MSPs have moved from the data center to the boardroom
MSPAlliance CEO Charles Weaver has watched the profession for 26 years. He explains how MSPs left the data center to advise CEOs on AI risk and governance.
MSPs have left the data center
The managed services profession used to have a simple job description. Keep the technology running. Fix what breaks. Make sure the lights stay on.
That era is over. Today, MSPs and IT teams are sitting across the table from CEOs, advising on AI risk, data liability, and governance questions that would have seemed unrecognisable to the profession even five years ago.
Charles Weaver has watched every step of that journey. As CEO and co-founder of MSPAlliance, the global standards and certification body for the managed services profession, he has spent 26 years at the intersection of where the industry was and where it is going. The shift he is watching now is unlike anything that came before. What he sees happening now, he says, has nothing to do with technology.
"MSPs have left the data center," he says. "They are now in the boardroom. They are now in the c-suite."
When chaos became community
Charles was not an IT guy in the way that most MSPs are. He had a law background and was an editor at internet.com and got to the channel when his conversations in the application services space kept pointing him toward MSPs.
What drew him to the space was not technology itself but the gap he could see opening up between the law and the world it was supposed to govern. Data protection, data privacy, IT security, none of these were conversations anyone was having in legal circles at the time. "They did not call it cybersecurity at that time," he says. "Nobody was really talking about that type of thing." He could see that was going to change, and that when it did, the people building and running technology infrastructure were going to be at the centre of it.
What he found when he got there stopped him in his tracks. The profession was building itself entirely in isolation. MSPs viewed one another as competitors. Information sharing was almost nonexistent. What was happening in the profession was very difficult to extract, and even more difficult to share with the service providers who arguably needed it the most. Everyone was facing the same issues, arriving at the same conclusions independently, but had no way to share what they had figured out.
In 2000, he brought five colleagues together to start MSPAlliance. "You have to talk to each other because you are not going to learn from anybody else other than the person in this room," he says.
This had never happened before. Before peer groups existed, before industry conferences, before anyone else thought to do it, MSPAlliance was putting MSP executives in a room together. The channel press did not understand what MSPs did. Analysts did not understand it. End users certainly did not. The only people who could help MSPs figure things out were other MSPs, and they were not talking to each other.
Those conversations unlocked something. Patterns began to surface. Common practices, common failures, common pressures that different MSPs had been navigating alone for years. "They were all just arriving at that same conclusion independently," he says. Every other established profession, legal, medical, accounting, engineering, had common professional characteristics and traits that the community shared. The MSP community at that time had none of those. That observation became the mission. By 2004 those patterns had become a formal control framework, the first of its kind built specifically for MSPs. Standards followed, then certifications, then a global audit programme. Today MSPAlliance counts over 30,000 members worldwide.
"If we're not going to have direct oversight and regulation from the government, then self-governance is paramount," he says. "Self-regulation comes with the responsibility of having self-imposed barriers of what the profession expects of the professional."
The profession had built its foundations. Then AI arrived and changed the equation entirely.
AI raises the stakes
For years, talent was the profession's biggest constraint. AI cut through a problem the profession had been wrestling with for years.
"That level one NOC or SOC technician has now largely gone away," says Charles. "I wouldn't say that's necessarily a bad thing, because the MSPs absolutely needed to figure out a way to scale that lower level of technical and security talent."
But AI did something more significant than solve a staffing problem. It dropped a set of questions into the profession's lap that nobody had ever had to answer before.
The doorway to the boardroom
Over the last few years, MSPs have started using AI, largely through tools that vendors have built it into. The most reputable players in the channel are using AI inside their own practices. They are not exposing it directly to customers. Not yet.
The caution is deliberate. Reputational concerns, uncertainty about user experience, and liability questions with no clear answers are all holding them back.
Charles cites the example of a 20-person law firm. A practice that decides to deploy Microsoft Copilot without asking the right questions first is not just making a technology decision. It is making a legal and ethical one. Where does confidential client data go? What are the firm's obligations to their clients? "You would not just want to turn on an AI system that was available on your computer," he says. "You would want to talk to somebody like an MSP and say, what is my exposure?"
That question is now arriving in every sector. A medical office. An HVAC company with a government contract. A small manufacturer handling sensitive supply chain data. The specifics differ but the shape of the problem is the same: AI introduces liability questions that most organisations are not equipped to answer alone. "How should we use this AI for our purpose and not get exposed to increased liability?" Charles says. "That is the fundamental question of at least the next decade. We're going to be wrestling with this issue, and the MSP is going to be central to that question."
For the SMBs and mid-sized businesses that MSPs serve, the pressure is even more acute. They were already losing ground, the time, cost, and expertise required are beyond most of them. "And I think that that's the biggest opportunity we could have asked for," says Charles. He sees tremendous upside for the profession over the next couple of decades, built almost entirely on its ability to guide clients through AI safely and well.
This is where that shift becomes concrete. MSPs are not just fixing technology anymore. They are sitting in rooms where business risk is being assessed, compliance obligations are being mapped, and decisions with legal consequences are being made. "They are now advising the executives on both technical security and data privacy, but also business and business risk items and questions," Charles says. The community, he says, is going to learn more than it ever thought it would care to know about non-technical business governance and risk governance. "It's new, I admit that it's new," he says, "but it's also a very important role evolution for the MSP because it means that they have arrived. It means that they have finally proven themselves as a trustworthy entity worthy of being inside the boardroom."
