RSP vs. MSP: Why the Safest Provider Doesn’t Sit Inside Your Network

A Remote Service Provider (RSP) secures and operates your website from the outside — at the network edge and the application layer — rather than installing privileged agents inside your network the way a traditional Managed Service Provider (MSP) does. That one architectural difference is why an RSP has a smaller blast radius when something goes wrong: a provider who never held the keys to your internal systems can’t hand those keys to an attacker. 

That is not a knock on the people who run MSPs. It is a statement about where the risk lives. And right now, the clearest proof of where it lives isn’t coming from vendors — it’s coming from cyber-insurance underwriters, who have quietly made the inside-the-network model one of the hardest things to insure. 

What is the difference between an MSP and an RSP? 

An MSP manages technology from inside your environment. To do its job — patching, monitoring, support — it installs remote management (RMM) tooling and endpoint agents that hold standing, privileged access across the systems it manages, usually for many clients at once. An RSP does a narrower job from outside that boundary: website security monitoring, protection, and reporting on the surface that faces the internet, without a privileged foothold on your internal network or endpoints. 

The distinction sounds academic until you ask the only question that matters in a breach: if the provider is compromised, how far does it spread? 

 Traditional MSP Remote Service Provider (like Centry Engine) 
Access model Privileged agents inside the client network (RMM, endpoints) External / edge and application layer, scoped to the website 
Blast radius if the provider is breached Can cascade across every client’s internal network Contained to website-layer access 
Standing privileged access to your endpoints Yes No 
Known supply-chain attack path Yes — through shared management tooling Not present in the same form 
Cyber-insurance risk class Among the hardest to underwrite A materially different exposure profile 

Why is “sitting inside the network” a security risk? 

Because access is shared, a single failure doesn’t stay contained. One compromised credential, or one bad update pushed through management tooling, can turn into incidents at every client that provider touches — simultaneously. Security teams call this aggregation risk, or blast radius: the damage isn’t limited to the target, it’s multiplied by everyone connected to it. 

This is not hypothetical. In a joint advisory, Protecting Against Cyber Threats to Managed Service Providers and their Customers (CISA AA22-131a), CISA, the NSA, the FBI, and international partners warned that attackers deliberately target MSPs as a route to reach their customers downstream. The 2021 Kaseya VSA attack showed the mechanism at scale: attackers compromised a widely used remote-management platform and pushed ransomware through it to MSPs and, from there, to as many as 1,500 downstream businesses at once. The tool that let one provider manage many clients efficiently was the same tool that let one attacker reach them all. 

Why are MSPs so hard to insure right now? 

Because underwriters price aggregation risk, and the MSP model concentrates it. If a carrier insures an MSP, a single event at that provider can generate claims from a dozen clients at the same time — exactly the correlated loss insurers exist to avoid. So, MSP applications face steeper scrutiny, higher premiums, and more declines than their size alone would suggest. 

The decision usually comes down to a short list of controls underwriters now expect to see enforced internally, not just sold to clients: 

  • Multi-factor authentication on remote access, RMM, and privileged accounts — not only email 
  • EDR deployed across endpoints, including the ones managed for clients 
  • Immutable or offline backups that are tested, not just scheduled 
  • Privileged access management that limits who can push changes across the client base 
  • A documented incident-response plan that covers a client-facing breach, not only an internal one 

None of that is exotic — it’s the same stack most MSPs already sell. The gap is usually that it isn’t fully applied internally, or it’s applied but never documented in a way an underwriter can verify. That documentation gap is often the real reason for a decline: not that the risk was too high, but that the submission couldn’t prove the risk was managed. 

The deeper point for a buyer is simpler. When the insurance market — an industry whose entire job is pricing risk accurately — treats the inside-the-network model as a hard risk to cover, that is an objective signal about the architecture, not a marketing claim from anyone selling an alternative. 

If you run an MSP, is an RSP a competitor or an asset? 

