MSP Ransomware Defense Needs More Than Backups
Acronis data shows 143 MSP victims in 2025. A six-point checklist helps providers verify real recovery capability.
When a managed service provider signs a client for ransomware protection, the service should do more than take nightly backups. According to data in the Acronis Cyberthreats Report, 143 MSPs, IT-service providers and telecom companies were hit by ransomware in 2025, with phishing responsible for 52% of initial access cases and unpatched vulnerabilities for 27%. Those numbers underscore a simple reality: an MSP that cannot prove its recovery path will actually work may be selling false confidence.
The Six Outcomes That Matter
Acronis, a cybersecurity vendor that sells to MSPs, argues that a complete ransomware protection service must deliver six tested outcomes: reduce exposure, detect activity before encryption, provide 24/7 response, preserve isolated recovery points, recover cleanly, and operate consistently across tenants. Backup alone is not enough, and neither is endpoint detection without a rehearsed recovery path.
The company turned those failure modes into a checklist. Each item pairs an operational job with a proof the MSP should demand, and maps it to an Acronis capability. The intent is to give providers a concrete way to verify what their service actually does before promising it to clients.
Reduce Exposure First
The first job is cutting the attack surface. That means setting patch SLAs by severity, proving multi-factor authentication is enabled for management portals and remote access, and separating backup and security administration. Acronis specifically recommends testing that one compromised technician account cannot change protection settings or delete recovery points.
On the Acronis platform, the relevant capabilities are vulnerability assessment, patch management, URL filtering, and role-based administration, all available through Acronis Cyber Protect Cloud. The MSP should verify which services are enabled per tenant, not just assume they are on everywhere.
Detect Before Encryption
Detection must happen before widespread encryption, not after. Acronis advises running a controlled behavioral test to confirm that an actionable incident appears before files start locking. The MSP should also check endpoint isolation and the identity, email, and Microsoft 365 response actions the client requires.
The tools here are Acronis Active Protection and EDR for endpoint behavior, with Acronis XDR adding visibility across email, identity, and Microsoft 365. Without that cross-surface view, an attacker moving from a phishing link to a compromised identity may slip past siloed alerts.
24/7 Response With Clear Ownership
Ransomware does not respect business hours. The checklist requires confirming who monitors, investigates, contains, and contacts the client after hours, and testing escalation paths. It also demands documentation of which actions require client approval before they can be taken.
Acronis MDR provides 24/7/365 monitoring and response on top of Acronis EDR or XDR. Full remediation actions, including recovery and RMM actions, are available with the Advanced tier. The MSP needs to know which tier it is selling and what that tier actually includes.
Preserve Recovery Points
Recovery points must be protected from the same attackers who might try to delete them. Acronis recommends using access-separated, immutable, and, where required, offline copies. The test is to attempt deletion with compromised credentials, then verify retention, alerts, and storage-policy changes.
Acronis Cyber Protect Cloud supports immutable backup storage designed to delay deletion and help protect recovery points from accidental or malicious removal. But the company is careful to note a key distinction: immutable, offline, and air-gapped are different controls. Each one must be verified separately.
Recover Cleanly and Measurably
Restoring from backup is not the same as recovering cleanly. The checklist says to select a known-good point, scan it, restore in isolation, rebuild dependencies in order, and validate the application. Critically, the MSP should record the achieved recovery point objective (RPO) and recovery time objective (RTO), not just whether the backup job succeeded.
Acronis Cyber Protect Cloud can scan backups and support malware-free recovery. Acronis Disaster Recovery can coordinate failover and recovery workflows when the required services are licensed and configured. But the incident team must still confirm that the selected point predates the compromise.
Operate Across Tenants
MSPs run multiple clients, often with different requirements. The final job is applying standard policies without flattening client needs. That means testing role separation, cross-tenant visibility, reporting, API access, and RMM/PSA handoffs while preventing cross-tenant exposure.
Acronis provides multi-tenant management, centralized reporting, and RMM/PSA integrations within the Cyber Protect Cloud platform. The goal is consistent operation across every tenant without creating a single point of failure where one client's compromise spills into another.
