Back to Business

What Makes a Good MSP? What Actually Separates the Good Ones

What Makes a Good MSP? What Actually Separates the Good Ones

Read ten MSP websites and you will find the same five sentences, reworded ten different ways. Proactive monitoring. Fast response times. A dedicated account manager. Enterprise-grade security. A partnership, not just a vendor relationship. Every provider says this, because every provider knows it is what buyers have been told to look for. The result is a checklist that filters out almost nobody, because almost everybody passes it on paper.

That does not mean the checklist is wrong. It means it stopped being useful once every MSP learned to write to it. If you want to know what makes a good MSP versus an average one, you need to look at the things that are harder to put on a homepage: how a provider is paid, how deep their team actually is, and how they behave in the situations a contract does not fully cover.

 

The Standard Checklist Is a Floor, Not a Filter

Certifications, service level agreements, vendor partnership tiers, communication style — these are worth checking, and a provider that fails them is a real warning sign. But passing them only tells you a provider is competent enough to write a good sales page. It does not tell you whether they will be the ones who catch a misconfigured backup before it matters, or the ones who discover it during a ransomware recovery.

To get past that, it helps to ask about three things most checklists skip entirely: what the provider is financially rewarded for, who is actually doing the work, and what happens outside the neat scenarios their contract describes.

What the Billing Model Actually Rewards

This is the least discussed and most revealing part of choosing an MSP. Time-and-materials billing pays a provider more when something breaks and takes longer to fix. Flat-fee, all-inclusive managed services pay the same regardless of how much goes wrong, which means the provider's financial interest is in fewer incidents, not more billable hours.

Neither model is dishonest, and plenty of good technicians work under both. But the incentive shapes behaviour over time in ways that are difficult to see from the outside. A provider paid by the hour has less reason to invest time in the unglamorous, invisible work — patch management, documentation, monitoring tuning — that prevents problems rather than resolving them. Ask a prospective MSP directly how they are paid and what that means for how they prioritise preventative work. A provider with a good answer to this question has usually thought about it before you asked.

Who Is Actually Behind the Ticket

A dedicated account manager sounds reassuring until you realise it can also mean a single point of failure. The more useful question is not who your primary contact is, but how deep the team is behind them: what happens if that person is on leave, what the technician turnover looks like, and whether senior engineers are involved in day-to-day support or reserved for projects while junior staff work through the ticket queue.

None of this is visible in a sales pitch. It shows up in how long issues take to escalate, how often you repeat the same explanation to different people, and whether the person fixing your problem understands why it happened, not just how to close the ticket.

How They Behave Outside the Happy Path

Every MSP looks good when a laptop needs a new hard drive. The differences show up in the messier cases: an outage at 11pm on a Sunday, a fault that sits ambiguously between your internal network and an ISP issue, a request that falls just outside what the contract technically covers.

In our experience, this is where the gap between providers is widest and most consequential, because it rarely gets discussed until it happens. A provider worth working with treats an edge case as a problem to solve rather than a contract clause to enforce. That does not mean unlimited free work — it means judgement, and a bias toward fixing the actual problem in front of them before arguing about whose fault it is. Ask a provider directly how they have handled a situation like this in the past. Vague or defensive answers are worth noting.

Security as a Default, Not a Line Item

One of the clearest tells is whether basic security is included in the base service or quoted separately as an add-on. Multi-factor authentication, patching, and immutable backups (backups that cannot be altered or deleted, even by someone with admin access, which matters when ransomware specifically targets backup systems to prevent recovery) are not advanced extras in 2026. They are baseline hygiene, and a provider that treats them as upsells is telling you something about where security sits in their priorities.

A reasonable benchmark here is the Australian Cyber Security Centre's Essential Eight, a set of baseline mitigation strategies designed for Australian organisations. It is worth asking any prospective MSP where they sit against it, and treating a confident, specific answer very differently from a vague one.

 

Questions Worth Asking Instead of a Checklist

A few questions tend to surface more than a certifications list ever will:

  • How are you paid, and how does that affect what you prioritise?
  • What happens if my main point of contact leaves the business?
  • Can you show me a redacted example of a monthly report a client actually receives?
  • What is included in the base fee, and what becomes a separate quote?
  • Tell me about a time a client's problem fell outside the contract. What did you do?

None of these require technical knowledge to ask, and the quality of the answer says more than any accreditation logo.

Where This Leaves You

Checklists exist because they are easy to write and easy to publish. They are not wrong, they are just no longer diagnostic, because every MSP has learned to score well on them. The things that actually separate a good provider from an average one — incentive structure, bench depth, and behaviour under pressure — are harder to fake and harder to fit on a homepage, which is exactly why they are worth asking about directly.

If you are already unsure how your current provider or internal setup stacks up against a baseline like the Essential Eight, a free AffinityScan assessment is a low-effort way to see where things stand before you make any changes.


FAQ

What is the biggest difference between a good MSP and an average one?
Usually it is not visible in a sales pitch. It shows up in how the provider is paid, how deep their engineering team is beyond your main point of contact, and how they handle situations that fall outside the strict terms of the contract.

Should I choose a flat-fee or time-and-materials MSP?
Both models can work well. Flat-fee arrangements generally align the provider's financial interest with preventing problems, while time-and-materials can suit businesses with irregular or project-based needs. The important step is understanding which model a provider uses and asking how it shapes their priorities.

How do I know if an MSP's security is genuinely comprehensive?
Ask whether measures like multi-factor authentication, regular patching, and immutable backups are included in the base service or billed separately, and ask where they sit against a recognised framework such as the ACSC Essential Eight.

Is a dedicated account manager a good sign?
It can be, but it should not be the only measure. Ask what happens if that person is unavailable, and how experienced the wider team supporting them is.

AffinityMSP
AffinityMSP
Back to Business