When Your IT Provider Finds a Compliance Problem, Who Benefits From the Fix?

Keep up with IT Club
Add IT Club as a preferred source in Google Search.
Compliance can be a genuine business need and a legitimate managed service. This buyer-side guide explains how to distinguish a requirement from a provider preference, what evidence to ask for and when independent challenge is worth the cost.
Your IT provider reviews your security and finds six things that need fixing. Conveniently, it can sell you all six fixes.
Does that mean the recommendations are wrong? No. An IT provider may be the person best placed to spot a weakness, explain it in context and repair it quickly. It is entirely legitimate for that work to be charged as a project or an ongoing managed service.
But it does mean you should understand who benefits from the decision. Compliance is increasingly discussed as a commercial opportunity for managed service providers as well as a way for customers to protect data, win tenders and satisfy a customer or regulator. That commercial model is not dishonest by itself. It simply creates an incentive that a sensible buyer should be able to see and test.
A provider making money from a recommendation does not prove the recommendation is unnecessary. It does mean the recommendation should come with evidence, alternatives, a clear risk explanation and a transparent price.
The quick answer
Trust your provider where that trust is earned — but keep enough knowledge, evidence and control to challenge its recommendations.
- Ask whether the recommendation is a legal, contractual, scheme or certification requirement.
- Ask what risk it reduces and what evidence supports it.
- Ask whether an existing product or process can meet the same need.
- Ask for one-off and recurring costs, including exit and renewal costs.
- Ask the provider to identify where it benefits commercially.
The important distinction
There is a useful difference between a genuine customer need and every possible product or service that could be sold in response to it.
| Question | What it tells you |
|---|---|
| What is the requirement? | Whether the pressure comes from law, a customer contract, a tender, a scheme or an internal risk decision. |
| What outcome is needed? | The security or governance result the business must achieve, rather than a product name. |
| What are the options? | Whether several proportionate ways exist to meet the requirement. |
| What is already in place? | Whether an existing Microsoft 365, endpoint, backup or business process can do part of the work. |
| What happens if we do nothing? | The practical risk, contractual consequence or certification impact — not just a sales label. |
Those categories should not be blurred together. A business might genuinely need Cyber Essentials, a defined information security management system, stronger access controls or better evidence for a tender. That does not automatically mean it needs every licence in a provider's preferred stack.
The MSP incentive chain
A compliance conversation can follow a perfectly understandable commercial chain:
ASSESS → FIND GAP → RECOMMEND FIX → SELL FIX → MANAGE FIX → RENEW
One provider can potentially participate financially at every stage. That may be efficient: the provider knows the environment, has access to the systems and can remediate a problem without a second supplier learning the basics.
The buyer's job is not to break that chain. It is to make sure the chain is visible enough to challenge.
For example, the current Cyber Essentials requirements cover five technical control themes. They do not turn a particular firewall, antivirus product or compliance portal into a universal purchase. The question is whether the organisation's in-scope technology and processes meet the applicable requirements and whether it can answer the assessment accurately.
ISO 27001 is similarly a framework for an information security management system within a defined scope. Certification is not a promise that every conceivable risk has disappeared, and it does not generally require one vendor's platform. A tool may help collect evidence, assign actions or maintain records. That can be useful. It is still a solution choice, not the same thing as the requirement.
The UK GDPR also uses a risk-based approach. The Information Commissioner's Office describes the obligation as implementing appropriate technical and organisational measures and being able to demonstrate that approach. It does not prescribe a single security product or a universal training timetable for every organisation.
This is why the sentence “the standard requires our platform” deserves a calm follow-up question: “Where does the standard say that, and what other ways did you consider?”
Do we actually have to do this?
Make this a normal question, not an act of rebellion. Ask your provider to classify each recommendation as one of the following:
- 1Mandatory requirement — a law, regulation, contract, tender or scheme requirement that applies to your situation.
- 2Certification or assessment requirement — something the relevant scheme, assessor or certification body requires for the defined scope.
- 3Sensible risk reduction — not mandatory, but a proportionate way to reduce a known business risk.
- 4Recommended best practice — a useful improvement whose priority depends on your circumstances.
- 5Provider preference — a way the provider prefers to configure or operate a service.
- 6Optional improvement — worthwhile perhaps, but not necessary to solve the stated problem now.
A good recommendation can move between categories as circumstances change. What matters is that the provider does not present all six as equally compulsory simply because they appear in the same proposal.
