MSP Glossary
Plain-English definitions of the terms MSPs use every day.
A
-
All-You-Can-Eat Pricing
A flat monthly fee per user or site that covers unlimited support within a defined scope, with no hourly billing for covered work.
B
-
BDR (Backup and Disaster Recovery)
The combined service of image-based backup plus the ability to run client systems again after failure, usually a local appliance replicating to vendor cloud.
-
BEC (Business Email Compromise)
Fraud conducted through a compromised or spoofed business mailbox to redirect payments, and one of the largest cybercrime loss categories for SMBs.
-
Break/Fix
The reactive IT support model where the client calls when something breaks and pays for the time and parts to fix it, with no recurring fee.
-
Business Continuity Plan
A client-owned document describing how the business keeps operating through a disruption, of which the technical disaster recovery plan is one part.
C
-
Churn Rate
The share of clients (logo churn) or recurring revenue (revenue churn) an MSP loses over a period, usually measured annually.
-
CIS Controls
A free, prescriptive set of 18 security controls whose IG1 tier serves as the baseline security checklist for small organizations and MSPs.
-
Client Offboarding
The structured process of ending a managed services relationship, returning client data and credentials and removing the MSP's access and tools.
-
CMMC
The US Department of Defense certification program that verifies contractors and subcontractors protect federal contract information and controlled unclassified information.
-
Compliance
Demonstrable conformance to an external standard such as HIPAA, SOC 2, CMMC, or PCI DSS, proven with evidence a third party can examine.
-
CSP (Cloud Solution Provider) Program
Microsoft's channel licensing program through which MSPs resell and administer Microsoft 365 and Azure, usually as indirect resellers via a distributor.
-
Cyber Insurance
Insurance covering losses from breaches and cyber attacks, carried both by the MSP itself and by its clients, whose underwriting questionnaires set the security baseline.
D
-
DRaaS (Disaster Recovery as a Service)
A subscription service that replicates client systems to a provider's cloud and can boot them there when the primary site or hardware is lost.
E
-
Endpoint
Any managed device running the MSP's agents, counted as a billing and tooling unit, including workstations, servers, mobile devices, and sometimes network gear.
-
Endpoint Detection and Response (EDR)
Endpoint security that records system behavior, detects attacker activity that signature antivirus misses, and lets a responder isolate and remediate the machine remotely.
-
Escalation
Handing a ticket from the technician working it to a higher tier with more skill, authority, or time, triggered by defined criteria rather than judgment.
F
-
First Call Resolution
The percentage of tickets resolved by the first technician who handles them, without escalation, reassignment, or a second client contact.
G
-
GDAP (Granular Delegated Admin Privileges)
Microsoft's time-bound, role-scoped model for partner access to customer tenants, replacing the legacy DAP standing-admin model.
H
-
HaaS (Hardware as a Service)
A model where the MSP bundles client hardware into the monthly fee, owning the equipment and its refresh cycle.
-
HIPAA
The US federal law governing the security and disclosure of protected health information, binding healthcare organizations and the IT providers that serve them as business associates.
I
-
IAM (Identity and Access Management)
The discipline and tooling for managing who a user is, how they authenticate, what they can access, and how that access is granted and revoked over time.
M
-
MDR (Managed Detection and Response)
A per-endpoint service in which an outside provider's analysts monitor EDR telemetry around the clock, investigate alerts, and contain threats on the MSP's behalf.
-
Monthly Recurring Revenue (MRR)
The sum of all contracted, repeating monthly fees an MSP bills, excluding projects, hourly work, hardware, and one-time charges.
-
MSP (Managed Service Provider)
A company that takes ongoing responsibility for a client's IT operations, support, and security for a fixed recurring fee rather than hourly billing.
-
Multi-Factor Authentication (MFA)
Authentication that requires a second proof of identity beyond a password, with phishing-resistant methods like FIDO2 keys and passkeys at the strong end.
N
-
Network Monitoring
Continuous automated observation of a client's network infrastructure and attached devices for availability, performance, configuration changes, and unexpected traffic.
-
NIST Cybersecurity Framework
The US government's voluntary, risk-based cybersecurity framework, organizing security programs under six functions from Govern to Recover.
