In the fifth of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
In Dickens’ Great Expectations, Pip dreams of wealth and status, only to discover that blind trust leads to heartbreak. Today, many organisations share Pip’s optimism when outsourcing IT and cybersecurity to Managed Service Providers (MSPs), believing that once the contract is signed, their cyber worries vanish. The reality? Outsourcing doesn’t eliminate risk; it often magnifies it.
MSPs promise expertise, 24/7 monitoring and cutting-edge tools. For overstretched IT teams, this illusion of safety sounds like salvation. Likewise, Boards often assume that an MSP equals immunity. Yet, Jacques Fourie, Director of Information Security at Kocho, highlights a dangerous trend:
“On the whole, UK businesses are very trusting of their MSPs’ abilities to withstand attacks …… research does also suggest that at least some of this confidence might be misplaced.”
In a ‘Ghosts of Breaches Past’ moment, there are a few UK examples of that misplaced trust. In 2025 attackers compromised Jaguar Land Rover (JLR), halting global production and costing the UK economy an estimated £1.9 billion. As has previously been published, JLR’s cybersecurity and IT operations at the time of the 2025 breach were supported under a £800 million outsourcing and digital transformation contract with Tata Consultancy Services (TCS). Perhaps in retrospect, not the best £800 million JLR has ever spent.
Elsewhere, CTS, a large UK Managed Service Provider featured on the BBC news in November 2023 when they were hit by a catastrophic cybersecurity breach which disrupted hundreds of UK law firms, leaving homebuyers stranded and legal systems offline for weeks. But in this case, that attack was possibly more damaging to CTS Group than it was to their clients. The bit that wasn’t widely publicised was that the disruption led to financial pressures on CTS Group forcing it into administration and 6 months after the breach, the managed service provider was sold to Bluecube.
A bit closer to home and rather more personal, we were contacted by a small business owner who knew one of our Directors and needed some help. The company had lost the entire contents of their current account just over a week previously and couldn’t work out what had happened. We started to investigate but the week’s delay didn’t help. In outline, the CEO’s account had been hijacked some months previously and the attackers sat waiting for a suitable payment to be scheduled to a supplier and then changed the bank details and the amount. How did it happen? Outsourced IT and Cyber Security to an MSP who had set up the O365 instance in its default configuration, didn’t impose 2FA and only five days logging. And their cyber security skills? Someone had done the CEH course. Result, a bank balance of ££s rather than ££,£££ and no ability to pay either their supplier’s invoices or staff wages. Hence the company closes and nearly a dozen people lose their jobs.
As Dickens might say, “The chains of complacency are forged link by link.” Over-reliance on MSPs without rigorous oversight creates a single point of failure.
There is absolutely no doubt that MSPs provide an invaluable role in delivering IT services effectively and are frequently cheaper than what can be achieved in house. But, you should treat your MSP as a partner, not a saviour and have well defined SLAs for security, incident response and breach notifications. Alan Shimel warns:
“You can outsource execution, but you can’t outsource responsibility. When your provider fails, the consequences fall on you, not them.”
Therefore, your team really should maintain in-house oversight for critical functions and ask some targeted questions before you sign the contract with an MSP, specifically these ones:
How many suitably qualified and experienced cyber security professionals do you have?
- What qualifications have they got?
- How many will be working primarily on our account?
What cyber specific certifications and compliance standards do you hold?
How do you prioritise your managed detection and response when more than one client is attacked?
How do you protect against supply chain attacks?
What visibility and reporting will we have?
And a final Dickensian Closing Thought. Pip’s downfall was blind faith in “Great Expectations.” Don’t let yours be the same. In the world of cyber risk, optimism without oversight is folly. MSPs can be valuable allies, but only if you hold them accountable. Otherwise, your business may star in its own Bleak House of Breaches.