The product-stack problem
Compliance and security projects can expand quickly. An initial review becomes an endpoint product, an email security product, a backup product, vulnerability scanning, awareness training, monitoring, a compliance platform, consultancy and a new monthly management fee.
Some or all of those may be justified. The practical buyer question is: what risk or requirement does each item solve, and do we already own something capable of solving it?
Duplication is not always waste. Separate controls can provide useful defence in depth, and a managed service can be valuable even when the underlying software already exists. But the provider should be able to explain the additional outcome rather than relying on fear, a badge or a vague promise that “more security” is always better.
Read: Are You Paying Twice for IT Security? →
The IT Club “Show Me” test
For every significant compliance recommendation, ask the provider to show you:
| Show me | The buyer question |
|---|---|
| Requirement | What requirement are we satisfying? |
| Evidence | Where does the framework, regulator or contract actually say this? |
| Risk | What happens if we do not do it, and how likely or serious is that outcome? |
| Options | Are there alternative ways to meet the same requirement? |
| Existing tools | Can something we already pay for solve some or all of it? |
| Cost | What is the one-off cost, monthly cost, renewal cost and exit cost? |
| Benefit | Who benefits commercially from this recommendation? |
That final question is deliberately challenging but does not need to be accusatory. Try: “If you were not selling the solution, would you still recommend exactly the same thing?” A good technology provider should be able to explain its reasoning without treating the question as disloyalty.
When independent challenge makes sense
Businesses do not need to separate their adviser and implementer in every case. Splitting the work can create delay, duplicated discovery and an argument about who owns the result. A capable provider may be the most efficient route.
Independent challenge is particularly useful when the project is expensive, the requirement is disputed, the proposed architecture changes a major business dependency, certification readiness is at stake or the assessor is also selling a substantial remediation programme.
Be clear about roles. A consultant may advise. An implementer may configure systems. A certification body or auditor assesses against its scheme or standard. Those roles can overlap commercially, but the person who sells a product should not be allowed to turn a sales preference into an unexplained certification rule.
Read: How Do You Prove Your Business Can Be Trusted? →
Read: Can You Move Microsoft 365 Away from Your Current Provider? →
What good looks like
A trustworthy MSP or compliance adviser should be comfortable:
- Distinguishing requirements from recommendations.
- Showing authoritative evidence without hiding behind jargon.
- Offering alternatives and explaining trade-offs.
- Acknowledging when an existing product is sufficient.
- Identifying its own commercial interest.
- Allowing independent review where proportionate.
- Recommending no purchase when no purchase is necessary.
The provider may still recommend a large project. The difference is that you can see why it is needed, what it will change, what it will cost and how success will be measured.
The question to keep asking
Recurring revenue is not inherently bad. Businesses often genuinely benefit from ongoing security monitoring, evidence collection, training and compliance support. A monthly relationship can be more useful than a once-a-year scramble before a tender or audit.
Recurring dependency is the problem. It appears when a business cannot explain what its services do, cannot access its own evidence, cannot challenge the recommendation and cannot leave without losing the ability to operate.
Your IT provider can be your adviser, implementer and ongoing support partner. Just make sure you are still the customer — not the business model.
Sources and further reading
This article uses the following sources and distinguishes their roles: Brigantia's source article describes compliance as a recurring commercial opportunity for MSPs; the following public guidance explains the requirements and assurance context for buyers.
Brigantia: How MSPs can turn compliance into a recurring revenue opportunity →
NCSC: Cyber Essentials overview →
NCSC: Cyber Essentials Requirements for IT Infrastructure v3.3 →
Plain-English Takeaway
Recurring revenue is not inherently bad. Recurring dependency is. Let your provider explain the requirement, show the evidence, offer proportionate options and identify its commercial interest before you approve a growing stack of compliance services.
Related Articles
Could Your Business Keep Running If Its Owner Died Tomorrow?
Death is the ultimate key-person test. This practical guide helps small businesses find the digital dependencies that could stop communication, money, customer delivery or recovery if an owner or key person became unavailable.
Read articleIs Your Website Actually Backed Up? Why a Cloud Website Still Needs a Recovery Plan
A website being hosted in the cloud does not automatically mean your business has an independent backup or a tested recovery plan. Learn what a useful website backup should protect, how GitHub can help, and what recovery questions to answer.
Read articleWhen Does a Business Need a Fractional Project Manager?
Many important technology projects fail not because of technical problems but because nobody owns delivery. A fractional project manager can provide experienced project leadership for a defined period without creating a permanent role — but success still depends on clear authority, executive sponsorship and realistic scope.
Read article