_0607

The Most Important Questions

If your current MSP were independently assessed against the NCSC framework:

  1. Could they evidence every control?
  2. Could they demonstrate governance maturity?
  3. Could they clearly define liability boundaries?
  4. Could they show you audit results?

If your answer is “I’m not sure” - that uncertainty represents risk.

Book an MSP Governance Review

We offer a structured review of your current MSP arrangements against NCSC guidance and regulatory expectations.

You will leave with:

  1. A clear risk position
  2. Identified governance gaps
  3. Practical recommendations
  4. No obligation to move to Optimising IT

 

Book your MSP Governance Review