Frequently Asked Questions

Find the answers you're looking for

Browse our most common questions

From cybersecurity and compliance to AI adoption and IT strategy, businesses face more technology decisions than ever before. These FAQs address common questions organizations have about protecting their data, improving operations, and building a technology environment that supports growth.

Man on laptop

Jump directly to the information you need:

Ransomware & Backup Recovery

Only if you test them. A backup that has never been through a full restore drill is a guess, not a plan. Attackers now target backup systems directly, encrypting or deleting them before triggering the main attack, so having backups isn’t enough on its own. They need to be immutable, isolated from your production network, and restore-tested on a regular schedule. An MSP that runs quarterly restore tests and documents the results can tell you, with evidence, whether your backups will actually work when you need them.

The average ransomware incident causes about 24 days of downtime, but that number depends heavily on backup health. Companies with intact, tested backups recover within a week 46% of the time; that drops to 26% when backups are compromised. Recovery speed is improving industry-wide: 53% of organizations fully recovered within a week in 2025, up from 35% in 2024. The businesses that recover fastest share one trait: a documented, rehearsed recovery plan rather than an improvised response.

AI Tools at Work

It can be, with the right guardrails. The real risk is ungoverned use, not the tool itself: employees pasting client data, contracts, or credentials into a public AI tool with no policy telling them what’s off-limits. Microsoft Copilot, deployed inside your Microsoft 365 tenant, respects your existing data permissions and stays inside your security boundary. Consumer ChatGPT accounts don’t offer that same containment. A written AI use policy paired with the right tool configuration is what makes AI safe.

Yes. Data entered into a consumer-grade AI tool without enterprise protections can be stored, used for model training, or exposed depending on that platform’s terms of service. This is a policy and configuration problem more than a technology problem. Enterprise versions of these tools (Microsoft 365 Copilot, ChatGPT Enterprise) commit to not training on customer data and add access controls tied to your existing permissions. The fix is moving your team to a governed, enterprise-tier tool and defining what data categories are off-limits anywhere.

Start with an enterprise-tier AI tool tied to your existing identity and access controls, not free consumer accounts. Write a short, plain-language AI use policy naming what data can and can’t be entered: client PII, financial data, proprietary source code. Train the team on it once, then reinforce it during onboarding. Review which AI tools employees are actually using, since shadow AI adoption is common, and bring anything unsanctioned under your governance rather than banning it outright.

Map AI use against whatever regulatory framework already applies to your business, HIPAA, financial services rules, client data-handling contracts, before deployment rather than after. Choose AI tools with clear data residency and retention commitments that support the access controls your compliance framework requires. Document your AI governance decisions the same way you’d document any other IT control; auditors and insurers are starting to ask for it. An MSP can build this into your existing compliance program instead of treating AI as a separate problem.

Cost & Licensing

Likely, at least on some seats. Industry data shows nearly half of licensed SaaS seats go unused, and Microsoft 365 is frequently one of the largest line items. Microsoft’s own pricing has risen too: E3 moved from $36 to $39 per user per month in 2026, E5 from $57 to $60. A license audit, matching active usage against what you’re paying for, is one of the fastest wins available in an IT budget.

Run a usage audit across every SaaS tool and license tier, not just Microsoft 365. Gartner estimates organizations waste 25 to 30% of SaaS spend on unused or underutilized subscriptions. Right-size license tiers to actual usage (a full premium license for someone who only uses email and chat is overspending), and consolidate overlapping tools, since most businesses run more collaboration and security tools than they realize. An MSP with visibility into your full stack can run this audit quarterly so waste doesn’t creep back in.

Compliance

If you create, receive, store, or transmit protected health information, as a provider, health plan, or a vendor handling that data on their behalf (a business associate), yes. This extends further than most owners expect: billing companies, IT providers with access to patient data, and some marketing vendors can qualify as business associates. The Security Rule is under active revision; HHS has pushed the anticipated final rule to mid-2027, so requirements are tightening rather than loosening. Confirm your specific obligations with compliance counsel, since applicability turns on the data you handle, not your industry label.