Certification has become one of the primary ways MSPs are learning to operate at that level. When an MSP helps a customer work through a SOC 2, an ISO audit, or a CMMC level two certification, roughly half of the controls being reviewed fall under the MSP's remit. Working through those controls is a crash course in risk management that goes well beyond whether the backup is running. "The non-technical outcome is not just does the firewall work," Charles says. "It's how does that fit into the larger risk picture that the customer is now facing."
Not every MSP is ready for this. Charles accepts that. But he is clear about the direction. "The vast majority of the community at large has already shown that it's going to be quite comfortable and needed in the boardroom." The entire industry, he says, is evolving by the day. On the job, in real time.
The catch with AI
The risk in all of these cases is not really an AI problem. It is a data security problem. And data security is the MSP's domain.
"AI and cybersecurity are identical," Charles says. "They cannot be separated." What that means in practice is that any business wanting to adopt AI needs to have its cybersecurity controls in proper working order first. Not at the same time. Not as an afterthought. Before. The MSP has to be in the room before the AI gets switched on, not called in after something goes wrong. "It's first to implement cybersecurity and effective IT controls in the organisation, and then, and only then, can they implement effective AI, manage it correctly, make sure that it's achieving the business outcome that the customer wants," Charles says. "I think that's going to be the repeatable cycle that every MSP goes through with every one of their customers."
For small and mid-sized businesses, this makes the MSP more important than ever. "There's no chance they are going to be able to do all of that themselves," Charles says. "They're going to need help, and that help is certainly going to come, as it always has, from the MSP."
Governments are arriving at the same conclusion. "How do you use AI safely and securely?" Charles says. "That is the pivotal question of the next several decades." The White House recently announced a national AI framework, effectively asking Congress to act on artificial intelligence at a federal level. MSPAlliance is in the process of writing a position paper in response. The argument: you cannot talk about AI governance without talking about managed services.
What has changed is that the government is now capable of having that conversation in a way it simply was not before. Twenty-six years ago, legislators did not understand what MSPs did. The questions were too technical, the profession too new, the gap too wide. "The quality of the knowledge in the public policy and legislative community is far better," Charles says. They understand what a well-run MSP looks like. They also understand what a poorly run one looks like, and what the consequences can be. MSPAlliance is also actively helping government do the work of separating legitimate MSPs from those operating outside the standard the community has built. "We're trying to help government figure out who is a good, legitimate MSP and who is outside that bucket," Charles says.
The questions being asked now are not about what MSPs are. They are about what MSPs can do. Governments across the US, Canada, and Europe want to know whether the MSP community has the capability to help defend against national cybersecurity threats. "They know absolutely today that MSPs play a vital role," Charles says. "They just don't know how to use the MSP." That gap, between recognising the profession and knowing how to deploy it, is where MSPAlliance is doing some of its most significant work.
Stepping it up
Twenty-six years in, MSPAlliance spends most of its time doing something that would have been unimaginable when it started: preparing MSPs for certification and audit. Organisations of all sizes, across the world, coming to demonstrate that they meet the standard the industry has spent three decades building. "We know what the best practice is," Charles says. "You don't have to guess. But now you have to prove it."
Anyone can set up as an MSP. The barrier to entry is low, and that is not a bad thing. It keeps the market open and competitive. But it also means the profession has to hold itself to a standard from the inside. That is the role MSPAlliance occupies as the certifying body for the managed services profession.
That shift, from figuring out what good looks like to requiring people to demonstrate it, is a measure of how far the industry has come. It is also a measure of how much the outside world has changed around it. Governments that spent years not knowing what an MSP was are now asking them to help defend national infrastructure. Businesses that used to hand over their IT and ask no questions are walking into conversations with lawyers and compliance officers, wanting to understand exactly what their provider is doing with their data. Cyber insurers have quietly raised the bar for everyone. The questionnaires MSPs face today when applying for coverage look nothing like they did five years ago. They have become a full-scope internal examination of how an MSP operates. An MSP that has been through proper certification already has the answers. Everyone else is finding out the hard way.
The next challenge is reach. Most MSPs that have not yet been certified are smaller operations, and the cost and complexity of going through a formal certification process has kept many of them from getting there. Using AI to bring that cost down and simplify the process is where Charles is focused right now. Every day, every week, MSPAlliance is making progress toward that goal, small achievements and sometimes big ones, inching toward a reality where certification is within reach for more of the channel.
The generational handoff is already happening. The MSPs who built the profession from scratch in the mid-90s, figuring things out with no playbook and no peers, are now selling and exiting their businesses. New generations are coming in.
The next generation coming into the channel will inherit something the founders of the profession never had: a body of knowledge built over three decades that can solve 80, 90 percent of the problems they will face. Charles recently joined the advisory board of Chico State's computer sciences department and will be a guest lecturer in the fall, bringing these conversations into the classroom. The remaining problems, the ones nobody has figured out yet, will be theirs to work through. That, he says, is exactly how it should be.
The industry that once had no rules is now helping write them for the rest of the world. "It's scary and exciting at the same time," Charles says. "That is not a bad place to be after 26 years."