‘We’ve built tools to make it easy for brokers to find good MSPs and certified MSPs. The idea is that when they need someone, there is a third party that has vetted them, with an easy button for insurance at the back end,’ says Edouard von Herberstein, Spectra CEO.
Spectra is expanding its role and positioning itself as a third-party validator of security practices while helping MSPs differentiate themselves, improve their insurance coverage and win new business.
The insurance provider certifies MSPs through a program that examines an MSP’s internal security posture, the security solutions it sells to customers and how those solutions are actually deployed.
“Certification is not a handwave,” Spectra CEO Edouard von Herberstein told CRN. “It’s a robust verification of their internal hygiene, the security solution they sell to customers, and we check deployment. We look at everything. You can’t just buy it. You have to show us that you actually do those things.”
That validation, the CEO said, is intended to address a longstanding challenge in the MSP market in which customers often have little visibility into whether their IT provider is actually following security best practices.
[Related: Why The Cybersecurity Channel Is Essential As An AI Reality Check: Analysis]
“How do you know the backup gets tested? How do you know it’s encrypted? How do you know it’s offline? How do you know the patching happens every month?” von Herberstein said. “As a customer, you have no idea. And if customers or MSPs just don’t know, neither does the insurer.”
Spectra has responded by moving from a traditional pass-fail certification model to a four-tier maturity model. The entry-level “approved” designation involves a basic assessment of an MSP’s capabilities. Higher levels examine areas including endpoint security, email security, identity and access management, backups, network segmentation, firewalls and disaster recovery.
And the benefits extend beyond the certification badge. The CEO said certified MSPs can gain access to insurance offerings with broader coverage and lower premiums, creating another potential differentiator for MSPs.
“They can say, ‘I know you have other MSPs bidding, but we have something that no one else has. We’re being certified, and the certifier is warranting the performance of my backup or the performance of my email security solution, or my endpoint solution,’” he said.
For Frank Merino, COO of Weston, Fla.-based Forthright Technology Partners, Spectra’s MSP certification is less about earning another industry badge and more about giving customers independent proof that an MSP is actually doing what it says it does.
Merino said Forthright had already developed its own “solution guarantee” years ago but wanted something more independent as it expanded into managed services. That led to Spectra, which he said stood out because the validation comes from an independent third party and includes a warranty component.
“It’s saying to your customer, ‘I’m going to put my money where my mouth is. If we fail, you get your money back. A third party is making the validation. You didn’t just take my word for it,’” he said.
He was particularly impressed by the depth of Spectra’s certification process. Rather than focusing solely on technology, Spectra examines an MSP’s operational practices, including contracts and evidence that security controls such as backups are actually being tested.
“We thought we were prepared,” he said. “We’d done all the technology stuff. We’d done the pen test. But before you know it, they’re saying, ‘Where’s this? Where’s this? Why do you need this?’ We started having to produce information that wasn’t part of some of these other regulatory factors.”
Spectra is also developing a referral ecosystem connecting MSPs with insurance brokers and their customers. Partnerships with technology vendors, including cybersecurity vendor Cynomi, are part of that strategy, with Spectra looking to encourage adoption of vetted security technologies across its MSP network.
Additionally, the company is preparing an AI-focused certification for MSPs, built around 23 controls intended to help them deploy AI securely for SMBs.
“We’ve built tools to make it easy for brokers to find good MSPs and certified MSPs,” von Herberstein said. “The idea is that when they need someone, there is a third party that has vetted them, with an easy button for insurance at the back end.”
For Merino, he sees trust as the biggest differentiator.
“Trust is a commodity that we cannot lose,” he told CRN. “What this certification does is say, ‘Look, I’m not just telling you that I’m doing it. Spectra made sure that I’m doing it.’”





