The Phantom Standard

    Not every MSP is built the same. Here's why that matters — and what we do differently.

    What Is The Phantom Standard?

    At Phantom, we believe managed IT shouldn't just keep the lights on — it should protect your business, satisfy your insurance carrier, support your compliance obligations, enable smart adoption of automation and AI, and hold up under scrutiny. The Phantom Standard is our internal benchmark for how we build, deliver, and maintain IT environments for every client we serve.

    It's not the minimum. It's the floor — and it's set deliberately higher than most of the industry. Every recommendation we make is filtered through one question: does this advance the client's business strategy? Our vCIO program is how we operationalize that alignment.

    This page explains what that standard includes, why we built it this way, and what the real risk looks like when an MSP cuts corners.

    What The Standard Covers

    Six pillars that define how we build, secure, and manage every client environment.

    Security Frameworks

    • Controls aligned to NIST CSF and CIS Controls
    • Endpoint detection and response (EDR) on every managed device
    • Multi-factor authentication required across all services
    • Regular vulnerability scanning and patch management
    • Security awareness training for client staff

    Cyber Insurance Alignment

    • We document your environment to meet carrier audit requirements
    • Our configurations satisfy common underwriting controls (MFA, EDR, backups, least privilege, etc.)
    • Clients are coached on how to accurately answer applications — and backed by documentation if questioned
    • Our Guardian Compliance tier is purpose-built for organizations with active insurance mandates

    Compliance & Regulatory Readiness

    • HIPAA-aligned configurations for healthcare clients
    • Support for CMMC and DFARS requirements for defense contractors
    • SOC 2 preparation support for service-based organizations
    • Documentation and evidence packages for audits and reviews

    Documented Processes & Accountability

    • Everything is documented: configurations, change logs, incident response procedures
    • Clients receive regular reports — not just alerts
    • Service delivered under a formal MSA, not a handshake deal
    • Escalation paths and response SLAs are defined, not improvised

    Operational Maturity

    • Tooling reviewed and updated against current threat landscape
    • Internal staff trained on evolving frameworks and threats
    • Vendor relationships maintained with tier-1 security and infrastructure providers
    • Change management process prevents configuration drift

    Partnership, Not Just Support

    • We advise on technology decisions — including where automation and AI fit — not just fix what breaks
    • Regular vCIO business reviews to align IT spend and roadmap with your strategy
    • Transparent communication about risk — we tell you what you need to hear
    • We are accountable to your outcomes, not just your ticket queue

    Built for the Insurance Conversation

    Cyber insurance carriers are tightening requirements. Premiums are rising, coverage is narrowing, and claims are being denied on the basis of misconfiguration or missing controls.

    Most MSPs deliver what they always have. Phantom builds environments that hold up to the underwriting process — and keeps the documentation to prove it.

    Whether you're renewing a policy, applying for the first time, or facing a post-breach audit, our environments are designed to give you the evidence you need.

    Insurance-Ready Controls

    • Multi-factor authentication enforced
    • EDR/MDR active on all endpoints
    • Privileged access controls documented
    • Backup strategy tested and verified
    • Security awareness training in place
    • Incident response plan on file
    • Patch management SLA enforced
    • Email security (DMARC, SPF, DKIM) configured

    Our Guardian Compliance tier is designed specifically for organizations with active compliance obligations or insurance mandates.

    The Cost of a Lower Bar

    Choosing an MSP is a risk decision. A lower price buys you a lower standard — and that gap has real consequences.

    Cyber Insurance Claim Denied

    Carrier discovers MFA wasn't enforced. Claim denied. Business absorbs $200K+ loss.

    Ransomware with No Recovery

    No tested backups. Attacker encrypts everything. Recovery costs exceed $50K with 2+ weeks of downtime.

    Compliance Violation

    HIPAA audit finds gaps in PHI access controls. Provider faces OCR investigation and civil penalties.

    Personal Liability Exposure

    Board-level inquiry after breach finds no documentation of security decisions. Leadership faces personal liability.

    Insurance Renewal Failure

    Renewal questionnaire answered incorrectly due to poor MSP communication. Coverage denied or voided.

    Breach Discovered in Diligence

    M&A buyer discovers misconfigured environment during due diligence. Deal collapses or valuation drops.

    "The MSP you choose is a direct input into your risk profile. That's not a sales pitch — it's a business fact."

    Why Phantom Sets This Standard

    We didn't arrive at this standard by accident. It was built deliberately, over years of working with organizations that had been burned by "good enough" IT, denied coverage when they needed it most, or failed audits after being told everything was fine.

    The Phantom Standard exists because our clients deserve to know exactly what they're getting — and exactly what's protecting them.

    NIST CSF & CIS Controls Aligned

    Cyber Insurance Documented & Supported

    Formal MSA on Every Engagement

    Compliance-Ready Configurations Standard

    Ready to Work With an MSP That Holds Itself to a Higher Standard?

    Let's talk about what your environment looks like today — and what it should look like.

    See if your current IT provider meets the Phantom Standard. The gap assessment is free, takes 30 minutes, and ends with a written summary.