Hobbyist MSPs

I just left an MSP for ethical reasons about three months ago. They and all of their customers exchange servers were compromised, they refused to address it in a reasonable time, had no reasonable post exploitation plan and were literally telling us not to respond to client emails asking about the hack. They had recently promoted me from network engineer to network operations security analyst so I wasn't signing my name to that garbage, called them criminals and quit. Was a long time coming, they as an MSP were charging their clients for patching, monitoring and AV, meanwhile monitoring just meant they checked if a server went down, they never checked events on the server, many servers were years behind on patches and AV, well they didn't even check AV alerts, they help desk manager when I brought it up said "Doesn't the AV do all of that". Most companies not only have crap MSP's but also are paying for services they are flat out not getting.

/r/msp Thread