For an MSP, an RSP layer is more asset than threat. Much of an MSP’s hardest-to-insure exposure comes from one place: the deep, privileged access it holds inside client networks. You can’t remove all of it — that access is the job. But you can stop adding to it for work that doesn’t need it. Website security, monitoring, and operations don’t require a privileged foothold on a client’s endpoints, so running that surface through an edge-based RSP layer keeps it off your internal attack surface entirely. 

Done that way, an RSP like Centry Engine gives an MSP three things at once: a website-security service to put in front of clients under its own brand, documented and verifiable controls on that surface for the underwriting file, and less concentrated risk to answer for when a carrier asks how far a compromise of you would spread. The point isn’t to replace what an MSP does inside the network. It’s to keep the part of the work that can live outside the network from making the inside-the-network problem any bigger. 

Doesn’t a remote provider still get inside my site? 

Yes — and this is the line worth drawing carefully, because it’s where the argument has to be honest. An RSP model can include software that runs inside the website — a plugin at the application layer that gives deeper detail and faster action on the site itself. What it does not do is place a privileged agent inside your corporate network and across your endpoints, which is the MSP model and the path the Kaseya attackers used. 

So, the claim is not “a remote provider can never be compromised.” Nothing that touches your systems is risk-free. The claim is narrower and more durable: a provider scoped to the website layer has no standing privileged foothold in your internal network, so a compromise of that provider has a far smaller blast radius. Less access to lose is less access an attacker can take. 

What should you ask any provider about their access model? 

Whoever you hire, the useful questions are about reach and blast radius, not features: 

  1. What, exactly, can you reach inside my environment — the website only, or my network and endpoints? 
  1. Do you hold standing privileged access, and to how many other clients with the same tooling? 
  1. If you are breached, what is the blast radius on my business — and how is it contained? 
  1. Can you show the controls (MFA, EDR, PAM, tested backups, an incident-response plan) applied to your owns ystems, documented the way an insurer would want to verify? 

A good provider will have clean answers. The answers themselves tell you which model you’re buying — the same diligence that goes into choosing a website monitoring tool in the first place. 

Key takeaways 

Is an MSP a security risk? An MSP is not inherently unsafe, but its architecture concentrates risk: because it holds privileged access inside many clients’ networks at once, a single compromise can cascade across all of them. That’s why regulators (CISA AA22-131a) and insurers treat it as a high-aggregation-risk model. 

What is a Remote Service Provider (RSP)? A provider that secures and operates your website from the outside — edge and application layer — without a privileged foothold in your internal network, giving a smaller blast radius if the provider is ever compromised. 

Why do MSPs struggle to get cyber insurance? Underwriters price aggregation risk. One event at an MSP can trigger correlated claims across many clients, so carriers scrutinize, surcharge, or decline MSP risk more than company size alone would explain. 

Does an RSP need access to my internal network? No. It may run a plugin inside the website at the application layer, but it does not install privileged agents across your corporate network and endpoints. 

Can an MSP use an RSP? Yes — and it can work in an MSP’s favor. Moving website security to an edge-based RSP layer keeps that surface off the MSP’s internal attack surface, adds documented client-facing controls that help the cyber-insurance underwriting story, and can be delivered under the MSP’s own brand. 

Centry Engine is built as a Remote Service Provider platform — website security, monitoring, and operations run from the edge, not from inside your network. See how it works on your own sites. 

Was this article helpful?

These Terms of Use ("Terms") govern your access to and use of the Centry Engine platform ("Service"), operated by CMHWorks, LLC ("Company", "we", "us", or "our").

1. Acceptance of Terms

By accessing or using the Service, you agree to be bound by these Terms. If you do not agree, you may not use the Service.

2. Use of the Service

You agree to use the Service only for lawful purposes and in accordance with all applicable laws and regulations. You shall not misuse the Service or attempt to interfere with its normal operation.