SOC 2 is more of a commercial requirement than a legal one for most businesses. If you sell software or services to enterprise customers, especially in finance, healthcare, or SaaS, a SOC 2 report is often what closes procurement review. It formally documents controls you likely already have: access management, monitoring, incident response. Treat it as a sales enabler and trust signal, and start readiness work early, since the audit period alone typically runs three to twelve months.

It depends on three things: the data you handle (health data triggers HIPAA, card data triggers PCI DSS, personal data of state residents triggers state privacy laws), who you sell to (defense contractors need CMMC, public companies need SOX controls), and where your customers live (Massachusetts, Rhode Island, and other states now impose requirements regardless of where your business is based). Most owners face more overlapping requirements than they realize. A compliance mapping exercise against your actual data flows and customer base is the right starting point, not an assumption based on your industry label.

Yes, and for most defense contractors it’s close to essential. CMMC 2.0 requirements became enforceable in DoD contracts starting November 2025, with mandatory third-party certification for Level 2 contracts arriving November 2026. Reaching the required 88-of-110 control score typically takes 6 to 12 months, and certified assessors are already booked out, so starting late gets expensive fast. An MSP experienced in CMMC can implement the required controls and manage the timeline so you’re not racing the clock at your next contract renewal.

If you store personal information about even one Massachusetts resident, an employee’s Social Security number, a customer’s account number, yes, regardless of company size or location. There’s no employee-count or revenue threshold. The law requires a written information security program covering encryption of data on portable devices, firewall protection, and secure authentication. Most businesses that assume this doesn’t apply to them are wrong; it’s triggered by whose data you hold, not where your office is.

The Rhode Island Data Transparency and Privacy Protection Act took effect January 1, 2026. It applies to businesses that control or process data for at least 35,000 Rhode Island residents, or 10,000 residents if more than 20% of revenue comes from selling personal data. Covered businesses must publish a clear privacy notice and conduct data protection assessments for higher-risk processing like targeted advertising or profiling. There’s no cure period: violations are enforceable immediately with no grace window, so it’s worth confirming your exposure with counsel before you approach the threshold.

Cyber Insurance

Carriers now require documented proof of specific controls before issuing a policy: multi-factor authentication across Microsoft 365, VPN, and admin accounts, endpoint detection and response (not basic antivirus), tested backups, and a written incident response plan. Questionnaire answers alone aren’t enough anymore; underwriters want screenshots, logs, and evidence. Marsh McLennan reports 41% of cyber insurance applications are denied on first submission. An MSP can close those gaps ahead of your application and assemble the documentation carriers now expect.

Premiums are rising industry-wide, not because of anything specific to your account. Analysts are forecasting 15 to 20% increases in 2026 following a sharp rise in ransomware incidents and credential theft in 2025. Businesses that can’t demonstrate current security controls are seeing renewal quotes double or more. The lever you control is documentation and maturity: businesses that can prove MFA, EDR, and tested backups are seeing smaller increases and fewer coverage exclusions than peers who can’t.

Expect a more rigorous renewal than last cycle. Carriers want evidence, not attestations: proof of MFA everywhere, EDR deployment records, documented and tested backup restores, and a written incident response plan your team has actually rehearsed. Gathering this after the renewal notice arrives puts you in a weak negotiating position. An MSP can maintain this documentation continuously so renewal becomes a formality instead of a scramble.

AI Investment & ROI

For most, yes, when applied to the right functions. Adoption is climbing fast: 68% of small businesses now use AI, and 91% of those report it boosted revenue. Reported returns run as high as $5.44 for every dollar invested, with marketing automation among the highest-performing use cases. Most businesses see their first measurable ROI within 60 days when they start with one focused use case, marketing content, customer service triage, workflow automation, rather than trying to transform everything at once.

Increasingly, yes, though results vary widely by how deliberately AI is deployed. Businesses using AI report productivity gains of 26 to 55% in the functions where it’s applied, and small businesses using AI-driven automation save an average of $7,500 a year, with the top quarter saving over $20,000. The gap between companies seeing real returns and those that aren’t usually comes down to focus: a clear use case beats broad, unstructured experimentation.

