Your MSP Just Got Acquired: What LA Businesses Should Do Next
Why Your MSP Suddenly Has a New Owner
You got the email. Warm subject line, a stock photo of a handshake, the words “exciting new chapter,” and a promise that nothing will change. Your account manager’s name is still in the signature block. Somewhere in paragraph four it says your service agreement has been assigned to the acquiring entity.
This is not a one-off. The managed services market is in the middle of a sustained roll-up: private-equity-backed platforms are buying regional MSPs, stacking them into multi-state entities, and consolidating the acquired companies onto a single toolset and a single service desk. For a boutique law firm in Century City or a post-production house in Burbank, that means the small shop you picked precisely because it was a small shop may now be a division inside something much larger.
That is not automatically bad. Larger platforms often bring a real around-the-clock security operations center, a documented incident response retainer, and depth your prior provider could not staff. But the transition is the risky part, and the risk is not hypothetical. This post is the checklist and decision framework we would use ourselves.
What Actually Changes After an Acquisition — and What Usually Doesn’t
Acquisitions in this market follow a predictable arc. The announcement promises continuity, and for the first stretch that is true. Then integration begins, because integration is the entire financial rationale for the deal.
What almost always changes, eventually:
- The tool stack. The acquirer standardizes the remote monitoring and management (RMM) platform, the endpoint detection product, the backup platform, the documentation system, and the ticketing/PSA system. Every one of those changes touches your endpoints.
- The escalation path. A named engineer who knew your matter-management system gets replaced by a tiered queue with a shared inbox.
- The people. Founder-operators typically have earnout periods, and senior technicians are the most portable asset in the industry. Attrition after a deal is normal.
- The service catalog. Offerings that don’t fit the acquirer’s standard package — the odd on-prem media server, the legacy VoIP PBX, the one Mac-heavy department — get deprecated or restructured.
What usually does not change:
- Your obligations. Most master service agreements contain an assignment clause permitting transfer to a successor or acquirer without your consent, and most auto-renew. An acquisition is generally not, by itself, a termination right.
- Your risk. You still own the regulatory exposure for your clients’ data no matter who is administering the systems.
- Your tenant. If your Microsoft 365 tenant is properly registered to your company, it stays yours regardless of who the partner of record is. If it isn’t, that’s a problem you need to find out about now — see below.
The Warning Signs That Separate a Good Handoff From a Bad One
Don’t judge the acquisition by the announcement. Judge it by what happens in the first weeks. Specific things to watch:
- Ticket first-response times drift. Pull your ticket history before and after. If you don’t have access to your own ticket data, that itself is a finding.
- Your named contacts stop answering and no successor is introduced. Silent substitution is the single most reliable predictor of a bad integration.
- You are asked to approve a new agent deployment with no change plan. A legitimate tool migration comes with a written change record, a rollback plan, and a maintenance window. “We’re pushing an update tonight” is not a change plan.
- Nobody can produce your documentation. Ask for a current network diagram, an asset inventory, and your admin credential list. A healthy provider hands it over the same week.
- Your quarterly technology review disappears. In MSP roll-ups, virtual CIO time is often the first thing cut, because it’s the least visible to the customer and the most expensive to staff.
- Renewal terms arrive before the relationship is re-established. Getting a new paper packet before you’ve met the new team is a sequencing choice, and it tells you something.
Any one of these is a conversation. Several of them, sustained, is a transition plan.
Read Your Contract Before You Read the Announcement Again
Pull the signed master service agreement and the statements of work. You are looking for six specific clauses:
- Assignment. Does it permit assignment to a successor without consent, or does it require your written approval? If approval is required and you were not asked, you have leverage.
- Term and auto-renewal. Find the renewal date and, critically, the notice window — how far before renewal you must give written notice to avoid another full term. Calendar it today. Missing that window is the most common way businesses get locked into a provider they’ve decided to leave.
- Termination for convenience. Does one exist? What notice does it require? Is there an early termination charge structure?
