Topic

Vendors & DPAs

Pass-through risk, customer-supplied paperwork, and what happens when a vendor goes down.

Blog

Why MSPs Shouldn’t Sign a Customer DPA Without Reviewing the Risk

Data Processing Agreements (DPAs) are often treated as boilerplate, but they’re not. A customer-supplied DPA can silently shift significant liability onto your business if you don’t know what to look for. This is the step many MSPs skip during onboarding. A new customer sends over a stack of documents during onboarding, and the MSA and [ ]

Julie Machal-Fulks Mar 10, 2026
Blog

What Happens If a Vendor You Rely on Goes Down?

You provide the service, but behind the scenes, you’re relying on vendors, cloud providers, security tools, AI models, and compliance platforms. What happens when one of them fails? If your contract doesn’t shift that risk, the client may assume you are responsible. Vendor Failures You Can’t Control Cloud hosting outage that knocks your platform offline. [ ]

Rob Scott Feb 9, 2026
Blog

How Monjur Uses Attorney-Supervised Contract Intelligence to Automate Vendor Contracting

Vendor contracting has become one of the most complex challenges for modern procurement and legal teams. The challenge extends beyond sheer numbers. It’s the complexity of applying internal standards consistently across vendor agreements that vary by structure, language, and risk profile. Manual review doesn’t scale. Generic AI lacks context. Legal teams stay stuck doing mechanical [ ]

Rob Scott Jan 19, 2026
Blog

Don’t Get Trapped by Customer-Supplied DPAs

When your customer sends over a Data Processing Agreement (DPA), it might look routine. But buried in those pages are often unfair risk-shifting clauses that push all the liability to you. The wrong DPA can make you responsible for things you don’t control, including your client’s own security failures. What Can Go Wrong You agree [ ]

Julie Machal-Fulks Jan 13, 2026
Blog

When a Vendor Fails, Your Contract Shouldn’t

Most small businesses depend on outside vendors: cloud providers, payment processors, CRM platforms, and remote tools. But what happens when a vendor goes down, gets breached, or hikes prices without notice? If your contracts don’t handle that risk, you could be stuck with angry clients, financial loss, or legal exposure for something you didn’t cause. [ ]

Rob Scott Jan 12, 2026
Blog

Vendor Management: The Overlooked Legal Risk for MSPs

For Managed Service Providers (MSPs), vendors are indispensable. From cloud hosting to cybersecurity tools, your ability to deliver value often hinges on the reliability of third-party providers. But with this reliance comes risk. Vendor-related failures can expose your MSP to financial loss, client disputes, and even legal liability. Despite the critical nature of vendor relationships, [ ]

Rob Scott Mar 17, 2025
Blog

Who’s Liable When Your Vendor Fails? MSP Risk Management 101

As a Managed Service Provider (MSP), you depend on vendors for critical tools and services, from cloud platforms to cybersecurity solutions. But what happens when these vendors fail? Whether it’s a service outage, a security breach, or non-performance, the ripple effects can disrupt your operations and jeopardize client relationships. If your contracts don’t clearly address [ ]

Rob Scott Mar 11, 2025
Blog

How Changes in Data Privacy Laws Impact MSPs

Data privacy laws are evolving faster than one can imagine. For managed service providers (MSPs), staying ahead of these changes is critical. The goal is not only to protect clients but also to safeguard your own business from legal and financial risks. From the European Union’s GDPR to emerging U.S. state laws, and federal regulations [ ]

Julie Machal-Fulks Mar 3, 2025
Blog

How to Evaluate Monjur’s Privacy, Security, and Compliance Library

Many MSPs find themselves in a tough spot dealing with privacy laws, cyber threats, and compliance rules. In a recent case, an MSP in California got sued when their client faced a ransomware attack and claimed their backup system didn’t work properly. This shows why solid legal protection isn’t just a nice-to-have. No. It’s a [ ]

Julie Machal-Fulks Feb 20, 2025
Blog

Choosing the Right Monjur Plan for Your MSP

Running an MSP isn’t easy. And dealing with legal agreements shouldn’t add to your stress. Yet many MSPs try to piece together their own contracts or download whatever they can find online. A copied-and-pasted agreement might have worked five years ago. But with ransomware, data privacy laws, and vendor risks growing daily, generic contracts are [ ]