3. Accounts and Security

You are responsible for maintaining the confidentiality of your account credentials and for all activities that occur under your account. You agree to notify us immediately of any unauthorized access or security breach.

4. Multi-Tenant Environment

The Service operates in a multi-tenant environment. Access to data is governed by role-based access control. You are responsible for ensuring your users comply with these controls.

5. Free Trial

New accounts begin with a free trial for the period stated at sign-up (no payment method required). During the trial you have full access to the Service. We will remind you before the trial ends. If you do not add a valid payment method and complete payment before the trial ends, your account is suspended as described in Section 6 — your data is retained during the retention window and no charge is made. Adding payment at any time converts the trial to a paid subscription with no interruption to your data or settings.

6. Fees, Payment, Suspension, and Data Retention

Paid features — including subscriptions, additional sites, full audits, and white-labeling — are billed at the prices shown at checkout. By completing a purchase you authorize us (and our payment processor) to charge your payment method for that purchase and, for recurring items, for each renewal term until the item is cancelled. Before each purchase you must confirm that you have read and agree to these Terms and our Privacy Policy.

Agency accounts. If your account is an agency, you are solely responsible for paying for all purchases and charges incurred anywhere within your account, including every client tenant you create and the users within those tenants. Only an account administrator may make purchases or change the subscription; users within an agency's tenants cannot incur charges on their own, and the agency remains responsible for all such fees.

Renewals and cancellation. Recurring purchases renew automatically until cancelled. You may cancel from your account; cancellation takes effect at the end of your paid term — access continues until then, you are not charged again, and you may undo the cancellation anytime before the term ends. Fees already paid for the current term are not refunded on cancellation; see Section 7.

Suspension, retention, and deletion. If your trial ends unpaid, a recurring charge fails through its grace period, or you cancel and your paid term ends, your account is suspended: operational services pause, but you can still sign in and manage billing, and your data is retained. If you add payment during the retention window, your account reactivates with no data loss. If the retention window lapses without payment, your operational data is permanently deleted in accordance with our Refund & Cancellation Policy; billing and legal records are retained as required. After deletion, resuming use of the Service requires a new subscription and prior data cannot be restored. The trial length, grace period, and retention window are set in our billing configuration and may change; the deletion date shown to you on your cancellation confirmation and in the accompanying email is the date we are held to.

7. Refunds and Cancellation

Our Refund & Cancellation Policy forms part of these Terms and is incorporated by reference. It states in full when fees are and are not refundable, how to cancel, and what happens to your data. This Section summarizes its principal terms; where this Section and that Policy differ, the Policy governs. Cancellation. You may cancel at any time, without giving a reason and without a cancellation fee. Cancellation takes effect at the end of your current billing cycle or prepaid term, and may be reversed at any point before that date.

Subscription fees are not prorated. A monthly subscription cancelled part-way through a billing cycle is not refunded for the unused remainder — the Service continues to the end of that cycle instead. Annual and other prepaid-term subscription fees are non-refundable in whole or in part, including where the Service is unused or only partially used.

Professional services are non-refundable once work has commenced. This includes consulting, assessments, compliance engagements, integrations, development, implementation and training. Work is deemed to have commenced on the earlier of the scheduled start date, the first hour recorded against the engagement, or the point at which we reserve named personnel or purchase materials for it. Deposits, retainers and mobilization fees are non-refundable from that point and are credited against the engagement fee. Cancellation before work commences is refunded, less any third-party costs already incurred and any documented preparation costs.

Third-party costs are non-refundable. These include domain registrations, SSL/TLS certificates, Microsoft licenses and subscriptions, Amazon Web Services charges, Microsoft Azure charges, Cloudflare charges, premium plugins and themes, and any other third-party software license, subscription, marketplace purchase or usage-based cloud charge procured for you. They are billed on the supplier's terms, which we cannot override. Where a supplier refunds or credits us, we pass through the amount actually received, less any non-recoverable processing fees.