Monitoring, Detection & Response

If your business operates outside a strict 9-to-5, or holds data attackers want, yes. Ransomware operators move fast once inside a network, with a median time from initial access to encryption of just 4 to 5 days, and attacks don’t wait for business hours. Monitoring that only runs during the workday leaves a real gap that round-the-clock coverage closes.

A Security Operations Center is the team and toolset that watches your network continuously, investigates alerts, and responds to threats in real time. Building one in-house is out of reach for most small and mid-sized businesses; it requires specialized staff working shifts around the clock. What most businesses actually need is SOC-as-a-service through an MSP or managed security provider, giving you that same continuous coverage without the overhead of staffing it yourself.

This should be a defined number in your contract, not a vague promise: look for detection and response service levels measured in minutes. Organizations using AI-driven detection and response contain breaches in a median of 63 days versus 85 days for those relying on manual processes, and that gap widens further when the first alert takes hours to reach a human instead of minutes. Ask any MSP you’re evaluating for their actual mean time to detect and respond, backed by data.

AI-Driven Threats

Traditional phishing training is losing ground fast: over 82% of phishing emails are now AI-generated, and they’re clicked at more than four times the rate of older, human-written attempts because they’re personalized and well-written. Email filtering tuned for AI-generated content, ongoing simulated phishing tests using current attack patterns, and a simple, well-known process for employees to verify unusual requests (especially financial ones) matter more now than ever.

Yes, and it’s already happening at scale: 85% of organizations reported at least one deepfake incident in the past year, with average losses near $500,000 per incident. The classic pattern is a faked voice or video call from an executive requesting an urgent wire transfer. The defense is procedural, not technical: require a second verification channel, a callback to a known number, an in-person confirmation, for any financial request involving urgency or a change in payment instructions.

Choosing A Support Mode

Most growing businesses land on a blend. In-house staff bring institutional knowledge and immediate presence; an MSP brings breadth, security, compliance, 24/7 coverage, that’s expensive to replicate with one or two internal hires. The deciding factor is usually specialization: can your internal team realistically stay current on ransomware defense, compliance frameworks, and cloud architecture all at once? For most businesses under a few hundred employees, the answer favors outsourcing some or all of it.

Co-managed IT pairs your internal IT staff with an MSP, splitting responsibilities instead of replacing one with the other. Your team keeps the relationships and institutional knowledge that come from being on-site; the MSP adds 24/7 monitoring, specialized security expertise, and extra capacity during projects or absences. It’s a strong fit for businesses that already have an internal IT person or small team but need more depth than one or two people can provide alone.

Start with their track record on response time and security outcomes: ask for actual data on detection and response times, client retention, and references from businesses your size, rather than relying on the sales pitch. Confirm they carry certifications relevant to your industry (HIPAA, CMMC, SOC 2 experience) if you need them. Look at how they report results; a good provider translates technical work into business impact you can act on.

Look for documented service level agreements with real numbers attached: response time, resolution time, uptime. Ask how they handle security incidents specifically and how fast, historically. Check whether pricing is predictable (flat-rate managed services) or exposes you to surprise hourly billing. References from current clients who’ve been through an actual incident tell you more than any sales conversation will.

Cost, Budgeting & Personal Liability

Managed IT is a predictable flat monthly fee covering ongoing monitoring, maintenance, and support. Break-fix is pay-per-incident, cheaper in a quiet month but far more expensive the moment something breaks badly, since you’re paying premium rates for emergency response with no preventive work happening in between. Businesses that switch from break-fix to managed services often find the real savings come from problems caught before they become emergencies.

Move to flat-rate managed services with a clearly scoped agreement rather than hourly break-fix billing, and get specific about what’s included versus what triggers an additional charge, especially after-hours work, new projects, and hardware. Ask for a written explanation of anything outside standard scope before it’s built into an invoice. Providers who are upfront about pricing structure before you sign are a good signal of how they’ll handle billing once you’re a client.

