Key Takeaways
Selling advisory and managed compliance services creates a liability profile that differs from break-fix IT. This operator guide shows MSPs, MSSPs, and cybersecurity consultancies how to write outcome-safe scope, separate advice from operation, define client responsibilities, align contract terms with insurance, and keep delivery records that support the position if a client is breached. It is operational guidance, not legal advice.
A managed service provider that adds vCISO, risk assessment or managed compliance to its catalogue takes on a different kind of exposure than it had selling patching and helpdesk. The service is judgement, and judgement is judged after the fact. When a client later suffers an incident, the question is rarely whether the provider was busy. It is whether the provider said what it would do, did it, and told the client what remained their decision.
This guide is for the operator: the founder, practice lead or service-line owner at an MSP, MSSP or cyber and GRC consultancy who signs the contracts and carries the risk. It is operational guidance on how to structure scope, terms and records so that they hold together. It is not legal advice. Contract law, professional liability rules and insurance wording vary by jurisdiction, so use qualified counsel and a broker who understands professional services before you standardise anything below.
Start by naming what you are actually selling
Most liability trouble begins with a scope that quietly promises more than the price supports. “We will manage your security” and “we will make you compliant” sound like reasonable sales language. As contract language they can be read as an undertaking to achieve a result.
Separate the offer into three layers and price and paper each one:
- Advise. You assess, recommend, prioritise and report. The client decides and acts. Typical vCISO work, risk registers, policy drafting and framework gap analysis sit here.
- Operate. You run a control or process on the client’s behalf, such as monitoring, vulnerability scanning cadence, access review coordination or evidence collection. You are accountable for running it as described.
- Assure. You give an opinion about the state of controls. Be careful here. Independence rules and regulator or certification-body expectations may restrict who can give which kind of opinion, and an assessment you deliver is not the same as an auditor’s certification.
Each service line should say which layer it is in. A single engagement can span layers, but the agreement should say which activities fall where. If the sales deck says “fully managed compliance” and the statement of work says “advisory support,” the deck is the document a client will quote.
Write scope as activities and deliverables, not outcomes
An outcome-based promise transfers the client’s risk to you without your control over the variables. Passing an audit depends on the auditor, the client’s behaviour throughout the audit window and the state of systems you may not operate. Avoiding a breach depends on attackers and on decisions the client makes daily.
Prefer scope language built from things you can actually deliver:
- the assessments, workshops and reports included, and how often
- the frameworks and control sets referenced, and the version or edition used
- the systems, entities, locations and business units in scope, and those explicitly out of scope
- response and delivery times for defined requests, distinguished from resolution times
- the tools or platform you use to deliver, and who administers them
- the number of review cycles or revisions included before change control applies
Then add a plain statement of the objective the client is pursuing, described as the client’s goal that your activities support, not as a guarantee you give. Sales teams sometimes resist this because it sounds weaker. It sounds weaker only to buyers who were about to rely on a promise you cannot keep, and those are the buyers who become disputes.
Write client responsibilities as deliverables too
Delivery depends on the client doing things: granting access, naming control owners, supplying evidence, approving changes and acting on findings. If the agreement is silent on these, you carry the delay and the blame.
List client responsibilities as concretely as your own. Name the roles, the inputs and the time allowed for a response. State what happens to timelines and fees when inputs are late. Record that remediation decisions, budgets and prioritisation sit with the client, and that recommendations are advice until the client accepts them.
The same applies to the client’s own attestations. If you rely on information the client provides, say so, and say that you do not independently verify it unless verification is part of the paid scope. That single sentence often decides whether a later argument is about your work or about the client’s inputs.
Make risk acceptance a recorded event
The most valuable document in an advisory relationship is often the one that shows you recommended something and the client chose otherwise. Building that into the process is inexpensive and much more persuasive than recollection.
Build a simple pattern:
- Issue findings with severity, rationale and a recommended action.
- Ask the named client owner to respond: accept, schedule, reject or transfer.
- Record who responded, when and in what channel, with any stated reason.
- Bring accepted risks back for review at a defined interval so acceptance is not permanent by default.
Keep the response tied to a person with authority to accept the risk, not a helpdesk contact. If a finding remains open with no response, escalate in writing through the contractual channel and record the escalation. A managed GRC platform or ticketing workflow can hold this record consistently across accounts, but the discipline matters more than the tool.
Align limitation clauses with insurance and with the buyer
Contracts commonly cap the provider’s liability and exclude certain kinds of loss. What is enforceable, reasonable or customary differs by jurisdiction, by client type and by what the client’s own regulators require, so the wording is a matter for counsel. What an operator can do is make sure three things are in the same conversation.
