Security leadership
Your IT provider is not your CISO. That's not a criticism of them.
"I assume our IT company has that covered."
It is the most common sentence we hear, and it is usually said with slightly less confidence than the words suggest.
What an MSP actually does
Your IT provider keeps the systems running. Email works, the case management system is up, the laptops are patched, the backups happen. That is real, skilled, necessary work, and most of them do it well.
But an MSP manages what it was asked to manage. It rarely enumerates what exists — the forgotten test server, the subdomain someone set up for a conference in 2019, the staff logins circulating in breach databases from services the firm never sanctioned. Those things are, by definition, not on anyone's list.
The scan finds what the contract doesn't cover
When a firm runs an external exposure scan, the findings almost always land in the gap between what the MSP was asked to do and what an attacker can see:
- Email authentication half-configured during a migration and never revisited — so anyone can send an invoice from the firm's own domain
- Staff credentials already sitting in public breach data
- A remote-access service left reachable from the internet
None of these are the IT provider's fault. They were never scoped. Nobody owned the question.
The missing role
In a large organisation the person who owns that question is the CISO. Their job is not to run the systems — it is to decide, own, document and maintain the security position, and answer for it.
In a firm of fifty to two hundred and fifty people, that person does not exist and cannot realistically be hired. It is a six-figure role in a market short of more than 11,500 people. So the question goes unowned, and the tools sit unmanaged.
What good looks like
The IT provider stays. They run the infrastructure — that role needs to exist. Above it sits someone whose job is to look at the firm from the outside, decide what matters, and hand the MSP a prioritised list rather than a vague worry.
Attacking the IT company is commercially self-defeating and usually wrong. Adding the layer they were never meant to be is the fix.
See it for your own firm
Run the free 60-second exposure scan.
The same outside-in view an attacker starts from. Public data only — nothing is probed.