11 Red Flags Your Australian MSP Might Be Hiding

Somewhere in Australia today, a business is renewing its IT contract without reading it. The invoice has arrived every month for years, the help desk answers when called, and nobody has asked a hard question about what sits behind the service in a long time. That is not laziness. It is trust, and most of the time it is earned. But trust is also exactly the condition under which gaps go unnoticed, because nobody is checking.
This is not an argument for switching managed service providers. Most businesses with a competent MSP should stay exactly where they are. It is a list of specific, checkable things that separate a provider who is genuinely managing your risk from one who is simply invoicing a service agreement from a distance. Some of these are things you can ask about in a five-minute phone call. None of them require you to understand networking.
We have grouped them into the three areas where gaps tend to hide: cybersecurity, backup and disaster recovery, and day-to-day support. If more than two or three of these sound familiar, it is worth asking your provider directly rather than waiting for an incident to answer the question for you.
Cybersecurity red flags
1. Nobody can tell you when the last vulnerability scan ran
A vulnerability scan checks your systems for known weaknesses, such as software that has not been patched or a setting that leaves a door open it should not. Ask your MSP when the last one ran on your environment and what it found. A specific date and a specific answer is a good sign. "We keep everything patched" without a date attached is not an answer, it is a reassurance, and the two are not the same thing.
2. Multi-factor authentication is optional rather than enforced
Most businesses in Australia now use MFA somewhere, usually because Microsoft or their bank made them. The question is whether it is enforced, particularly on administrator and privileged accounts, the logins that can change settings, create new users or access everything at once. If a staff member can simply decline the MFA prompt or if admin accounts were never brought into the policy, the control exists in name rather than in practice. Attackers know this gap exists because it is one of the most common ways ransomware groups get in.
3. Alerts sit untouched overnight
Security tools generate alerts constantly. The useful question is not whether your MSP has monitoring tools, almost everyone does, it is who looks at the alerts outside business hours and how quickly. A genuine 24/7 security operations centre (SOC) means a person, not just a dashboard, is watching and can act at 2am on a Saturday. If every serious incident over the past few years happened to be noticed first thing Monday morning, that is not coincidence, it is a coverage gap, and ransomware does not keep business hours deliberately.
4. You hear about a major vulnerability from the news before your provider mentions it
When a significant flaw is disclosed in software your business runs, Microsoft 365, VPN appliances, accounting platforms, whatever it might be, a proactive provider is already assessing exposure and patching before most clients have heard the term. If the pattern in your business is that staff forward you a news article and your MSP responds after you ask, the relationship is reactive by default rather than proactive by design, regardless of what the contract says.
Backup and disaster recovery red flags
5. Backups have never actually been restored, only confirmed as "completed"
A backup job finishing without an error is not the same as a backup that works. Files can corrupt, permissions can break, and an incomplete configuration can quietly exclude something important for months before anyone finds out, usually during the recovery nobody wanted to need. Ask when your backups were last test-restored, not just reported as successful. If the honest answer is never, you do not currently know whether your backup strategy works. You know that it runs.
6. Nobody can give you a number for recovery time or data loss
Two figures matter here and they are worth knowing by name. Recovery Time Objective (RTO) is how long it would take to get your systems back up after something goes wrong. Recovery Point Objective (RPO) is how much data you would lose, measured in time, because it had not been backed up yet when the incident happened. A provider who manages this properly can give you both numbers for your specific environment. A provider who answers with "it depends" and stops there has not actually modelled your recovery, they have described backups in general terms.
7. Backups are reachable from the same login as production
If the same set of admin credentials that run your day-to-day systems can also delete or encrypt your backups, you do not have a backup strategy, you have a second copy of the same single point of failure. This matters enormously with ransomware, because modern attacks specifically target backups before encrypting production, precisely to remove the easy way out. Genuine protection here usually involves separate access and immutable storage, meaning the backup cannot be altered or deleted even by someone with admin rights, for a set period.
