Skip to content

The MSP Onboarding Checklist: Your First Two Weeks

By Donovan Brown
September 6, 2026
8 sections
Server rack lights — IT infrastructure
Photo: Massimo Botturi on Unsplash

A concrete, two-week checklist Texas business owners can use to hold a new MSP accountable — from asset discovery to backup testing to SB 2610 alignment.

01

The Manufacturer in Round Rock Who Didn't Know What He Didn't Know

A plant manager called us after his previous IT guy — a solo contractor who'd been "handling things" for six years — stopped answering his phone. Nobody had a network diagram. Nobody knew which of the eleven laptops in the front office still had local admin rights for a vendor account nobody remembered granting. The backup software was running, technically, but no one had ever tried to restore a file from it. That's not a hypothetical. That's a Tuesday in Texas manufacturing and construction, and it's the exact situation a real onboarding process is built to fix.

If you're switching MSPs — or hiring one for the first time — you deserve to know what should happen in the first two weeks, not vague promises about "getting up to speed." Here's the actual checklist we run, and what you should expect to see land on your desk by day fourteen.

02

Week One: Find Out What You Actually Have

You can't protect or support what you can't see. Week one is discovery, full stop, and it should produce documents, not just conversations.

  • Full asset inventory. Every server, workstation, switch, firewall, wireless access point, and printer, with make, model, age, and warranty status. If a device is out of warranty and end-of-life, you need to know now, not when it dies during payroll week.
  • Complete admin account audit. Every account with elevated access — domain admin, local admin, cloud tenant admin — gets listed and reviewed. Old vendor accounts and former employees with lingering access are the single most common finding in this step, and credential abuse shows up in some form in 39% of breaches according to Verizon's 2026 DBIR. That's the number one reason this audit happens in week one, not week six.
  • Backup verification with an actual restore test. Not "the backup ran last night." A file, or better, a full VM, gets restored to confirm it works. Sophos found the median cost to recover from a ransomware incident, excluding any ransom paid, runs $375,000 as of their 2026 report. Untested backups are how that number gets worse.
  • Network diagram. A real one, showing VLANs, firewall rules, VPN endpoints, and how your offices talk to each other and to the cloud. If your prior provider never handed one over, that's a documentation gap the new team needs to close immediately.
  • Firewall and router configuration review. Default credentials, outdated firmware, and open management ports get flagged here. This is also when someone checks whether remote management is exposed to the open internet — a shockingly common finding on older gear.
  • Microsoft 365 or Google Workspace tenant review. Sharing permissions, MFA enforcement status, mailbox forwarding rules, and external sharing links all get pulled and reviewed. Worth knowing: Microsoft 365 Copilot only surfaces data a user already has at least view access to — it exposes existing oversharing rather than creating new risk, per Microsoft's own documentation. That means the oversharing problem usually already exists; Copilot just makes it visible faster.
03

Week Two: Stabilize and Set a Security Baseline

Week two is where the new provider stops taking inventory and starts fixing what's broken or missing.

  • MFA rollout everywhere it's missing. Email, VPN, remote desktop, and any admin console that doesn't already require it. This is usually the single highest-impact change made in the first two weeks.
  • Patch and vulnerability baseline. Every known vulnerability gets checked against the CISA Known Exploited Vulnerabilities catalog, and a remediation clock starts. The DBIR's 2026 data shows the median time to fully remediate a KEV-listed vulnerability sitting at 43 days, up from 32 the year before — a trend moving the wrong direction industry-wide. A good MSP should be setting internal targets to beat that median, not match it.
  • Endpoint detection and continuous monitoring deployment. EDR and SIEM tooling should be live on every endpoint by the end of week two, with alerting tuned so your team isn't drowning in false positives on day one.
  • Shared and service account cleanup. Shared logins, especially for point-of-sale, accounting, or line-of-business apps, get identified and either eliminated or locked down with individual accounts and MFA.
  • Vendor and license reconciliation. Software licenses, domain registrations, SSL certificates, and vendor contracts all get catalogued with renewal dates. Losing a domain because nobody tracked the renewal is embarrassing and entirely preventable.
  • Written incident response and escalation plan. Who gets called, in what order, for a ransomware event versus a printer outage. Your provider should clearly define what's covered under business-hours support versus after-hours emergency response, so there's no ambiguity at 11 p.m. on a Saturday.
  • A 90-day roadmap document. Not a sales pitch — a prioritized list of what gets fixed, in what order, with rough timelines. If the roadmap is vague or missing, that's a sign onboarding wasn't done properly.
04

