MANAGED SECURITY PROVIDER COMPARISON Instructions: Give each provider the same asset list and scenarios. Copy these fields for each proposal. Record written evidence, missing answers and who will resolve each gap. Do not put credentials or sensitive logs in this form. Organization / evaluator / date: ____________________ Provider / proposal version / verified contact: ____________________ Covered users, devices, servers, email, cloud and networks: ____________________ Explicit exclusions and onboarding method: ____________________ Missing agent/log-feed detection: ____________________ RESPONSIBILITY RECORD (repeat for each activity) Activity: inventory / monitoring / investigation / containment / recovery / communication / access administration / provider incident / transition One accountable owner: ____________________ Contributors and subcontractors: ____________________ Authority to act and required approval: ____________________ Evidence and handoff to next owner: ____________________ Unresolved gap / action owner / due date: ____________________ RESPONSE COMMITMENTS Coverage hours and time zone: ____________________ Severity definitions: ____________________ Acknowledge / investigate / contain / restore commitments: ____________________ Clock start, pauses, exclusions and escalation: ____________________ Primary and backup customer contacts: ____________________ Provider-compromise notification and continuity plan: ____________________ SAME FICTIONAL SCENARIO FOR EACH PROVIDER Saturday: an unfamiliar finance-account sign-in adds a forwarding rule. What data would you receive? ____________________ Who investigates and what evidence do they seek? ____________________ Who can revoke sessions or disable the account? ____________________ Who is called if the first contact is unavailable? ____________________ What timeline and audit evidence will we receive? ____________________ Repeat for a failed backup and an unavailable provider. COMMERCIAL AND EXIT CHECKS Setup and recurring cost / pricing unit: ____________________ Extra incident, after-hours, restore, storage and export charges: _____________ Term / renewal / cancellation / transition: ____________________ Ownership and export of logs, accounts and configuration: ____________________ Provider/subcontractor access, MFA and access logging: ____________________ Evidence supporting claims, including scope and date: ____________________ ACCEPTANCE AND DECISION [ ] Reconciled proposed coverage with the inventory. [ ] Defined responsibility and authority for each activity. [ ] Agreed harmless test event, handoff test and recovery exercise. [ ] Reviewed legal/procurement obligations with appropriate advisers. Decision and reasons: ____________________ Conditions before signing / owner / deadline: ____________________ Source context: NCSC provider-selection guidance; local contracts and rules need their own review. This is a procurement aid, not a legal agreement. https://www.ncsc.gov.uk/guidance/choosing-a-managed-service-provider-msp Yenra | Updated September 9, 2026 Guide: https://yenra.com/mss-managed-security-service/