# When the Firefighter Catches Fire: Why MSP Ransomware Defenses Keep Failing in Practice


Managed service providers are supposed to be the security backstop for thousands of small and mid-sized businesses that can't afford a full security team. That's the pitch, and it mostly holds. But it also makes MSPs the single most efficient target in ransomware's entire ecosystem — compromise one provider, and you've potentially unlocked a hundred clients at once.


Acronis published a six-point ransomware readiness checklist aimed at MSPs this week, and while the framework is sound, the document buries the part that actually kills businesses: the gap between *having* a capability and *having tested it when the building is already on fire*.


## The Supply Chain Problem MSPs Would Rather Not Discuss


Kaseya. ConnectWise. SolarWinds-adjacent breaches. The pattern has been consistent for five years: threat actors increasingly treat MSPs not as targets in themselves but as distribution infrastructure. Ransomware deployed through an MSP's own remote management tooling carries an implicit trust token — the malicious payload arrives via the same channel as legitimate patches. Endpoint detection doesn't flag it. Client firewalls wave it through.


CISA and the FBI have issued repeated advisories on MSP targeting since 2022, and yet the fundamental architecture hasn't changed much. MSPs still need broad, persistent access to client environments to do their jobs. That access is the attack surface. There's no clever configuration that makes it disappear.


What the Acronis checklist gets right is framing ransomware resilience as a multi-layer problem rather than a product purchase. Endpoint detection alone fails when the attacker has MSP-level credentials. Backups alone fail when those backups are network-accessible from the compromised environment. You need exposure reduction, anomaly detection, immutable or air-gapped recovery points, and a tested restoration workflow — and all of those things have to work together under duress, not in a calm quarterly review.


## The Six Capabilities, Pressure-Tested


The checklist covers roughly this territory:


  • Reducing attack surface — MFA on everything, least-privilege access, RMM platform hardening
  • Detecting early-stage activity — behavioral anomalies before encryption starts
  • Protecting backup integrity — immutable snapshots, offsite or air-gapped copies
  • Preserving recovery points — granular, frequent, verified
  • Rapid response and isolation — automatic or near-automatic containment
  • Restoring operations quickly — tested runbooks, not just theoretical RTOs

  • Each of these is legitimate. The problem is the word "test." Most MSPs have these capabilities in some form. Far fewer have run a realistic tabletop or simulated incident to find out where the wheels actually fall off.


    Backup frequency is where I see the most dangerous overconfidence. An MSP might snapshot client workloads every four hours and call that "protected." But four hours of billing data, project records, or clinical notes lost during a Friday-afternoon attack is not an acceptable outcome for most clients — and the client never agreed to that SLA explicitly because nobody ever asked.


    Recovery time is the other ghost in the room. MSPs routinely quote RTOs in hours. Actual recovery from a full ransomware event, including system rebuild, data restoration, verification, and endpoint re-enrollment, routinely takes days. The checklist says "restore operations quickly." What that means in practice depends entirely on whether anyone has ever practiced it.


    ## What Vendors Like Acronis Aren't Saying


    Acronis sells backup and endpoint protection products to MSPs. That's the context for this checklist, and it's worth holding. The six points conveniently map to Acronis product capabilities. That doesn't make the advice wrong — it's genuinely solid — but it does mean there's a selection effect in what gets emphasized.


    What's missing from the vendor-authored version of this conversation:


    RMM hardening gets insufficient attention. The remote monitoring and management platform is the MSP's master key. It needs its own security review — access logs, anomaly detection, IP restrictions, and an incident response plan that assumes the RMM itself may be the attack vector. Most MSP security guidance treats RMM as the solution rather than as a potential liability.


    Client communication plans are never mentioned. When ransomware hits an MSP's environment and touches client data, the legal and regulatory clock starts immediately. GDPR, HIPAA, state-level breach notification laws — the MSP that hasn't drafted client breach notification templates before an incident will be drafting them under deadline while also trying to restore systems. That's a recoverable situation that becomes unrecoverable.


    The human element in detection gaps. Behavioral anomaly detection is only useful if someone is watching the alerts. Many MSPs run lean NOC operations. Alerts that fire at 2 AM on a Saturday get triaged on Monday morning. Ransomware actors know this.


    ## What a Real Readiness Test Looks Like


    MSPs serious about this should not self-grade the checklist. Commission an external tabletop exercise. Have a third party simulate compromise via your RMM — not your clients' endpoints, but your own tooling — and time how long it takes your team to detect, contain, and communicate. Then do the same for backup restoration: pick a client environment, simulate a full wipe, and measure actual recovery time against your contractual commitments.


    The MSPs that survive ransomware events well aren't the ones with the best technology stacks. They're the ones that have practiced being wrong.


    ---


    ## HackWire Analysis


    The Acronis checklist is a useful document, but it's also a document published by a vendor with a direct financial interest in your buying their backup and endpoint solutions. Read it that way.


    What concerns me more than any single technical gap is the structural incentive problem in the MSP market. MSPs compete heavily on price, which compresses margins, which means fewer security staff, less testing time, and more reliance on automated tooling that no one has time to tune properly. The same economic pressure that makes MSPs attractive to SMBs — "security at scale, for less" — is the same pressure that creates the shortcuts attackers exploit.


    The Kaseya VSA incident in July 2021 is still the clearest illustration of how fast this can cascade. REvil compromised roughly 60 MSPs and somewhere between 800 and 1,500 downstream businesses in a single weekend. Most of those downstream businesses had no idea their MSP was the entry point until files were encrypted. The MSP-as-trusted-infrastructure model has a single-point-of-failure problem baked into it, and checklists don't solve structural problems.


    The capability that actually differentiates resilient MSPs from vulnerable ones isn't on any six-point checklist: it's the willingness to run realistic failure drills, find the gaps before attackers do, and be honest with clients about actual RTOs rather than aspirational ones. Security theater kills companies. Testing saves them.


    For defenders: if your MSP cannot tell you the last time they tested a full restore from backup under simulated breach conditions, that's the conversation to have — before the incident, not during it.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Ransomware](https://www.hackwire.news/category/ransomware) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)