Choosing an MSP is a real decision — the wrong choice can take 6-12 months to recover from. Here's the framework:
Filter criteria (must-haves)
- Tennessee presence — for site visits, hardware delivery, and meaningful relationship. National MSPs serve TN but rarely show up.
- Microsoft Partner credentials — given how much business runs on Microsoft 365, this is non-negotiable
- Track record — 5+ years in business minimum; ideally 10+. MSP businesses fail constantly.
- Industry references — clients of similar size in your industry willing to take a reference call
- Insurance coverage — professional liability, errors and omissions, cyber liability minimums (commonly $1M-$5M)
- Documented SLAs — not "we respond fast" but specific response and resolution targets with penalties for missing them
Selection criteria (nice-to-haves)
- Compliance experience — if you're regulated, MSP must have done HIPAA / CMMC / SOC 2 / PCI work for clients like you
- Security maturity — they have a real security stack, real MDR partner, and can explain it in detail
- vCIO capability — not just helpdesk; senior strategic thinking available when you need it
- Tooling transparency — they tell you what platforms they use and why, not "trust us"
- Onboarding discipline — written onboarding plan with specific milestones
- Contract terms — 12-month initial term with month-to-month after, reasonable cancellation clauses
Red flags
- Cheapest quote — race to the bottom usually ends in pain
- 3+ year contract lock-ins
- Vague pricing — "depends on your environment" with no anchor numbers
- Refuses to provide references
- No insurance, no formal SLA
- Single technician operation — "MSP" of one person is a vacation/illness/burnout risk
- No documented security stack
- Generic vendor list with no rationale for choices
The interview questions to ask
- What does your typical client look like? How does my business compare?
- Walk me through what your team would do in the first 90 days of our engagement.
- How do you handle a major security incident? Have you run real incident response in the last year?
- What does my SLA actually guarantee? What's the penalty if you miss it?
- Can I talk to two clients of similar size in my industry?
- If we decide to leave in two years, what does the transition look like?
Have a different question?
Talk to a real engineer — free 30-minute consultation, no pressure pitch.
Ask Maverick
615-274-9555