Most people never ask the MSP what their security practice is, let alone ask for a third-party assessment of the organization. I hope this post convinces anyone looking at hiring, or who already uses, an MSP to get verification of their practices.
Look for Reduced Risk, Not Perfection
Why Executives Resist Security Initiatives
You will be hard pressed to find people asking the IT department for tighter security controls that affect them and how they do their work. So, it is likely that if a request comes from the executive office to implement tighter security controls, what they are really wanting is to implement tighter security controls on everyone else and in the background.