Cloud Core MSP can provide selected identity, endpoint, email, monitoring, vulnerability, awareness, documentation, backup, and incident-coordination capabilities. Effective security also depends on supported systems, current access, client decisions, and coordinated changes.
How security services work
Available capabilities depend on the endpoint package and other security services purchased for the environment. Layered controls reduce risk and improve visibility, response, and recovery readiness, but they do not prevent every incident or guarantee a compliance or insurance outcome. The client retains governance, policy, insurance, legal, and compliance responsibilities where applicable.
Available security capabilities
- Identity and access controls, including multi-factor authentication, named administrative access, sign-in policies, and user lifecycle support.
- Endpoint and email protection, security telemetry, alert review, and standard remediation for covered systems.
- Logging, monitoring, and response coordination for supported data sources included in the selected service.
- Vulnerability scanning, prioritized remediation recommendations, and corrective-work tracking.
- Staff security awareness, simulated phishing, completion records, and follow-up reporting.
- Security documentation, technical safeguard support, evidence collection, and control-review assistance.
- Backup monitoring and recovery support for systems with a purchased backup service.
- Incident planning, escalation coordination, and initial containment actions. Full incident response, forensics, legal support, and major recovery remain separate professional services.
Operating responsibilities and dependencies
- Keep covered operating systems and applications within supported versions and allow required monitoring, patching, and security tools to operate.
- Provide timely access approvals, accurate information, and designated decision-makers for security and remediation work.
- Use multi-factor authentication for administrative and remote access and maintain named, accountable administrator access.
- Notify Cloud Core MSP of significant changes and coordinate administrative, vendor, identity, network, and cloud changes that can affect security.
- Maintain required vendor relationships, subscriptions, licensing, logging sources, and backup services.
- Participate in remediation decisions when budget, operations, user experience, legacy systems, or business requirements affect the available response.
- Maintain appropriate password, access, onboarding, and offboarding practices throughout the organization.
When a material risk remains
Cloud Core MSP documents material risks and recommended action through the appropriate support record, report, email, planning document, or service review. Leadership can then evaluate the operational effect, cost, timing, and any specialist guidance needed.
If required access is removed, a significant remediation is delayed or declined, or uncoordinated changes make a service unsafe or unreliable to operate, Cloud Core MSP may limit the affected service until the condition is resolved and will explain the reason and operational impact.
- Examples include unsupported systems, missing MFA, unavailable backups, shared administrator accounts, exposed services, weak vendor access practices, or unmanaged devices touching business systems.
Incident coordination and containment
During a suspected or confirmed incident affecting covered systems, Cloud Core MSP may take reasonable initial containment actions and coordinate escalation to reduce immediate exposure and support continued response.
- Disable or reset accounts.
- Isolate endpoints or servers.
- Restrict network access.
- Block suspicious sign-ins or forwarding rules.
- Suspend exposed services.
- Preserve relevant logs where available.
- Escalate to vendors, cyber insurance contacts, counsel, or incident response partners when authorized.