Rob Scott Feb 18, 2025
Blog

Compliance Check List: Required Data Processing Terms for MSPs

Are your contracts leaving you exposed? As MSPs face increasing scrutiny over data handling practices, having specific and well-defined data processing terms has become non-negotiable. Recent cases, like the Acronis litigation in California, highlight the risks of outdated MSP agreements. With state, federal, and international privacy laws evolving rapidly, compliance is growing more complex. For [ ]

Julie Machal-Fulks Feb 17, 2025
Blog

Navigating Vendor Risk: Why MSPs Need a Comprehensive Approach

Most MSPs focus too much on vendor features and too little on vendor risks. For Managed Service Providers (MSPs), third-party risks directly affect daily operations and client relationships. Recent incidents like the 2021 Kaseya ransomware attack and the 2020 SolarWinds breach, each affecting over 1,000 customers, shows how severe the consequences of vendor-related issues can [ ]

Rob Scott Feb 14, 2025
Blog

How to Navigate the Regulatory Labyrinth as an MSP

In the ever-changing landscape of data privacy, staying up-to-date with regulations is not only beneficial, it’s crucial. Managed service providers (MSPs) bear the responsibility of ensuring their practices align with evolving state, federal, and international laws. In recent years, we’ve seen a dramatic surge in state-level data privacy laws, creating an increasingly complex regulatory framework for [ ]

Julie Machal-Fulks Jun 23, 2023
Blog

The Importance of Data Processing Terms in Managed Services Provider Contracts: A Lawyer’s Perspective

In the digital age, businesses rely heavily on managed services providers (MSPs) to handle their data processing needs efficiently and securely. However, the evolving landscape of data privacy laws, both at the federal and international levels, necessitates careful consideration of data processing terms in customer contracts. From HIPAA and GLBA to CMMC, GDPR, and Canada’s [ ]

Julie Machal-Fulks Jun 19, 2023
Blog

Mitigating Vendor Risks as an MSP with Contracts-as-Service Solution

As a Managed Service Provider (MSP), your clients entrust you with a crucial responsibility: ensuring the security and smooth operation of their IT systems. This responsibility extends to the vendors that provide the software, hardware, and services vital to these systems. Vendor risk management, thus, becomes a critical aspect of your role. Federal regulations, such [ ]

Rob Scott Jun 12, 2023
Blog

The Importance of Vendor Risk Management

Request A Consultation Vendor risk management has become an increasingly important aspect of IT management, especially for MSPs who are trusted by their clients to ensure the safety and security of their systems. This task includes carefully scrutinizing and managing the vendors who provide the software, hardware, and services that support these systems. The Role [ ]

Rob Scott May 22, 2023
Blog

How MSPs Can Manage Vendor Risk

As a Managed Service Provider (MSP), managing vendor risks is a critical aspect of your job. Your clients rely on you to ensure that their IT systems are secure and running smoothly, which means you must carefully vet and manage the vendors that provide the software, hardware, and services that support those systems. Such vendor [ ]

Rob Scott Apr 17, 2023
Blog

Why MSPS Need Their Own Data Processing Agreements

Over the past ten years regulation of data privacy and security has proliferated at the international, federal and state levels. Several industry-based federal regulations have been developed such as HIPAA for healthcare and GLBA for financial services. Other geographically based regulations such as GDPR (EU) and CCPA (California) apply to the personal data of citizens [ ]

Julie Machal-Fulks Jan 11, 2023
Blog

MSP Policy & Procedures

POLICY & PROCEDURES FOR MANAGED SERVICE PROVIDERS (MSP) With the tightening of data protection laws that followed the introduction of GDPR, enforcement actions have begun to be more widespread. Heavy penalties are handed out by the Data Protection Authorities. There have already been some big victims, including Marriott and British Airways, who were both handed [ ]

Rob Scott Dec 12, 2022
Blog

Negotiating Technology Contracts: On-premise vs. Cloud and Hosted Software

More and more businesses are considering accessing hosted software rather than purchasing on-premise software. They are also placing data in third-party public or private clouds instead of selecting on-premise software. This article will explain the key considerations and contractual provisions when deciding to utilize a hosted software cloud solution versus on-premise software solutions. KEY CONSIDERATIONS [ ]

Rob Scott May 13, 2021
Blog

Benefits of Negotiating a Source Code Escrow Agreement in a Software Vendor Contract

Many businesses have software licenses that are tailored to the business’ needs, and are for business operations on a day-to-day basis. But what happens if the software provider goes out of business or discontinues support for the software? In short, the business may not have meaningful access to necessary software after it is no longer [ ]

Rob Scott Sep 1, 2016