8. Nobody can tell you how far back your retention actually goes
Retention is simply how long backup copies are kept before they are deleted to make room for new ones. It matters more than people expect, because some incidents, like a slow data corruption issue or a compromise that sat undetected for weeks, are only recoverable if you can go back further than the usual few days. If this number has never been discussed for your business specifically, it was probably set by a default template rather than a decision made with your risk in mind.
Support and service delivery red flags
9. The same issue keeps reopening because tickets get closed, not resolved
Ticket volume looks good on a report. Ticket volume is not the same as problems actually going away. If your team keeps logging the same printer fault, the same login issue or the same slow application month after month, something is being closed rather than fixed, probably to hit a response-time metric rather than because the root cause was addressed. Ask how your provider measures success internally. If it is purely speed of first response, that explains a lot.
10. There is no real escalation path when something serious happens
Most support tickets are genuinely simple and a first-line technician handling them quickly is a good thing, not a bad one. The test is what happens when something is not simple, a server down, a suspected breach, data that will not open. If the answer is that you are stuck in the same queue as everyone asking for a password reset, with no clear way to get a senior engineer on the phone fast, that gap will matter most on exactly the day it matters most.
11. If your provider disappeared tomorrow, your own team could not get into your own systems
This is the one worth sitting with. Ask who has your domain registrar login, your firewall configuration, your network diagram, your admin passwords, and whether your own staff, not just the MSP, can access them if needed. A provider acting as a genuine partner documents your environment as though you might need to walk into it without them one day, even though neither of you expects that to happen. A provider holding that knowledge as leverage, intentionally or simply through poor documentation habits, has created a dependency that looks like service until the relationship ends badly.
What shows up when we take over an environment
When we onboard a new client who has come from another provider, the pattern worth naming is not that the old MSP was incompetent. Most of them were not. The pattern is that backups were usually the thing nobody had actually tested, and documentation was usually the thing that existed in someone's head rather than in a system the client could access. Those two gaps rarely cause a problem for years. Then they cause a very expensive one in a single afternoon. Neither gap requires a cyberattack to matter. A departing staff member, a failed hard drive or a ransomware note will all find them equally well.
Where Affinity MSP fits in
We built our cybersecurity practice around the idea that a 24/7 security operations centre should mean an actual person responding at 3am, not a dashboard generating a log nobody reads until Monday, which is why our monitoring, endpoint protection and email security run around the clock rather than during business hours. On the backup side, we treat a restore test as part of the job, not an optional extra, and we can tell a client their actual RTO and RPO because we have modelled it for their specific environment rather than quoting a industry-wide default.
If you want a starting point rather than a sales conversation, AffinityScan is a free, domain-based assessment that flags exposed vulnerabilities in your current setup without requiring you to end any existing relationship first. For businesses working toward a recognised baseline, our Essential 8 Framework guidance gives a structured way to benchmark where your current provider stands. And if the honest answer to several of the questions above was "I am not sure," our managed IT services team is happy to talk through what a second opinion would look like, with no pressure attached.
Frequently asked questions
What counts as a genuine MSP red flag versus a minor inconvenience?
A red flag is usually something that only becomes visible during an incident, by which point it is too late to fix cheaply: an untested backup, no after-hours monitoring, or documentation that only exists in one person's head. A minor inconvenience, like a slow ticket portal, is worth raising but rarely worth switching providers over on its own.
How long does it typically take to switch managed service providers in Australia?
Most transitions take between four and eight weeks depending on the size of the environment and how well documented it is by the outgoing provider, which is itself often the clearest test of whether red flag eleven applies to your situation.
Is it normal for a current MSP to be slow handing over documentation or access during a transition?
Some delay is normal while accounts and access are verified for security reasons. Prolonged resistance, vague answers about what exists, or demands tied to outstanding invoices are not normal and are worth raising directly or involving a third party to mediate.
How does Affinity MSP help businesses evaluate their current IT provider?
We offer AffinityScan, a free domain-based cybersecurity assessment, as a no-obligation way to see where vulnerabilities currently sit, and we are happy to walk any business through the specific questions in this article against their own environment, whether or not they end up becoming a client.



