skip to content

Why does one managed-service provider outprice any single client's domain administrator as a target?

level: middleimportance: must knowfreq 66%

answer

  1. price the second victim, not the first
  2. fixed cost once, marginal cost a sign-in
  3. the client list is part of the prize
  4. budget sized to their revenue, risk to yours
  5. changes the class of adversary, not just odds

basics

~20 s

Aggregation. One provider identity is already provisioned into every client it administers, so the cost of the second victim and the two-hundredth is a sign-in. That multiplier makes the provider worth spending on that no single client would ever attract.

solid answer

~50 s

A client's domain administrator buys one estate. A provider's engineer identity buys every estate that provider administers, because the rights are already provisioned in each tenant and no further access work is needed. The economics follow: the whole cost of the operation is paid once at the provider, and the marginal cost per additional victim collapses to a sign-in. Two consequences an interviewer wants. First, the provider's client list is a target list, and it is enumerable from the inside on day one. Second, the defence budget is mismatched by design — a 40-person provider funds security out of its own revenue while carrying the aggregate value of two hundred clients, so a crew that would never spend a scarce capability on your firm will happily spend it on the firm that administers two hundred of you.

go deeper

for a junior

Be ready to state the multiplier in one sentence: one provider identity is already entitled in every client tenant, so one intrusion buys many estates. Know that the provider's client list is itself valuable.

for a middle

Explain fixed versus marginal cost from the operator's side and why the second victim is nearly free. Be able to say why 'they might be less secure than us' is an incomplete answer.

for a senior

Show that aggregation changes the class of adversary a mid-sized firm faces, and translate that into what you ask a provider for: partitioned identities, per-client credentials, and privilege that is not standing.

for a principal

Own the structural point that defence is funded by the provider's revenue while loss lands on the clients, and be ready to say how you price that mismatch into a contract or a provider choice.

## The arithmetic Put the two targets side by side and price the operation the way the person running it does. **Target A — one client's domain administrator.** Cost: whatever it takes to get that credential. Return: one estate, of one company's size, with one company's data and one company's ability to pay. **Target B — the provider that administers two hundred such companies.** Cost: whatever it takes to get one engineer identity at the provider. Return: two hundred estates, each of which the identity is *already* entitled to enter. There is no second access problem. The rights were provisioned at onboarding; the intruder does not have to find a path into client 47, because the path is the product. The fixed cost is paid once. The marginal cost of the next victim is a sign-in. Any operation whose cost is dominated by getting the first foothold is transformed by that, which is why this pattern attracts crews with budgets and patience that a mid-sized company would otherwise never face. ## The list is part of the prize The second thing the intruder gains is the target list itself, and it is authoritative. The provider's console enumerates every client, and the relationship record says what role is held in each. Reconnaissance that would normally take weeks per victim is a page in an administrative interface. The intruder can also *sort* it: by client size, by sector, by which tenants hold the interesting data, by which clients are in a jurisdiction they care about. Selection is cheap, so they take the profitable ones and leave the rest. ## The budget mismatch, which is the part candidates miss The usual answer stops at *the provider might have weaker security than us*, which is true but shallow and sometimes false — plenty of providers are better run than their clients. The sharper version is structural rather than a judgment about competence: > A provider's security spending is sized to its **own** revenue. Its security *relevance* is sized to the **aggregate** value of its clients. A forty-person provider with a few million in revenue funds a security programme a forty-person business can afford, while holding privileged access across estates whose combined value is two or three orders of magnitude larger. No amount of diligence closes that gap, because it is not a diligence gap. It is a mismatch between who pays for the defence and who carries the loss. The corollary bites in the other direction too. Your risk from the provider is not only the provider's own hygiene; it is the hygiene of the provider's **weakest client**, because that client is a room the shared engineer identity walks into. ## What this predicts, and what it does not It predicts a change in the *class* of adversary, not merely the probability of an incident. Scarce capability — a purchased exploit, a long patient operation, a bespoke intrusion — is allocated by expected return. Your ninety-person firm does not justify it. The provider that administers two hundred ninety-person firms plainly does. So the honest sentence in an interview is: *by outsourcing administration we have not only inherited a partner's identity hygiene, we have joined a target whose value justifies attention we would never attract alone.* It does not predict that the provider is negligent, that in-housing is safer (an in-house team of one is not obviously better), or that the aggregation is avoidable. Aggregation is the entire economic point of managed services; the same multiplier that makes the provider a target is what makes competent administration affordable at all. ## Talking about it without hand-waving Two things make the argument concrete rather than rhetorical. First, name the multiplier as a number you can actually ask for: how many tenants does this provider administer, and does one engineer identity reach all of them or is the estate partitioned? Second, name what would blunt it: per-client credentials rather than one identity spanning the book, privilege that exists only during an approved engagement, and the smallest role that does the job. Those attack the multiplier directly — they turn *one identity, two hundred estates* back into two hundred separate access problems, which is exactly the economics the intruder came here to escape.

  • A client says its provider is a 40-person shop, so the risk is small. What is wrong with that reasoning?
    It sizes the risk by the provider's headcount, which is the wrong quantity. The provider's headcount sets its defensive budget; its client book sets the attacker's expected return. A small provider administering two hundred estates is a large target defended on a small budget, which is the worst combination rather than a reassuring one.
  • What single question about the provider most changes your exposure estimate?
    Whether one engineer identity reaches every client, or the book is partitioned so an identity reaches only its assigned clients. That one answer decides whether a compromise at the provider is a two-hundred-estate event or a five-estate event, and it costs the provider operational convenience rather than money — so it is a fair thing to ask for.
  • Does aggregation also work against the adversary in any way?
    Yes, in one respect: a two-hundred-victim operation is loud and short-lived, because the provider's other clients notice each other. Crews that want quiet, long access sometimes deliberately use only a handful of the available tenants. That is why 'they had access to all two hundred' and 'they used all two hundred' are different claims, and only the first is usually provable.

Robbing the locksmith rather than the houses. The locksmith's van is worth two hundred break-ins, and it is one van.

saying these in an interview costs you the question

  • Sizes the risk by the provider's headcount or revenue
  • Treats a passed questionnaire as if it reduced the multiplier
  • Assumes the value is aggregated data rather than aggregated access
  • Says the provider is a target only because its own security is weak
  • Ignores that the provider's weakest client is also your exposure

context