How EDR, XDR, MDR, and Immutable Backup Fit
These tools are often lumped together, but they do different jobs. EDR monitors endpoint activity and supports investigation, isolation, and remediation. XDR connects endpoint signals with other attack surfaces so analysts see one incident instead of separate alerts. MDR adds people and process: a staffed service investigates and responds around the clock. Immutable backup protects recovery points from alteration or deletion; it neither detects data theft nor replaces incident response.
In the Acronis model, EDR provides endpoint detection and response, XDR extends visibility to email, identity, and Microsoft 365 applications, and Acronis MDR operates on EDR or XDR. Acronis Cyber Protect Cloud is the backup, management, and multi-tenant operating layer. Immutability is one recovery control; it is not the same as an offline or air-gapped copy.
The Recovery Runbook
Recovery time is the sum of detection, triage, containment, clean-point selection, restoration, and validation. An MSP reduces RTO by shortening every stage, especially the handoffs between security, backup, identity, networking, and the client. Acronis lays out an eight-step runbook: declare the incident and assign one commander with an out-of-band channel; identify affected tenants, identities, workloads, and likely initial access; isolate compromised endpoints and block malicious sessions, tokens, and remote access; preserve evidence before wiping systems or rotating logs away; close the entry point by patching, disabling access, and rotating credentials; choose the latest recovery point that predates compromise and passes validation; restore identity and infrastructure dependencies before applications and user data; and scan, test, reconnect in stages, and monitor for renewed activity.
Automation can remove repeatable waits, but an incident commander should approve high-impact actions such as mass isolation, credential resets, and failover. After each drill, the MSP should record achieved RPO/RTO and every delay, then revise the runbook from evidence rather than estimated restore speed.
Why Immutable Backup Is Not Enough
Double-extortion ransomware is a growing threat. Immutable backup can preserve recoverability, but it cannot retract data that attackers already stole or remove breach-notification duties. Acronis is blunt on this point: no, immutable backup is not enough. A ransomware protection service must look for exfiltration and identity abuse before encryption begins.
That requires correlating endpoint, identity, email, Microsoft 365, DNS, proxy, and egress telemetry. During response, the MSP should isolate devices, revoke sessions and tokens, rotate credentials, block attacker destinations, and preserve evidence for legal and notification decisions. Acronis EDR provides endpoint context and response, while Acronis XDR adds telemetry and response across email, identity, and Microsoft 365. Network egress evidence may still come from firewalls, SIEM, or other client controls, so those handoffs must be tested in advance.
How to Evaluate an MSP Ransomware Platform
Before buying or standardizing a platform, Acronis recommends requiring a live demonstration of seven items: coverage for client workloads and tenant tiers; prevention and detection before broad encryption begins; named 24/7 response ownership, escalation paths, and approval boundaries; immutable-storage mode, retention behavior, and privileged-access separation; clean-point selection, malware scanning, and isolated restoration; measured RPO/RTO in a dependency-ordered recovery drill; and multi-tenant roles, reporting, audit evidence, and RMM/PSA/API integrations.
An integrated option, Acronis says, is Acronis Cyber Protect Cloud with Acronis MDR. It brings together capabilities for the six operational jobs, subject to the selected MDR tier, licensing, deployment, storage architecture, and the MSP's incident-response responsibilities. The MSP should require a live incident-and-recovery test using the production configuration.
The Stakes for MSPs and Their Clients
For MSPs, the takeaway is that ransomware protection is not a product you buy and forget. It is a service you must prove, again and again, under realistic conditions. The cost of failure is not just lost data; it is client trust, legal exposure, and potentially the business itself.
The report's figures on phishing and unpatched vulnerabilities show where the threat comes from, and the six-point checklist offers a way to measure readiness. An MSP that cannot demonstrate each control in its actual production environment should assume it will be caught off guard when a real attack hits.
Sources
- BleepingComputer Original source
Continue Reading
Legacy Lenovo login tied to Dropbox account hacks
Dropbox says attackers abused a legacy Lenovo login integration to access 5,000 accounts.
SonicWall SMA 1000 Zero-Days Exploited in Chained Attacks
SonicWall patches two zero-days in SMA 1000 VPN appliances, warning of active exploitation that combines both flaws.
BGP hijack pushes malware via a 256-IP range
Attackers exploited routing and TLS flaws to abuse a hijacked /24 block in a 22-hour window.