It depends on the circumstances, your role, whether reasonable security measures were in place, and the specific law involved, so this is a question for your attorney rather than a general answer. That said, regulators and courts increasingly scrutinize whether leadership exercised reasonable oversight of cybersecurity, not just whether an attack occurred. Documented policies, board-level reporting on cyber risk, and evidence that reasonable controls were in place are what typically differentiate a defensible position from a liability problem.

Infrastructure & Tool Sprawl

Yes, this is one of the more mature, practical uses of AI in IT operations today. Predictive monitoring tools analyze patterns in hardware performance, network traffic, and system logs to flag failing drives, overloaded servers, or degrading equipment before they cause an outage. This shifts IT support from reactive to proactive, a meaningful upgrade in uptime and cost, since planned replacements are always cheaper than emergency ones.

Watch for a few concrete signals: hardware or software past its vendor’s end-of-life support date (no more security patches), recurring performance complaints from staff, systems that can’t support current security tools like modern EDR or MFA, and rising maintenance costs on aging equipment. An infrastructure assessment against these markers gives you a prioritized, evidence-based upgrade plan, worth revisiting annually since “current” has a shorter shelf life than it used to.

Yes. Once hardware or software passes its vendor’s end-of-life date, it stops receiving security patches, so any vulnerability discovered after that date stays open indefinitely. Attackers actively scan for exactly this kind of unpatched, outdated equipment because it’s a reliable way in. An inventory of what’s running past its support window, and a replacement plan for it, is one of the highest-value, lowest-drama security upgrades a business can make.

For most businesses that have added tools over several years, yes. Tool sprawl is a common byproduct of reacting to individual threats one at a time rather than following a coherent security strategy. Overlapping tools cost more, create gaps where nobody’s watching the seams between them, and add complexity that makes a real incident harder to investigate quickly. A security stack review, mapping what each tool actually does against what you’re paying for it, usually reveals real consolidation opportunities.

Fewer than most vendors will tell you; it depends more on integration than on quantity. A well-run small business security stack typically centers on a handful of core categories working together, endpoint detection and response, email security, identity and access management, and backup, rather than a dozen point solutions that don’t talk to each other. Integration matters more than adding another tool.

Security Architecture & Vendor Risk

Zero trust is a security model built on one principle: verify every access request based on identity, device health, and context, and never automatically trust a user or device just because it’s already inside your network. It replaces the older model of a secure perimeter where anything inside was assumed safe. In practice, it means multi-factor authentication everywhere, tightly scoped access permissions, and continuous verification rather than a one-time login. For businesses with remote or hybrid teams, it’s close to a baseline expectation now.

The tools that create the strongest security posture, single sign-on, managed devices, conditional access policies, are largely invisible to employees when set up correctly; the friction most people associate with security usually comes from bolted-on tools rather than an integrated approach. Multi-factor authentication tied to a simple authenticator app, combined with centrally managed devices, secures remote work without adding real steps to someone’s day.

Potentially, depending on your contracts, the data involved, and applicable law; this is worth confirming with legal counsel for your specific exposure. Many state privacy laws and industry frameworks (HIPAA business associate rules included) extend some responsibility to the business that engaged the vendor, not just the vendor itself. Contractual protections, indemnification clauses, security requirements written into vendor agreements, are your first line of defense, and vendor risk assessments before signing are what most businesses skip and later regret.

Often, more than most businesses realize. A breach at a vendor with access to your systems or data can expose you just as directly as a breach of your own network, and attackers increasingly target smaller vendors specifically because they’re a weaker link into larger, better-defended targets. A vendor risk review, what data or system access each vendor actually has, and whether that access is still necessary, is a straightforward exercise most businesses have never done.

Fewer than most vendors will tell you; it depends more on integration than on quantity. A well-run small business security stack typically centers on a handful of core categories working together, endpoint detection and response, email security, identity and access management, and backup, rather than a dozen point solutions that don’t talk to each other. Integration matters more than adding another tool.

We use cookies to improve your experience on our website. By browsing this website, you agree to our use of cookies.