-
NOC (Network Operations Center)
A team that watches infrastructure health and remediates operational faults, as distinct from a SOC, which detects and contains attackers.
P
-
PAM (Privileged Access Management)
Controls and tooling that govern accounts with elevated rights by vaulting credentials, granting elevation just-in-time, and recording privileged sessions.
-
Patch Management
The recurring process of testing, deploying, and verifying operating system, firmware, and third-party application updates across every managed endpoint and server.
-
Peer Group
A paid, structured cohort of non-competing MSP owners who share financials, benchmark against each other, and hold one another accountable on a fixed schedule.
-
Penetration Testing
An authorized, human-driven attack simulation that demonstrates what a real attacker could achieve, as opposed to automated vulnerability scanning.
-
Per-Device Pricing
A managed services pricing model charging a flat monthly fee for each managed workstation, server, or network device regardless of who uses it.
-
Per-Seat Pricing
A managed services billing model that charges a flat monthly fee per supported user, covering all of that person's devices and support, also called per-user pricing.
-
Phishing
A social-engineering attack that uses email, messages, calls, or fake login pages to trick a person into surrendering credentials, approving payments, or running malware.
-
Professional Services Automation (PSA)
The business system of record for an MSP, combining ticketing, time tracking, contracts, billing, projects, and CRM in one platform.
Q
-
QBR (Quarterly Business Review)
A scheduled meeting between the MSP and a client's decision-maker that reviews service performance, security findings, and the technology roadmap and budget.
R
-
Ransomware
Malware that encrypts systems and demands payment, now paired with data theft for double extortion and aimed at MSP tooling as a way to hit many clients at once.
-
Remote Monitoring and Management (RMM)
The agent-based platform an MSP uses to monitor, patch, script, and remotely control every managed endpoint across all clients from one console.
-
RPO (Recovery Point Objective)
The maximum amount of data, measured in time, a client can afford to lose between the last good backup and a failure.
-
RTO (Recovery Time Objective)
The maximum acceptable time a system or business function can be down after a failure before the outage causes unacceptable harm.
-
Runbook
A step-by-step procedure for one specific recurring technical task, written so any technician can execute it correctly without prior knowledge of the environment.
S
-
Security Awareness Training
Managed employee training plus phishing simulation that reduces human-factor risk and satisfies a standard cyber-insurance control.
-
Shadow IT
Applications, services, and devices employees use for work without IT's knowledge or approval.
-
SLA (Service Level Agreement)
The contractual attachment defining the support targets an MSP commits to, chiefly response time by priority, and the remedy when it misses.
-
SLO (Service Level Objective)
An internal, measurable service target you aim for and report on, as distinct from the SLA you contractually guarantee.
-
SOC 2
An AICPA attestation report in which an independent CPA firm evaluates a service organization's controls against the Trust Services Criteria.
-
SOC (Security Operations Center)
A team that monitors security telemetry around the clock, triages alerts, investigates suspicious activity, and contains confirmed threats.
-
SOP (Standard Operating Procedure)
A written, approved description of how the MSP performs a recurring business or operational process, distinct from a technical runbook for a single ticket type.
-
SSO (Single Sign-On)
Authentication once with a central identity provider that then grants access to every connected application without separate passwords.
T
-
Technical Account Manager
A named, non-selling point of contact who owns the technical relationship with a client account between the service desk and the strategy conversation.
-
Technology Stack
The fixed set of tools, platforms, and configurations an MSP standardizes on and deploys across every client it supports.
-
Ticketing System
The software, usually the PSA's ticket module, that records every unit of service desk work as a ticket with time, status, and history.
V
-
Value-Based Pricing
A pricing approach that sets the fee by the economic value the service delivers or protects for the client rather than the MSP's cost to deliver plus a markup.
-
vCIO (Virtual CIO)
A fractional executive role, usually filled by the MSP, that owns a client's technology strategy, roadmap, budget, and quarterly business review.
-
vCISO (Virtual CISO)
A fractional executive role that owns a client's security program, risk decisions, compliance posture, and decision authority during incidents.
-
Vulnerability Management
The continuous cycle of scanning for, prioritizing, and remediating security weaknesses across an environment.
Z
-
Zero Trust
A security model in which no user, device, or network location is trusted by default and every access request is verified and limited to least privilege.