AFSL Holders: Is Your MSP Truly Protecting You—or Just Saying They Are?

Wednesday May 7, 2025

If you’ve ever paused mid-email, wondering if that strange link a colleague just clicked might be the one that spirals into a breach—you’re not alone.

Honestly? I get it. In this role, you’re carrying more than anyone sees: the compliance checklists, the client trust, the reputation of your firm. And in the background, there’s always this quiet question humming away: Are we actually protected?

The Calm Before the Breach

Here’s the part no one says out loud… Most cybersecurity problems aren’t caused by some dramatic, movie-style hacker attack. They come from small gaps—patches not applied, backups not tested, multi-factor authentication not enforced. And they often slip through because a business assumes their IT provider is “on top of it.”

But when you hold an AFSL, “assuming” isn’t a risk you can afford.

You need certainty. Documentation. Proof that your IT partner isn’t just responsive, but proactive. That they know your regulatory obligations, not just your printer model. Because if something does go wrong, ASIC won’t be looking at your MSP—they’ll be looking at you.

What Good Cybersecurity Looks Like (When You’re in Finance)

If your current MSP is truly aligned with your AFSL responsibilities, here’s what should already be in place:

  • ACSC Essential Eight controls—actively implemented, not just mentioned in a proposal once.
  • Regular vulnerability scans and patching cycles (with logs you can access).
  • Multi-factor authentication (MFA) enforced on all remote access and email platforms.
  • Ongoing user awareness training—especially around phishing and social engineering.
  • Backup and disaster recovery plans that are actually tested (not just theoretical).
  • Incident response documentation, ready to present during audits or tenders.
  • ISO 27001-aligned practices—even if not certified, the frameworks matter.

And if your MSP supports clients in financial services, they should be able to help you demonstrate compliance with CPS 234, the Privacy Act, and ASIC regulatory guides like RG 104.

The Quiet Risk of Misalignment

I’ve spoken with so many firms—smart, diligent, well-run operations—who only realise their MSP isn’t doing enough when it’s too late. A phishing scam gets through. A backup fails. A client asks for cyber documentation they can’t produce.

And then the questions begin:

  • “Why wasn’t this flagged earlier?”
  • “Is this covered under our SLA?”
  • “Why didn’t they explain what we needed to stay compliant?”

The truth? Many MSPs mean well. But they’re generalists. They don’t live and breathe ASIC bulletins or APRA circulars. They don’t see the difference between a dental practice and a boutique AFSL holder in South Yarra.

But you do. And your clients definitely do.

How to Pressure-Test Your MSP (Without Starting a War)

You don’t need to storm into Monday with a confrontation. But a quiet, firm check-in can speak volumes. Try these questions:

  • “Can you walk me through how we’re aligned to the ACSC Essential Eight?”
  • “Do we have documented incident response and breach reporting procedures?”
  • “Are our backups tested regularly, and how would we access them if needed?”
  • “Can you help us prepare for a client cyber due diligence questionnaire?”
  • “Do you maintain logs of patching, MFA enforcement, and admin access?”

If the answers are vague, defensive, or buried in jargon, it might be time to rethink who’s really keeping your firm secure.

author-image

Craig Boyle

Craig Boyle is the Co-Founder and Head of Sales & Marketing at MSP Blueshift, an award-winning Australian IT services company. With a career in the IT industry dating back to 1998, Craig has deep technical knowledge and a passion for helping businesses grow, protect, and streamline their operations. Through his writing, he breaks down complex IT and cybersecurity topics into clear, actionable insights for business leaders who want peace of mind and performance from their IT investments.

When he’s not writing or advising clients, Craig can be found at the racetrack supporting his son’s karting career.

Related Insights

View more