5 Smart Questions to Ask Your MSP About Their Own Security

The most useful questions to ask your MSP right now have nothing to do with your own network. They are about the tools your provider uses to reach into it.

On September 11, 2026, the U.S. Cybersecurity and Infrastructure Security Agency added a critical ConnectWise ScreenConnect vulnerability to its Known Exploited Vulnerabilities catalog after confirming that attackers were already using it in real attacks. ScreenConnect is one of the most widely used remote support platforms in the managed services industry, which means the story is not really about one product. It is about a category of tools that sit at the center of how nearly every managed IT provider reaches into a client’s network.

For a small or mid-sized business, the useful takeaway is not which specific vulnerability appeared this week. It is a short set of questions to ask your MSP so you understand how they secure the tools they use to reach you.

What Actually Happened With ScreenConnect?

The flaw, tracked as CVE-2026-84869, is an improper privilege management and missing authorization issue. In practical terms, it could allow an attacker to transfer files to a device and execute them during an active remote support session without the host user ever approving the action. CISA set a remediation deadline of September 14, 2026, for federal agencies covered by Binding Operational Directive 26-04, and the same urgency applies to any organization running the affected version.

Diagram showing how a single remote support tool connects one MSP to many client networks
5 Smart Questions to Ask Your MSP About Their Own Security 8

The specific patch was straightforward for providers who noticed. The harder question sits one level up: how confident is your provider in their ability to spot, patch, and respond to something like this on their own infrastructure, not just on yours?

Why This Matters for Small Businesses?

Managed service providers are built on trust and access. A single provider often holds administrative reach into dozens or hundreds of client environments using remote support tools, remote monitoring platforms, and centralized password vaults. That concentration of access is efficient for delivery, and it is also exactly why attackers have been aiming at the provider layer rather than at each client individually.

According to the Huntress 2026 Cyber Threat Report, abuse of remote monitoring and management tools now accounts for 24% of all observed incidents, up from 7% the year before. Huntress’s own analysis flagged ScreenConnect specifically, including one case where a rogue install sat quietly for five months before an attacker used it as an entry point. The ScreenConnect entry in the KEV catalog is not an isolated event. It is the latest example of a documented, ongoing trend, and it is why the cybersecurity posture of your provider now matters as much as your own, which is exactly why the questions to ask your MSP have shifted this year.

Business owner asking an IT consultant security questions across an office desk
5 Smart Questions to Ask Your MSP About Their Own Security 9

5 Questions to Ask Your MSP

If you already have a managed IT provider, or you are evaluating one, these are the questions to ask your MSP directly. Good providers will have clear, unrehearsed answers.

1. How quickly do you patch the tools you use to reach my network?

Ask about their patch cadence for their own infrastructure, not just yours. A provider running weekly patch cycles internally is in a very different position than one that treats their tools as “set and forget.” Our September Patch Tuesday breakdown shows how quickly critical fixes can pile up in a single month.

2. What monitoring do you have on your own remote sessions?

Session logging, anomaly detection, and alerting on unusual remote access patterns should all exist on the provider side. If they cannot describe what triggers an alert on their own systems, that is a signal worth paying attention to.

3. Do you enforce multi-factor authentication on every tool that reaches my environment?

Every account, every technician, every tool. Not “we use MFA on email.” MFA on the remote support platform, on the RMM console, on the password vault, and on any cloud dashboard that touches client data. Enterprise-grade password managers make this practical to enforce at scale.

4. What is your response plan if one of your own accounts is compromised?

The right answer is not “that would not happen.” The right answer is a specific set of steps: session revocation, credential rotation, client notification timelines, and a documented containment playbook. This should also connect back to whatever cybersecurity insurance obligations exist on either side.

5. Are you aligned to a recognized security framework internally, not just for compliance reporting?

Frameworks like the NIST Cybersecurity Framework 2.0 and the CIS Controls exist for exactly this reason. A provider who applies these internally, not only when a client asks about compliance, is thinking about their own posture the same way they think about yours.

Checklist of 5 questions to ask your MSP covering patch cadence, session monitoring, MFA, incident response, and security framework alignment
5 Smart Questions to Ask Your MSP About Their Own Security 10

What to Do Next?