Hosting. Newly provisioned hosting accounts carry a 30-day money-back guarantee on the hosting plan fee, measured from the date the account is first provisioned. The guarantee excludes the third-party costs listed above, together with migration services and software licenses, and does not apply to renewal fees, reinstated accounts, or plan changes on an existing account. Renewal hosting fees are non-refundable.

When we do refund. We will review a refund request and, where it is substantiated, issue a refund in the following circumstances: duplicate billing; billing errors, including a charge made after a validly submitted cancellation; accidental multiple purchases of the same order; and a failure to provision a paid service that is attributable solely to us. Requests must be made within 60 days of the charge. We acknowledge a request within 2 business days, communicate a decision within 10 business days of a complete request, and issue an approved refund within 10 business days of that decision, to the original payment method in the original currency. Service credits are not refunds. Where a service level agreement applies, credits under it are applied against future invoices and are the sole remedy for service level shortfalls.

Termination for cause. No refund or credit is available where we suspend or terminate the Service under Section 12.

Services purchased outside the Service. Where you purchase professional services, managed services, hosting or other offerings under a separate order form, statement of work or master services agreement, the terms of that document govern that engagement, and the Refund & Cancellation Policy governs anything it does not address.

8. Data Ownership

You retain ownership of all data you submit to the Service. We act as a processor of your data solely for the purpose of providing the Service.

9. Acceptable Use

You shall not:

10. Availability

We strive to provide reliable access but do not guarantee uninterrupted or error-free service.

11. Limitation of Liability

To the maximum extent permitted by law, CMHWorks, LLC shall not be liable for any indirect, incidental, or consequential damages arising from the use of the Service.

12. Termination

We may suspend or terminate access to the Service at our discretion, including for violations of these Terms. Where we do so for fraud, abuse, a security threat, unlawful activity or a material breach of these Terms, no refund or credit is provided and any outstanding fees for the remainder of your term become immediately due.

13. Changes to Terms

We may update these Terms at any time. Continued use of the Service constitutes acceptance of the updated Terms.

14. Contact

[email protected]

Open the full Terms of Service page

This Privacy Policy describes how CMHWorks, LLC ("Company", "we", "us") collects, uses, and protects information in connection with the Centry Engine platform.

1. Information We Collect

We collect information necessary to provide and operate the Service, including:

2. How We Use Information

We use information to:

3. Data Processing Role

For customer data, we act as a data processor on behalf of our customers, who act as data controllers.

4. Data Sharing

We do not sell personal information. Data may be shared with trusted service providers necessary to operate the Service, subject to confidentiality obligations.

5. Data Security

We implement reasonable administrative, technical, and organizational safeguards to protect information, including access controls and encryption where appropriate.

6. Data Retention

We retain information only as long as necessary to provide the Service and fulfill legal obligations.

When a term ends — by cancellation, by an unpaid trial, or by a lapsed grace period — your account is suspended rather than deleted: operational services pause, but you can still sign in and manage billing, and your data is retained. Adding payment during the retention window reactivates the account with no data loss. If the retention window lapses without payment, operational data is permanently deleted; billing and legal records are retained as required by law, and deletion cannot be reversed. The retention window is stated in our Refund & Cancellation Policy, which governs it. The exact deletion date is shown to you on your cancellation confirmation and in the accompanying email, and that is the date we are held to.

7. User Rights

You may request access to, correction, or deletion of your personal data through the Support page in your account, by writing to [email protected], or by post to the address in Section 10. Export tools are available in your account while it is active, and remain available while an account is suspended.

8. International Use

By using the Service, you acknowledge that your information may be processed in jurisdictions different from your own.

9. Changes to Policy

We may update this Privacy Policy from time to time. Continued use of the Service constitutes acceptance of the updated policy.

10. Contact

[email protected] CMHWorks, LLC, 19287 Lincoln Rd., Purcellville, VA 20132, United States.

Open the full Privacy Policy page