Why This Matters More in Texas Right Now

Texas SB 2610, effective September 1, 2025, gives businesses with 20 to 99 employees protection from exemplary damages in a breach lawsuit — but only if they've implemented the CIS Controls IG1 safeguards, all 56 of them. That's not a footnote for your legal team to worry about later; it's a direct argument for doing this onboarding checklist correctly and documenting it. IG1 covers a lot of the same ground listed above: asset inventory, access control, MFA, backup, and vulnerability management. An MSP that skips these steps in onboarding isn't just leaving you less secure — they're leaving you unprotected under a law written specifically for businesses your size.

05

What Should Be Sitting in Your Inbox by Day Fourteen

By the end of two weeks, you should have, in writing: an asset inventory spreadsheet, a network diagram, an admin account list with anything revoked flagged, a backup test confirmation, an MFA status report, a vulnerability remediation list with target dates, and a 90-day roadmap. If any of those are missing, ask why. A provider that can't produce documentation after two weeks probably didn't do the work — they just showed up and started billing.

06

Red Flags Worth Watching For

If your new MSP's first two weeks consist mostly of phone calls and reassurances with no documents to show for it, that's a problem. Same goes for a provider who can't tell you your own patch status, who never mentions backup testing, or who treats MFA rollout as a "phase three" item instead of week one. None of this work is exotic. It's just work that has to actually get done, in order, and written down.

07

Frequently Asked Questions

How long should full MSP onboarding really take?

The checklist above covers the critical first two weeks — discovery and stabilization. Full optimization, including deeper security hardening and long-term projects from the 90-day roadmap, typically runs another 60 to 90 days depending on how many locations and systems you have.

What if my previous provider won't hand over documentation or credentials?

This happens more than it should. A capable MSP can rebuild most of the asset inventory and network map independently through discovery tools, but you should expect this to add time and, in some cases, require a formal written request or contract review to force cooperation.

Does completing this checklist satisfy Texas SB 2610?

It covers most of the ground CIS Controls IG1 requires, but SB 2610 protection depends on documented, ongoing implementation of all 56 safeguards, not a one-time cleanup. Treat the two-week checklist as the starting point, not the finish line.

Should I expect any downtime while this happens?

Some, usually brief — MFA rollout, patching, and firewall rule changes occasionally require short reboots or reauthentication. A provider doing this correctly schedules disruptive changes outside business hours and tells you in advance.

08

Next Step

If your current provider has been in place more than two weeks and you still don't have a network diagram, an asset inventory, or a tested backup restore in writing, ask for one this week. If you're evaluating a new MSP, hand them this checklist and ask them to walk through it line by line before you sign anything. LayerLogix runs this exact process for businesses in The Woodlands, Round Rock, and across Texas, with 100% Texas-based support and over 20 years doing this kind of work. Call 888-792-8080 if you want a second opinion on what your current setup is missing.

Related Services

Need Help With Managed IT Services?

LayerLogix provides expert managed it services solutions for businesses across Houston and nationwide.

Serving Houston, The Woodlands, and nationwideGet a Free Consultation
Back to Blog
Keep Reading

Related Articles

Need Expert IT Support?

Let our team help your Houston business with enterprise-grade IT services and cybersecurity solutions.

Call NowBook a Call