Skip to content

Reference

MSP glossary

The acronyms and terms buyers hit when shopping for managed IT — defined in plain English. If you spot a term missing, tell us and we'll add it.

BAA

Business Associate Agreement

A HIPAA-required contract between a healthcare organization (covered entity) and any vendor that touches Protected Health Information. Establishes each party's responsibilities for safeguarding PHI. Required with every MSP, cloud provider, email host, and backup vendor a clinic uses.

BEC

Business Email Compromise

A category of attack where a threat actor impersonates an executive, vendor, or trusted party via email — usually to redirect a payment or steal credentials. One of the most financially damaging attack types for small business.

BYOD

Bring Your Own Device

A policy that lets employees use personal phones or laptops for work. Requires mobile device management (MDM) controls to keep business data separate and remotely wipeable without touching personal data.

CMMC

Cybersecurity Maturity Model Certification

A US Department of Defense cybersecurity certification required for contractors and subcontractors handling Controlled Unclassified Information (CUI). Tiered levels; most defense-adjacent SMBs need Level 2.

CSP

Cloud Solution Provider

A Microsoft partner program that lets resellers sell and manage Microsoft 365 and Azure licensing on behalf of customers. CSPs typically provide first-line support and consolidated billing.

EDR

Endpoint Detection and Response

Security software installed on laptops, desktops, and servers that continuously monitors for suspicious behavior (not just known malware). Modern replacement for traditional antivirus. Examples: SentinelOne, CrowdStrike, Microsoft Defender for Business, Sophos.

EMR / EHR

Electronic Medical Record / Electronic Health Record

Software used by clinics to store patient records, billing, and clinical workflows. Common in the US: Epic, Athenahealth, eClinicalWorks, Dentrix (dental), Eaglesoft (dental).

HIPAA

Health Insurance Portability and Accountability Act

US federal law that governs the privacy and security of Protected Health Information (PHI). Includes the Privacy Rule, Security Rule, and Breach Notification Rule. Applies to healthcare providers, insurers, and their vendors (business associates).

Intune

Microsoft's cloud-based Mobile Device Management (MDM) and endpoint management platform, part of Microsoft 365 Business Premium and higher. Enforces device configuration, application deployment, and compliance policies across Windows, macOS, iOS, and Android.

IR runbook

Incident Response runbook

A documented, step-by-step procedure for responding to a cybersecurity incident. Includes who to call, containment timelines, forensic partner contacts, breach notification obligations, and insurance carrier communication.

M365

Microsoft 365

Microsoft's productivity cloud, including Outlook, Exchange Online, SharePoint, Teams, OneDrive, and (at higher tiers) Intune, Defender, and Azure AD / Entra ID.

Managed IT

A pricing and delivery model in which an outside IT firm handles a business's day-to-day technology operations — help desk, monitoring, patching, backup, cybersecurity, and vendor management — for a predictable monthly fee, usually per user.

MDR

Managed Detection and Response

A 24/7 Security Operations Center (SOC) staffed by human analysts who monitor endpoint and network alerts (typically from an EDR product) and respond to threats in real time. The "human eyes" layer on top of EDR tooling.

MFA

Multi-Factor Authentication

A security requirement that a user proves identity via at least two of: something they know (password), something they have (phone, security key), or something they are (biometric). Table stakes for any account handling business data.

MSA

Master Services Agreement

The umbrella contract between a client and MSP covering scope, service levels, pricing, liability, and termination terms. Individual engagements sit under it via Statements of Work (SOWs).

MSP

Managed Service Provider

A company that delivers managed IT services (see above) to other businesses. Contrast with break-fix (per-hour billing) and internal IT (in-house employees).

NAP

Name, Address, Phone

The three fields Google (and other search engines) use to identify a local business across the web. Consistency across your website, Google Business Profile, and directory listings directly affects local search rankings.

On-prem

On-premises

Software or infrastructure that runs on hardware physically located at the customer's office (or their colocation facility), rather than in a cloud data center.

PCI DSS

Payment Card Industry Data Security Standard

A security standard required for any business that stores, processes, or transmits credit card data. Enforced by the card brands (Visa, Mastercard, etc.) via merchant acquirers, not by law.

PHI

Protected Health Information

Any individually identifiable health information — patient records, appointment history, billing, insurance data. Protected under HIPAA and equivalent state laws.

PSA

Professional Services Automation

The core business software MSPs use to manage tickets, time, billing, and client relationships. Examples: ConnectWise Manage, Autotask, HaloPSA.

RMM

Remote Monitoring and Management

The agent software MSPs install on client endpoints and servers to monitor health, deploy patches, and remotely support users. Examples: NinjaOne, Datto RMM, ConnectWise Automate.

SIEM

Security Information and Event Management

A platform that aggregates security logs from across an environment (firewall, endpoints, identity provider, cloud infrastructure), correlates them, and alerts on threat patterns. Typically used at 50+ endpoints or when compliance requires centralized log retention.

SLA

Service Level Agreement

A specific, measurable commitment about service quality — e.g., "15-minute response during business hours" or "99.9% uptime." Real SLAs include remedies (credits) when missed.

SOC

Security Operations Center

A team of security analysts (usually 24/7) who monitor alerts and respond to threats. Can be internal, outsourced, or provided as part of an MDR service.

SOC 2

An independent audit report demonstrating that a service organization's controls meet specific criteria for security, availability, and confidentiality. Common requirement from enterprise customers evaluating SaaS or MSP vendors.

Still fuzzy on a term?

Book a 20-minute call and we'll translate everything on your current IT provider's proposal into plain English.