If your managed IT provider set up your security stack in 2019 or 2020 and hasn’t meaningfully changed it since, you are not getting managed security. You are getting managed maintenance. Those are two different things, and the gap between them is where breaches happen.
The threat landscape has shifted faster in the last two years than in the previous decade combined, driven largely by the rapid adoption of AI tools on both sides of the attack. Attackers are using AI to write more convincing phishing lures, automate reconnaissance, and generate malware variants that evade signature-based detection. If your MSP is still handing you the same firewall rules, the same antivirus policy, and the same quarterly report it handed you in 2020, that plan was built for a different era.
What a Static Security Plan Actually Looks Like
Most organizations do not realize their security plan is stale because the reporting looks the same. Tickets get closed, patches get applied, and the monthly summary says “no critical incidents.” But look closer at what is actually in the plan.
Signs your security plan has not kept pace:
- Your endpoint protection is still signature-based antivirus rather than a behavioral EDR (endpoint detection and response) solution.
- Multi-factor authentication is optional or only applied to a handful of systems.
- There is no defined process for reviewing and revoking user access when roles change.
- Your MSP has never mentioned SIEM, log aggregation, or centralized alerting.
- Phishing simulation and security awareness training are either absent or a once-a-year checkbox.
- Nobody has reviewed your Microsoft 365 or cloud configuration against a current hardening baseline.
- Incident response is a vague promise rather than a documented, tested plan.
If three or more of those apply, your security posture is built on assumptions that no longer hold.
How AI Changed the Threat Your Plan Needs to Address
The specific mechanism matters here. AI has lowered the skill floor for attackers. Phishing emails that used to be easy to spot because of poor grammar and odd formatting are now polished and contextually accurate. Business email compromise attempts are more targeted. Credential stuffing attacks are faster and more automated.
On the defensive side, AI-assisted tools can correlate behavioral signals across endpoints, identities, and network traffic in ways that rule-based systems simply cannot. An EDR platform with behavioral analytics will catch a lateral movement attempt that a traditional antivirus product never sees, because the antivirus is looking for known bad files, not suspicious process behavior.
Your MSP’s security plan needs to account for both sides of that shift. If it was written before AI-assisted attacks became routine, it was not designed to detect what attackers are actually doing today.
What a Current Security Plan Should Include
A managed IT provider delivering security in 2025 should be able to show you a plan that addresses the following at minimum.
Endpoint protection with behavioral detection. EDR, not legacy antivirus. The tool needs to watch what processes are doing, not just what files look like.
Identity and access controls. MFA enforced across all users and all remote access points. Privileged access reviewed on a schedule. Conditional access policies that account for device health and location.
Email and phishing defense. Anti-phishing controls in Microsoft 365 or your mail platform, combined with regular simulated phishing and training that actually changes behavior.
Log collection and alerting. Centralized logging from endpoints, identity systems, and network devices. Someone needs to be looking at those logs, either through a SIEM or a managed detection service. “We collect logs” is not the same as “we review and alert on logs.”
Vulnerability management. Patching is table stakes. A current plan also includes regular vulnerability scanning and a defined process for prioritizing and remediating findings based on exploitability, not just severity score.
Incident response. A written plan that defines roles, communication steps, and containment procedures. It should be reviewed at least annually and tested through a tabletop exercise.
Cloud and SaaS configuration review. Microsoft 365, Azure, AWS, and similar platforms ship with permissive defaults. A current security plan includes periodic review of those configurations against a hardening baseline.
How to Have the Conversation With Your MSP
You do not need to be a security expert to ask the right questions. Ask your provider to walk you through what has changed in your security plan in the last 12 months. Ask specifically what they have done in response to AI-assisted phishing and credential attacks. Ask when your incident response plan was last updated and tested.
If the answers are vague, or if the response is essentially “we handle it,” that is a signal. A provider doing real security work can point to specific changes, specific tools, and specific processes. Managed security is not a set-it-and-forget-it service. It requires continuous review, and your provider should be able to demonstrate that review is actually happening.
If they cannot, you are paying for a plan that was designed for a threat environment that no longer exists.