Skip to content
human
renaissance
A shelf plank drawn straight beneath its unchanged brick load by two terracotta props.

Technical Debt · 5 min read

Buying an MSP? The SOC 2 Report Is Lying to You

An acquired MSP's RMM tool can detonate across every client at once. Five operational checks that find the security debt SOC 2 reports never show.

Answer summary

The practical answer

Short answer
An acquired MSP's RMM tool can detonate across every client at once. Five operational checks that find the security debt SOC 2 reports never show.
Best fit
Industry: Managed Services (MSP). Function: Technology & Security
Operating path
Technical Debt → Turnaround & Restructuring → Transaction Advisory Services
Key metric
$2.73M Average ransomware recovery cost in 2024, excluding the ransom payment itself.

The thing that detonates is the RMM, not the policy binder

Picture the diligence call. The MSP's owner shares his screen, pulls up a clean SOC 2 Type II, a current cyber policy, and a 14-page security handbook. Everyone nods. The deal moves to LOI. What nobody opened in that meeting was the one console that matters: the RMM — the remote monitoring and management tool that pushes scripts to every endpoint across every client, on demand, from a single login. That console, not the binder, is what you're actually acquiring.

A SOC 2 report tells you a set of controls were designed and operated across a lookback window. It does not tell you whether that RMM is reachable from the open internet today, whether MFA is enforced at the platform level or bolted onto individual user accounts where a session token bypasses it, or whether there's a shared break-glass admin password three former techs still remember. The paperwork describes the building. The RMM is the master key, and you find out who has copies only after the wire clears.

This is the part that makes an MSP roll-up different from any other services acquisition. When you buy an accounting firm, a breach hits the accounting firm. When you buy an MSP, a single compromise of that toolset reaches every downstream client at the same time — because reaching all of them simultaneously is literally the product. Verizon's 2025 Data Breach Investigations Report found that breaches with a third-party angle — supply-chain vectors — doubled to 30% of the total. An MSP doesn't sit near the supply chain; it is the supply chain for everyone it manages.

And that cost is anything but abstract. Sophos' State of Ransomware 2024 puts the average recovery at $2.73 million before you count any ransom paid — and in a platform strategy that figure is multiplicative, not additive, because one infected RMM seeds the entire client base. You priced EBITDA. You may have bought a contagion event with a multi-client liability tail.

When you buy an MSP, you don't buy one company's attack surface. You buy the blast radius of every client it manages, plus the one tool that can reach all of them at once.
Justin Leader · CEO, Human Renaissance

Five things to actually open on the screen-share

Compliance diligence asks for documents. Operational diligence asks the owner to log in and show you. The difference is the entire game. Here is what to demand live, ranked by how fast it kills a deal.

1. Make him log into the RMM in front of you

Don't ask "do you have MFA?" Everyone says yes. Ask him to authenticate into the RMM while you watch, then check three things: is the login page resolving on a public URL anyone can reach, is MFA enforced as a platform policy (not an honor-system toggle per user), and pull the admin account list. If there's a generic "msp-admin" account with a static password used for emergencies, stop. A single shared super-admin credential on the one tool that controls every client is a closing condition, not a finding.

2. Trace five departed techs through every system

MSPs are meticulous about offboarding client identities and careless about their own. Name five technicians who left in the last 12 months and trace each one through the RMM, the PSA, the documentation platform (IT Glue or Hudu), and the password vault. You are looking for the tech who left in March whose RMM login still works in October. Orphaned technician access to the master tool is a standing backdoor with a name attached — and it's the single most common live finding on these deals.

3. Skip the patch policy; read the scanner export

Every MSP's policy says "critical patches within 30 days." Ignore it. Ask for a raw vulnerability-scanner export across a random 10% of managed endpoints, then subtract the "first detected" date of each critical vuln from today. If the policy says 30 days and the lived average is 90-plus, you've found the gap between the sales deck and the Tuesday reality — and it usually traces back to technical debt in how security is actually implemented, not a one-time miss.

4. Find out who's running last-decade antivirus

Ask what percentage of endpoints carry real EDR versus legacy antivirus — and crucially, whether the budget clients on old AV share RMM infrastructure or network segments with the premium ones. Security across a managed fleet is a herd-immunity problem. A breach that lands on a $400-a-month client propagates up the same RMM that reaches the $40,000 client. "We only deploy EDR for customers who pay for it" means the cheapest contract sets the security floor for the whole platform.

5. Demand a restore, not a green checkmark

When ransomware hits, the backups are the first thing the attacker encrypts. Ask two questions and accept no hand-waving: are client backups immutable, and can you see an actual restore test from the last 90 days — a recovered file, not a screenshot of a "backup succeeded" message. Then ask the one that matters most: is the backup console on the same domain and identity provider as the RMM? If it is, there is no air gap. One compromise takes the production data and the safety net in the same motion.

Chart showing the rise in supply chain attacks targeting MSPs
from 2023 to 2025
Fig. 01

Now turn each finding into a number on the purchase agreement

Security findings get filed as "IT's problem" and quietly forgotten by closing. That's how you inherit them at full price. Operational gaps are MSP valuation factors, and each one belongs in a specific column of the deal model, not in a follow-up email nobody reads.

Sort every finding into three buckets, each with a different financial home:

  • Closing conditions (fix before the wire). Internet-exposed RMM, no MFA on platform admins, shared break-glass passwords, live access for departed techs. These don't get a price; they get fixed before money moves. There's nothing to negotiate when the master key is sitting in the parking lot.
  • Day-100 capital (working-capital adjustment). Tooling migrations with a hard dollar cost — say, moving 5,000 endpoints off legacy AV onto a real EDR platform. Add up licenses plus implementation labor and either deduct it from working capital or fund it out of the integration budget. It's a known check you're going to write; price it now.
  • Permanent OPEX (EBITDA adjustment). If the MSP can't hit its own patch SLA without two more security engineers it never hired, that's a permanent lift in cost of goods sold. It lowers pro-forma EBITDA, and at any reasonable multiple it should lower the price by far more than two salaries.

The leverage runs deeper than any single line item. IBM's Cost of a Data Breach Report 2024 found roughly a $2.2 million swing in breach cost between organizations with mature security automation and those running on manual checks. An MSP managing thousands of endpoints from spreadsheets and tribal knowledge isn't just inefficient — it's carrying that delta as an unpriced liability, and you'll own it the day after close.

So before the model gets locked, work the operational security posture the same way you'd work the QofE: make them log in, read the raw exports, watch a real restore, and put a dollar figure on every gap. In an MSP deal the binder is theater. The RMM is the asset and the risk in one tool — price it like it.

Sources (3)
  1. Verizon 2025 Data Breach Investigations Report (DBIR)
  2. IBM Cost of a Data Breach Report 2024
  3. Sophos State of Ransomware 2024
A panelled door ajar at night spilling warm lamplight across a herringbone floor, the corner of a worked desk visible through the gap.

Start here

Fourteen days, operator-led.

A diagnostic that names the gap before it reaches your multiple.