Back to BlogBlog

Five Cloud Protection Questions Every MSP Should Ask

Gerald Naude

Gerald Naude

Chief Operating Officer

19 August 20268 min read
Five Cloud Protection Questions Every MSP Should Ask

MSPs don’t build trust by having all the answers. They build trust by asking better questions — questions that help clients understand what they cannot afford to lose.

MSPs don’t build trust by having all the answers. They build trust by asking better questions — questions that force their clients to confront what they cannot afford to lose.

The shift from break-fix to managed services changed what clients expect. They no longer want a technician who shows up after something goes wrong. They want a strategic partner who prevents it. And nothing demonstrates strategic thinking faster than a well-placed question in a boardroom.

Here are five cloud protection questions every MSP should be asking — not just of their clients, but of their own service delivery.

01 — What cloud or SaaS data is mission-critical to your business?

This sounds obvious. It is not.

Most businesses will immediately point to email and file storage — Microsoft 365, Google Workspace, maybe a shared drive or two. But mission-critical data extends far beyond the inbox. Think CRM records (the entire sales pipeline), financial data in cloud accounting platforms, project management histories, HR records, and industry-specific SaaS applications that hold years of operational intelligence.

The reason this question matters: you cannot protect what you have not identified. And many organisations have never conducted a formal data audit of their SaaS footprint. Shadow IT compounds the problem — departments adopt tools without consulting IT, creating blind spots in the protection strategy.

As an MSP, leading this conversation positions you as the adult in the room. You are not selling backup; you are helping your client map their digital estate. That is a fundamentally different value proposition.

02 — Who is responsible for backing it up — your cloud provider, your business, or someone else?

This is the question that consistently catches decision-makers off guard.

The shared responsibility model is well-documented in every major cloud provider’s terms of service. Microsoft, Google, Salesforce — they all state clearly that they are responsible for infrastructure availability, not your data. The platform stays up; your data is your problem.

Yet a staggering number of businesses operate under the assumption that “it’s in the cloud, so it’s safe.” They conflate uptime with protection. They assume that because Microsoft guarantees 99.9% availability, their deleted, corrupted, or ransomware-encrypted data is somehow recoverable.

It is not.

Native recycle bins and retention policies are limited — typically 30 to 93 days depending on the service and licence tier. After that window closes, the data is gone. No support ticket will retrieve it.

For MSPs, this question is a powerful educational moment. It shifts the conversation from “Do we need backup?” to “Who owns this risk?” — and the answer is always the business.

03 — How far back would you need to recover data after accidental deletion, corruption, or ransomware?

Retention is where the real business conversation starts.

Consider a scenario: an employee accidentally deletes a critical shared folder. Nobody notices for six weeks. When they do, the native retention window has long expired. Without third-party backup with extended retention, that data is irrecoverable.

Now consider ransomware. The average dwell time — the period between initial compromise and detection — continues to grow. Threat actors increasingly delay encryption, lurking inside systems for weeks or months. If your backup retention only covers 30 days and the infection has been present for 60, every restore point is compromised.

This question forces a practical discussion about Recovery Point Objective (RPO): how much data loss is tolerable? For some businesses, losing a day’s work is a mild inconvenience. For others — legal firms, financial services, healthcare — losing even an hour’s data could mean regulatory non-compliance, financial penalties, or reputational damage.

The answer your client gives here directly shapes the backup policy, the retention schedule, and ultimately the cost of the solution. It is not a technical question — it is a business continuity question.

04 — How long could your business operate without access to that data?

If question three defines how much data you can afford to lose, question four defines how much time you can afford to lose.

Recovery Time Objective (RTO) is one of the most underestimated metrics in IT planning. Businesses rarely think about it until they are staring at a blank screen, waiting for a restore to complete, with clients calling and employees unable to work.

A few realities worth surfacing in this conversation:

  • Email downtime does not just mean no new messages. It means no access to calendars, contacts, attachments, and shared mailboxes. For client-facing teams, that is operational paralysis.
  • File storage recovery at scale (terabytes of SharePoint or OneDrive data) can take days, even with a good solution in place. Without one, it does not happen at all.
  • SaaS application data — CRM, ERP, project management — often cannot be partially restored. It is all or nothing, and the “all” part takes time.

The MSP’s role here is to translate technical recovery timelines into business impact. “Your full restore would take approximately 18 hours” means nothing. “Your sales team would be unable to access any client records or pipeline data for a full business day” means everything.

05 — When was the last time that data was successfully restored and recovery tested?

This is the question that separates a good MSP from a great one.

Backup without tested recovery is a promise without proof. And yet, an alarming number of organisations — including those with sophisticated IT teams — have never performed a genuine restore test. They have backup jobs running. They see green ticks on dashboards. They assume everything is fine.

Until it is not.

A backup that has never been tested is an untested hypothesis. Healthy backup jobs can still fail at restore time due to corruption, misconfiguration, compatibility issues, or simply because the recovery process was never documented or practised.

For MSPs, regular recovery testing is both a technical discipline and a business differentiator. It is the difference between saying “We back up your data” and saying “We have verified, this quarter, that your data is recoverable within your agreed timeframes.” The second statement is what earns long-term contracts and referrals.

The bigger picture: from backup vendor to strategic resilience partner

These five questions are not really about backup. They are about business continuity, risk management, and the strategic role an MSP plays in a client’s organisation.

When you ask these questions, you are doing something most technology providers never do: you are making the client think. You are surfacing risks they had not considered, challenging assumptions they had never questioned, and framing the conversation around business outcomes rather than technical features.

That is how MSPs move from being a line item on a budget spreadsheet to being a trusted advisor in the boardroom.

The businesses that thrive through disruption are not the ones with the most advanced technology. They are the ones that asked the right questions before the disruption arrived.

You never know if you do not ask.

Ready to have this conversation?

Soteria Cloud gives MSPs the platform and the tools to deliver on the promises these questions create. From automated cloud backup across Microsoft 365 and Google Workspace to granular recovery, extended retention, and verified restore testing — we help you move from selling backup to delivering resilience.

Explore the Soteria Cloud partner programme and start turning these questions into your competitive advantage.

Tags

MSPCloud protectionBusiness continuityRPORTORecovery testingMicrosoft 365Data backupSouth Africa

Share this post

Ready to strengthen your resilience strategy?

Partner with Soteria Cloud for integrated cyber protection.