- Data ownership and return. Does the agreement obligate the provider to return your documentation, configurations, and backup data in a usable format on termination, and within what timeframe? Many agreements are silent, which practically means “no.”
- Subcontracting and offshoring. Roll-ups frequently move front-line support offshore. If you handle client confidential material — and if you’re an entertainment or family-law firm, you do — check whether the agreement restricts where your data can be accessed from.
- Security and breach notification obligations. How fast must they tell you if they are breached? Verizon’s most recent analysis found that third-party involvement in breaches doubled to 30% of cases, which makes your provider’s own breach-notification clock a direct operational concern, not a legal formality.
The Security Risk That Isn’t in the Announcement Email
Here is the part most owners underrate. A tool migration means the new parent company installs its RMM agent on every server and workstation you own. That agent runs with SYSTEM-level privilege and can execute arbitrary scripts across your fleet. You are, in a real sense, re-consenting to a supply chain relationship — with a company you have not vetted.
Attackers know this. CISA and its international partners published joint guidance specifically on protecting against cyber threats to managed service providers and their customers, and its recommendations map almost exactly onto what an acquisition transition should look like. Apply them as acceptance criteria for the new provider:
- Enforce MFA on every provider account touching your environment, including break-glass accounts. Ask them to show you the conditional access policy, not describe it.
- Apply least privilege to the delegated relationship. In Microsoft 365, that means Granular Delegated Admin Privileges (GDAP) scoped to specific roles with time limits — not the old, unlimited delegated admin. Ask which GDAP roles they hold in your tenant and for how long.
- Require dedicated, named admin accounts per technician rather than a shared service account. Shared credentials survive employee departures; named ones can be disabled.
- Get logging you can see. You should be able to independently review sign-in logs and admin activity in your own tenant. If visibility only exists inside the provider’s portal, you can’t audit them.
- Verify tenant and license ownership. Confirm your Microsoft 365 tenant is registered to your legal entity with a company-controlled global admin account, that your domain registrar and DNS are in accounts you own, and that your backup repository is not exclusively inside the provider’s vault.
The supply chain framing matters because the standards bodies already treat it that way. NIST SP 800-161r1 sets out cybersecurity supply chain risk management practices for exactly this scenario: your provider’s controls are, functionally, your controls.
Build Your Exit Kit Now, Whether or Not You Leave
Assemble this regardless of your decision. If you stay, it’s good hygiene. If you leave, it’s the difference between a short transition and a painfully long one.
- Asset inventory: every server, workstation, firewall, switch, access point, and mobile device with make, model, serial, warranty status, and OS version.
- Network documentation: current topology diagram, VLAN and subnet map, firewall rule export, VPN configuration, ISP circuit IDs and account numbers.
- Credential inventory: an export of your entries from the provider’s password manager or documentation platform, transferred into a vault you control.
- Identity and licensing: confirmation of tenant ownership, list of global admins, GDAP relationships, license counts and renewal dates, and the current Cloud Solution Provider partner of record.
- Backup proof: the backup job configuration, retention policy, most recent successful restore test with date, and — this is the one people miss — written confirmation of how you would extract backup data if the relationship ended.
- Line-of-business application contacts: vendor support numbers and account IDs for your practice management, document management, accounting, and any media asset management systems.
- Ticket and change history: an export, not a summary.
A provider that produces this quickly is a provider worth keeping. A provider that stalls has told you what you needed to know.
