I built and ran the kind of IT operation that Tidebreak now assesses. That is the whole of it, and it is the part most assessors cannot say.
Twenty-five years in IT. Eight of those years in Microsoft Consulting Services, deploying and untangling environments for organizations that ranged from regional firms to operations large enough to have their own internal politics about a domain controller. After that, VP of Engineering Services at a mid-market managed service provider, running the delivery teams that professional-services firms paid to keep their systems standing. I have held the pager. I have signed off on the migration that had to land over a weekend. I have sat across from a managing partner who wanted to know, in plain language, whether his firm was in good shape, and I have given the answer he wanted to hear because I believed it and because I was the one running the thing.
That last sentence is the reason this firm exists. So let me stay with it.
What the delivery chair can and cannot see
The view from inside a delivery team is a real view. It is not a lesser one. When you have spent years standing up environments, you develop an instinct for where the bodies are buried, because you are the one who buried some of them under deadline. You know that the backup job shows green because it completed, not because anyone restored from it. You know that the firewall rule added "temporarily" for a vendor integration is still there two years later, because removing it means a phone call nobody wants to make. You know which clients have multifactor authentication switched off for the one partner who travels and complains.
You know all of this. And here is the part that took me a long time to be honest about: knowing it does not mean you will surface it. Not because you are hiding it. Because the engagement model does not reward unprompted disclosure. The client asks, you answer, and the parts the client did not know to ask about sit exactly where they sit. The incentives are not malicious. They are structural. An MSP is paid to keep the lights on and the tickets closed. It is not paid to walk into a quarterly review and itemize the ways its own delivery has drifted from what right looks like.
I want to be precise here, because this pillar of how I talk about the work is the one most easily misread as an attack on MSPs. It is not. I ran one of those teams. The engineers I worked with were conscientious people doing demanding work under real constraints. The problem is not the people. The problem is that you cannot ask the delivery team to be the independent check on the delivery team. That is not a character question. It is the same reason a CFO does not sign her own company's audit opinion, and the same reason a CPA does not audit the books she wrote. Her professional standing depends on the fact that she did not write them.
The question I could not answer from that chair
Every firm I served on the MSP side reached the same question eventually, usually around a renewal, sometimes after a near miss, occasionally because a cyber insurance application asked something the firm could not answer. The question was always some version of this: how do we know our IT is actually in the posture we are paying for?
From inside the MSP, that question has no honest answer that I can give. I am the one being paid. My read on the environment is the read of the person who configured it. I can tell you what we did. I cannot tell you, with any independence, whether what we did was enough, because I am too close to it and because my livelihood is tied to the relationship continuing. The question is completely legitimate. It simply has no legitimate answer from the delivery team.
For a long time I treated that as just the way things were. The client asks, you reassure, everyone moves on. What changed for me was watching how often the gap between "we do the work" and "we can show the work" turned into a problem at exactly the wrong moment. A firm cannot forward tribal knowledge and a senior engineer's memory to an underwriter. It cannot hand a regulator a green dashboard and call it a risk posture. The layer of documentation that actually matters under scrutiny, the signed access reviews, the dated patch decisions, the record of who can touch what and why, is the layer that most commonly does not exist, because nobody whose job is to keep the lights on is also paid to build it.
Why I left to assess instead of operate
I could have built another MSP. I know how. I could have hung out a vCISO shingle and embedded myself in firms' security functions on a fractional basis. There is honest work in both. Neither is what I wanted to do, because neither resolves the structural problem I had been living inside. An MSP assessing IT is still the delivery team grading itself. A vCISO is on the firm's team, which is the right place to be for ongoing leadership and the wrong place to be for an independent point-in-time read. The moment you are embedded in the security function, you are assessing decisions you helped make.
What was missing was the chair I had never been able to sit in while I was operating: an independent third party who knew the MSP-delivery world from the inside, who could not be bluffed by an engineer because he had been that engineer, and whose compensation did not move based on what he found. No referral arrangement with the providers being assessed. No upsell path to managed services. No reseller relationship with the tools under review. The assessment is the deliverable, not a sales tool dressed up as one.
So the work I do now is deliberately narrow and deliberately independent. I perform point-in-time assessments of a firm's IT environment and of the performance of the MSP or IT provider the firm pays. I map what I find to recognized frameworks: CIS Controls v8.1.2 (2024) as the primary security reference, NIST CSF 2.0 (2024) for the governance tier, and the professional standard that governs the firm's own world. For a law firm that is the ABA Model Rules of Professional Conduct (as updated through 2023). For a CPA firm it is the AICPA Code of Professional Conduct (as updated through 2025), now read alongside SQMS No. 1 (effective December 15, 2025). For a healthcare practice it is the HIPAA Security Rule and Breach Notification Rule (45 CFR Part 164 Subparts C & D). For a financial-services firm it is the FTC Safeguards Rule (16 CFR Part 314, as amended 2023), SEC Regulation S-P (2024 amendments), and where the firm is New York connected, NYDFS 23 NYCRR Part 500 (Second Amendment).
The frameworks are not the differentiator. Anyone can buy a copy of CIS Controls v8.1.2 (2024). The differentiator is that I have spent years on the delivery side knowing which findings the framework will not hand you, the habits that are invisible from the inside and obvious from the outside once you know to look. That is not a framework exercise. It is a time-served one. Eleven of my twenty-five years were spent looking at someone else's environment from inside the delivery team, first at Microsoft and then at the MSP. That is the view an assessor needs and the view most assessors do not have.
The chair I built
What I do now is sign a report your MSP cannot sign, for the same reason your CFO cannot sign her own audit opinion. Independence is not a virtue I am claiming. It is a structural feature of the work, and it is the one feature I could never manufacture from the delivery chair no matter how good my intentions were.
I built the firm I would have wanted my MSP clients to have. A set of questions that would not otherwise get asked, asked by someone who knows the answers an MSP gives and knows which ones to push on, with no commercial stake in what those answers turn out to be. That is the chair. It took me twenty-five years on the other side of the table to understand why it needed to exist, and that is exactly why I am the one who can sit in it.