Association CEOs do not need to be technologists to have productive conversations with their MSP, but they do need enough visibility to understand where the organization stands, where the risks exist, and what questions are worth asking. After more than 40 years in the association space, we believe a stronger MSP partnership often starts with a few practical questions.
Where are we most exposed right now?
Every organization carries some level of risk, and a good MSP should be able to tell you exactly where your risk is elevated and why. For CEOs and senior leaders, the goal is not to manage every technical detail. It is to understand which risks require attention, investment, or follow-up.
“Leadership needs to understand which risks exist and why,” says Mark Dolesh, who leads managed services at DelCor. “If we’ve had those discussions and they ask us where they’re most exposed, we should be able to tell them exactly where we see it and what they need to do to close those gaps.”
What are our backups and how do you test them?
Backup strategies are the infrastructure equivalent of emergency exits: essential, frequently overlooked, and often only used when it’s crucial they work.
“A backup isn’t a backup unless you can restore it,” Dolesh says. “You need to make sure they’re actually testing these backups.” Ideally, your MSP will answer this question with a description of what is being backed up, where backups are stored (and whether any are offline or air-gapped), how frequently recovery testing happens, and what the restoration process looks like.
What’s not covered in our agreement that we might assume is?
This question can be the one that matters most when something goes wrong. Cyber incident response is a common example. When a breach occurs, an MSP will help, but a full forensic investigation, cyber accounting, or compliance reporting is typically outside the scope of standard managed services. Knowing that in advance means you can make arrangements before you need them instead of scrambling during a crisis.
What should we be reviewing together and how often?
A successful MSP relationship has a rhythm. Beyond resolving tickets and tackling day-to-day challenges, there should be regular, structured check-ins where progress is tracked, risks are surfaced, and both parties remain aligned on priorities and commitments. Done well, these conversations help create a shared understanding of where things stand today and where the organization is headed. In Dolesh’s experience, a well-run partnership review should cover the following:
- Current projects and initiatives
- Potential future projects and initiatives
- Notable industry trends
- Security awareness training outcomes, including failed phishing simulations and follow-up
- Ticket metrics against SLAs, and end-user feedback
Striving for a partnership, not a transaction.
The through-line in every conversation about what makes a managed services relationship work is the same: it functions best when both sides treat it as a partnership.
That word gets used a lot and means different things to different people. In this context, it means something specific: the MSP knows your organization well enough that you don’t have to start from scratch every time something comes up.
Your MSP should know where the challenges are, which systems require special attention, and what support or training your staff needs to be successful. This kind of institutional knowledge compounds over time in ways that a transactional relationship never can.
You do not need a technical background to ask better questions. You just need a clear understanding of what your organization depends on, where visibility matters, and how your MSP can help you make informed decisions. The strongest partnerships are built through regular conversations, honest answers, and the shared context that helps both sides plan, adapt, and respond with confidence.

Talk to Our Experts
Looking for more information? Have questions? We’re here to help!
Drop us a line, and we’ll get in touch right away.