Stay, Renegotiate, or Switch: A Decision Framework
There are three real options. Most businesses should pick the middle one first.
| Option | Continuity risk | Your leverage | Effort required | Best when |
|---|---|---|---|---|
| Stay and observe | Low near-term, rising through integration | Lowest — silence reads as satisfaction | Minimal; requires monitoring metrics | Your environment is stable, the named team is intact, and renewal is far off |
| Stay and renegotiate now | Low; you keep institutional knowledge | Highest — the acquirer wants clean retention numbers going into its next raise | Moderate; requires a written ask and a deadline | Renewal is approaching, or you need SLA, offshoring, or documentation terms fixed |
| Run a competitive process | Highest during cutover; lowest afterward | High, but only if you start before the renewal notice window closes | Substantial; expect a structured onboarding period | Response times have degraded, your industry needs specialized handling, or the acquirer can’t answer the security questions above |
The renegotiation window is genuinely real and genuinely short. Acquirers are measured on customer retention through the integration period. That is the moment to ask for a named account lead in writing, a defined escalation path with response commitments, quarterly technology reviews as a contractual deliverable, a data-return clause, and a restriction on where your data may be accessed from. Ask in writing, with a response date. Note that the structure of the engagement — whether you’re on a predictable recurring arrangement or drifting back toward unpredictable per-incident billing as the acquirer unbundles services — is itself a negotiable term worth pinning down in that same conversation.
The California Compliance Obligations That Travel With Your Data
Ownership of the provider changes. Your obligations do not.
If you’re a California business subject to the CCPA as amended by the CPRA, your contracts with service providers must contain specific required terms, and swapping in a new corporate entity is a good moment to confirm those terms actually carry over rather than assuming assignment covered it. The California Attorney General maintains current guidance on CCPA obligations, and the California Privacy Protection Agency’s regulations on cybersecurity audits, risk assessments, and automated decisionmaking phase in audit requirements on a schedule tied to business size and revenue. Check that page for the thresholds and deadlines that apply to you. If an audit is in your future, the completeness of your provider’s documentation stops being a convenience issue.
Separately, California’s breach notification statute requires notifying affected residents without unreasonable delay, and businesses must also submit a sample notice to the Attorney General when more than 500 California residents are affected. Read that alongside the scale of the underlying problem: the FBI’s Internet Crime Complaint Center reported $16.6 billion in losses in 2024, a 33% increase over the prior year. A confused, undocumented handoff between two MSPs is precisely the window in which those events happen, because nobody is quite sure who owns the alert.
How to Run a Clean Transition Without Downtime
If you decide to move, sequence it deliberately. The failure mode is not choosing wrong; it’s overlapping badly.
- Give notice only after the incoming provider has completed discovery. Never terminate before your new provider has documented what they’re inheriting.
- Run parallel for a defined period. Both providers hold access during cutover. Yes, that overlap costs more. It costs less than a failed backup discovered after the old provider’s accounts were disabled.
- Migrate identity last, backups first. Establish independent backup with a verified test restore before touching admin delegation. If anything goes wrong later, you have a floor.
- Rotate every credential at cutover. All of them, including service accounts, firewall admin, switch management, wireless PSKs, and any shared vendor logins. Departing technicians retain knowledge you cannot revoke.
- Confirm the old RMM and remote access agents are actually uninstalled, and verify from an endpoint inventory rather than from an assurance. Orphaned agents with SYSTEM privilege are a common finding in post-transition assessments.
- Re-test your business continuity assumptions against Southern California realities. Between wildfire season, PSPS de-energization events, seismic risk, and the traffic geography that makes a Downtown-to-Woodland-Hills emergency site visit an all-afternoon proposition, an LA business needs to know whether its new provider can actually restore operations remotely — and whether their nearest engineer is in the region at all. Ask where the people who would show up physically are based. In a consolidated national platform, the honest answer is sometimes “nowhere near you.”
- Set a formal review at an agreed date with written success criteria settled before the transition starts, not after.
Industry specificity matters more than size here. A firm handling talent agreements, unreleased media assets, or matters under protective order has requirements that a generalized national help desk queue will not intuit — and the institutional knowledge that made your old provider valuable is exactly the asset most likely to walk out the door during integration.
If your Los Angeles MSP has been acquired and you’re weighing whether to stay, renegotiate, or move, We Solve Problems can help you decide. We’re an LA-based managed IT, cybersecurity, Microsoft 365, and compliance provider experienced in clean transitions where credentials, backups, and documentation end up in your hands. Contact us to review your environment and your current agreement.