The Phantom Standard
Not every MSP is built the same. Here's why that matters — and what we do differently.
What Is The Phantom Standard?
At Phantom, we believe managed IT shouldn't just keep the lights on — it should protect your business, satisfy your insurance carrier, support your compliance obligations, enable smart adoption of automation and AI, and hold up under scrutiny. The Phantom Standard is our internal benchmark for how we build, deliver, and maintain IT environments for every client we serve.
It's not the minimum. It's the floor — and it's set deliberately higher than most of the industry. Every recommendation we make is filtered through one question: does this advance the client's business strategy? Our vCIO program is how we operationalize that alignment.
This page explains what that standard includes, why we built it this way, and what the real risk looks like when an MSP cuts corners.
What The Standard Covers
Six pillars that define how we build, secure, and manage every client environment.
Security Frameworks
- Controls aligned to NIST CSF and CIS Controls
- Endpoint detection and response (EDR) on every managed device
- Multi-factor authentication required across all services
- Regular vulnerability scanning and patch management
- Security awareness training for client staff
Cyber Insurance Alignment
- We document your environment to meet carrier audit requirements
- Our configurations satisfy common underwriting controls (MFA, EDR, backups, least privilege, etc.)
- Clients are coached on how to accurately answer applications — and backed by documentation if questioned
- Our Guardian Compliance tier is purpose-built for organizations with active insurance mandates
Compliance & Regulatory Readiness
- HIPAA-aligned configurations for healthcare clients
- Support for CMMC and DFARS requirements for defense contractors
- SOC 2 preparation support for service-based organizations
- Documentation and evidence packages for audits and reviews
Documented Processes & Accountability
- Everything is documented: configurations, change logs, incident response procedures
- Clients receive regular reports — not just alerts
- Service delivered under a formal MSA, not a handshake deal
- Escalation paths and response SLAs are defined, not improvised
Operational Maturity
- Tooling reviewed and updated against current threat landscape
- Internal staff trained on evolving frameworks and threats
- Vendor relationships maintained with tier-1 security and infrastructure providers
- Change management process prevents configuration drift
Partnership, Not Just Support
- We advise on technology decisions — including where automation and AI fit — not just fix what breaks
- Regular vCIO business reviews to align IT spend and roadmap with your strategy
- Transparent communication about risk — we tell you what you need to hear
- We are accountable to your outcomes, not just your ticket queue
Built for the Insurance Conversation
Cyber insurance carriers are tightening requirements. Premiums are rising, coverage is narrowing, and claims are being denied on the basis of misconfiguration or missing controls.
Most MSPs deliver what they always have. Phantom builds environments that hold up to the underwriting process — and keeps the documentation to prove it.
Whether you're renewing a policy, applying for the first time, or facing a post-breach audit, our environments are designed to give you the evidence you need.
Insurance-Ready Controls
- Multi-factor authentication enforced
- EDR/MDR active on all endpoints
- Privileged access controls documented
- Backup strategy tested and verified
- Security awareness training in place
- Incident response plan on file
- Patch management SLA enforced
- Email security (DMARC, SPF, DKIM) configured
Our Guardian Compliance tier is designed specifically for organizations with active compliance obligations or insurance mandates.
The Cost of a Lower Bar
Choosing an MSP is a risk decision. A lower price buys you a lower standard — and that gap has real consequences.
Cyber Insurance Claim Denied
Carrier discovers MFA wasn't enforced. Claim denied. Business absorbs $200K+ loss.
Ransomware with No Recovery
No tested backups. Attacker encrypts everything. Recovery costs exceed $50K with 2+ weeks of downtime.
Compliance Violation
HIPAA audit finds gaps in PHI access controls. Provider faces OCR investigation and civil penalties.
Personal Liability Exposure
Board-level inquiry after breach finds no documentation of security decisions. Leadership faces personal liability.
Insurance Renewal Failure
Renewal questionnaire answered incorrectly due to poor MSP communication. Coverage denied or voided.
Breach Discovered in Diligence
M&A buyer discovers misconfigured environment during due diligence. Deal collapses or valuation drops.
"The MSP you choose is a direct input into your risk profile. That's not a sales pitch — it's a business fact."
Why Phantom Sets This Standard
We didn't arrive at this standard by accident. It was built deliberately, over years of working with organizations that had been burned by "good enough" IT, denied coverage when they needed it most, or failed audits after being told everything was fine.
The Phantom Standard exists because our clients deserve to know exactly what they're getting — and exactly what's protecting them.
NIST CSF & CIS Controls Aligned
Cyber Insurance Documented & Supported
Formal MSA on Every Engagement
Compliance-Ready Configurations Standard
Ready to Work With an MSP That Holds Itself to a Higher Standard?
Let's talk about what your environment looks like today — and what it should look like.
See if your current IT provider meets the Phantom Standard. The gap assessment is free, takes 30 minutes, and ends with a written summary.