If you already have a managed IT provider, send these five questions in a short message and see how they respond. The quality of the answer matters as much as the content: unrehearsed and specific beats polished and vague every time.

If you are weighing options, bring these questions to ask your MSP into the conversation before you sign anything. A provider who treats these questions as reasonable and expected is showing you how they operate. One who deflects is also telling you something.

At Pexo, security posture starts with the tools we use before it reaches the networks we protect. If you are evaluating your options, our managed IT services team is happy to walk you through exactly how we answer each of these questions for our own environment.

What Actually Makes a Password Manager “Enterprise-Grade”?

Enterprise password management got a real signal this week: Keeper Security was named a Leader by both GigaOm and ISG, two independent analyst firms, in the same week. GigaOm placed Keeper in the Enduring Innovators quadrant of its Enterprise Password Management Radar. ISG did the same in its own report on identity and access management.

That is not just a vendor award. It is a useful excuse to ask a question most small businesses never actually answer: what does “enterprise-grade” mean here, and is your business still relying on something far short of it?

If your team’s passwords live in browser autofill, a shared spreadsheet, or a sticky note on a monitor, you are not alone. But you are also not protected the way you might assume.

Why “Enterprise-Grade” Isn’t Just Marketing?

Laptop screen showing scrambled encrypted data, illustrating the zero-knowledge encryption behind enterprise password management.
What Actually Makes a Password Manager "Enterprise-Grade"? 14

The phrase gets used loosely, but in identity security it means something specific: zero-knowledge architecture. In a true zero-knowledge system, your passwords are encrypted and decrypted only on your own device. The provider itself, Keeper included, never has access to your actual vault contents, not even in the event of a breach on their end.

Compare that to a browser’s built-in password manager, which is convenient but was never built with that same architecture as its foundation, or a spreadsheet, which has no encryption at all. The difference isn’t features. It’s what happens if the provider itself is ever compromised.

The Real Risk of Employee-Managed Passwords

For most small businesses, password management isn’t a decision, it’s a default. Employees reuse passwords across personal and work accounts. Browser autofill works fine until a device is shared, lost, or handed off to someone else. And the business owner has no real visibility into any of it, no way to know which accounts are weak, reused, or still active for an employee who left six months ago.

This is the actual gap. Not a lack of awareness that passwords matter, but a lack of any system that makes good password behavior the easy default instead of something each employee has to choose on their own.

What Least-Privilege Access Actually Looks Like?

Hand badging an access card at a secure office door, with a glowing clock and checkmark icon representing time-bound access.
What Actually Makes a Password Manager "Enterprise-Grade"? 15

There’s a second layer beyond passwords themselves: who can access what, and for how long. Keeper’s recent Workflow feature for its Privileged Access Management platform is a useful concrete example. Instead of employees holding standing access to sensitive systems indefinitely, access requests are made, explicitly approved, and automatically expire at the end of a set window.

That’s the practical meaning of least-privilege access: not a policy document, but a system where nobody holds more access than the task in front of them actually requires, and nothing is left open by accident.

D.I.Y. vs. Consumer vs. Enterprise: What’s the Real Difference?

Here’s how DIY tools, consumer apps, and true enterprise password management actually compare:

 Browser / SpreadsheetConsumer Password ManagerEnterprise Password Management
EncryptionNone or basicZero-knowledge, per-userZero-knowledge, org-wide
Visibility for the businessNoneLimitedFull audit trail
Offboarding a departed employeeManual, easy to missManualCentralized, immediate
Access controlNoneBasic sharingTime-bound, least-privilege
Built forIndividualsIndividuals / small teamsOrganizations with real risk exposure

Where This Actually Matters for Your Business?

None of this is about replacing one app with another. It’s about closing a gap most businesses don’t realize they’re carrying until something goes wrong, an employee’s reused password gets caught in an unrelated breach, or a former employee’s access was never actually revoked.

This is part of the identity and access security work we handle as part of a managed IT and cybersecurity program, not a separate project bolted on afterward. If your team is still relying on browser autofill or a shared spreadsheet, that’s usually the first thing worth changing. If it’s something you’ve been meaning to look at, enterprise password management is a reasonable place to start.