The cap and the cover. Ask your broker what your professional indemnity and cyber policies would respond to, under which conditions, with which exclusions and at what retention. A cap that sits far above your realistic cover leaves the difference on your own balance sheet. A cap that sits far below what your buyer expects will meet resistance in procurement, especially from larger or regulated clients.
The service and the exclusions. Policies can carry conditions about the services you provide, the claims-made notification window and contractual liability you assume beyond what the law would impose. If your paper promises an outcome, an insurer may treat that promise as liability you took on by contract. Check this with the broker before you reuse a template.
The paper and the buyer. Enterprise and public-sector buyers often bring their own terms and may negotiate the cap. Decide in advance which clauses are firm, which have a pre-approved fallback and who is authorised to approve a deviation. A deal desk rule as simple as “anything outside the fallback goes to the practice lead and counsel” prevents one-off promises from becoming your real standard.
Where the client’s cyber insurance depends on controls being in place, remember that your service may be part of the client’s representations to its own insurer. Be precise about what you did and did not implement, so the client does not describe your advisory work as an operated control on an application form.
Keep advice and operation from bleeding into each other
The riskiest situations arise when an advisory engagement drifts into operation without a change in paper. A vCISO who begins approving firewall changes, an analyst who starts closing tickets on the client’s behalf, or a consultant who becomes the de facto owner of a control can each create a duty nobody priced or insured.
Guard against drift with a few working rules:
- Route any request that moves from advice to action through change control, with a written scope amendment.
- Keep operated activities in the service catalogue with their own service description, so they are visible to whoever reviews delivery.
- Do not accept named-owner status for client controls unless it is in scope. Advisers can support an owner; they should not silently become one.
- Review each account at a set interval to check the work being done still matches the paper.
Talent adds pressure here. A junior analyst under time pressure will say yes to a client request that a practice lead would refuse. Give delivery staff a short list of requests that need escalation and make it acceptable to say that something is outside scope.
Keep the delivery record that supports your position
If a client is breached, the first useful question is what you knew, what you advised and what the client decided. The answer should not depend on someone’s memory or on searching several inboxes.
A workable record for each account includes:
- the signed agreement, statement of work and every amendment
- dated deliverables such as assessments, risk registers and board or executive reports, with version history
- findings and recommendations with client responses and recorded risk acceptances
- the list of systems and entities in scope at each point in time
- meeting notes with decisions and named attendees
- evidence of who owned each remediation action and its status
Retention periods and access rules should follow your legal advice and the client agreement. Store client-specific records so that one tenant’s material cannot leak into another’s, and agree what happens to them at the end of the contract.
Handle incidents without changing the story
Incidents test the paper. Two habits help. First, agree in the contract how each party notifies the other, what each is expected to do and who speaks to regulators, insurers and affected people. Second, when something goes wrong, preserve the record and route external statements through counsel before anyone offers an admission or a promise of compensation in an informal message.
Also decide in advance how your own team reports an internal error, such as a missed review or a misapplied change, to the client. Prompt, factual disclosure is easier to defend than a delayed one, and your contract and insurance may require notice within a set period.
A practical rollout for the practice
You can tighten this without rewriting every contract on day one.
- Inventory. List every live service and the wording on its scope, any outcome language in proposals and the liability clauses in current agreements.
- Classify. Mark each service as advise, operate or assure, and note where an account has drifted.
- Consult. Take the inventory to counsel and your broker. Ask specifically about outcome promises, caps, exclusions and notification conditions.
- Standardise. Produce one set of scope templates by layer, a client-responsibilities schedule and a risk acceptance workflow, with approved fallbacks.
- Train. Brief sales, delivery and account management on what can and cannot be promised, and who approves deviations.
- Migrate. Apply the new paper at renewal or through a negotiated amendment, starting with the highest-risk accounts.
- Review. Revisit the templates after each significant claim, near miss or change in cover.
What good looks like
A practice that has done this work can explain in a sentence what each service does and does not include. Its proposals do not contradict its contracts. Its clients have written records of the decisions they made, and its delivery staff know when to escalate. Its liability terms have been read against its insurance rather than copied from a template.
None of this removes risk. Advisory work will always be judged with hindsight. What it does is make the exposure something you chose and priced rather than something you discovered after a client’s bad day.
Where GetCybr fits
GetCybr provides a shared GRC operating layer for partners delivering recurring risk, compliance and vCISO services across client tenants. It can hold findings, recommendations, client responses and evidence records in one place per account, mapped to recognised frameworks, while your practice keeps responsibility for scope, judgement and contract terms. If you are standardising how your service line records advice and decisions, book a demo to see how that workflow can run in one platform.
Ready to Scale Your vCISO Practice?
See how GetCybr helps MSPs deliver enterprise-grade security services.


