A cybersecurity report identified 143 managed service providers (MSPs), IT service providers, and telecommunication companies as ransomware victims in 2025. Phishing was responsible for 52% of initial access incidents, while unpatched vulnerabilities accounted for 27%. In response, a six-point checklist has been proposed for MSPs to enhance ransomware protection and accelerate recovery.
The checklist emphasizes that comprehensive ransomware protection extends beyond mere backup solutions or endpoint detection without a defined recovery strategy. It integrates prevention, detection, response, and recovery, requiring MSPs to verify each control against specific tenant, workload, storage, and service tier configurations.
The first point is to reduce exposure. This involves establishing service level agreements (SLAs) for patching based on severity and enforcing multi-factor authentication (MFA) for management portals and remote access. It also requires separating backup and security administration to prevent a compromised technician account from altering protection or deleting recovery points. Acronis Cyber Protect Cloud, for example, offers vulnerability assessment, patch management, URL filtering, and role-based administration to support these measures.
Second, detection across the attack lifecycle is crucial. MSPs should conduct controlled behavioral tests to confirm that actionable incidents are generated before widespread encryption occurs. This includes verifying endpoint isolation and the client's required response actions for identity, email, and Microsoft 365. Acronis Active Protection and EDR provide endpoint behavioral analysis, while Acronis XDR extends visibility to email, identity, and Microsoft 365.
Third, a 24/7 response capability is essential. This requires confirming who monitors, investigates, contains, and contacts clients after hours, testing escalation paths, and documenting approval requirements for actions. Acronis MDR offers 24/7/365 monitoring and response, with full remediation actions available in its Advanced tier.
Fourth, preserving recovery points is critical, utilizing access-separated, immutable, and, where necessary, offline copies. MSPs should attempt deletion with compromised credentials to verify retention, alerts, and storage policy changes. Acronis Cyber Protect Cloud supports immutable backup storage designed to protect recovery points from malicious removal.
Fifth, clean recovery involves selecting a known-good point, scanning it, restoring it in isolation, rebuilding dependencies in order, and validating the application. MSPs should record achieved recovery point objective (RPO) and recovery time objective (RTO) rather than just backup job success. Acronis Cyber Protect Cloud can scan backups for malware-free recovery, and Acronis Disaster Recovery can coordinate failover and recovery workflows.
Finally, consistent operation across tenants is necessary. This means applying standard policies without compromising client requirements, testing role separation, cross-tenant visibility, reporting, API access, and RMM/PSA handoffs while preventing cross-tenant exposure. Acronis provides multi-tenant management, centralized reporting, and RMM/PSA integrations within its Cyber Protect Cloud platform.
The report also clarifies the roles of various security technologies. Endpoint Detection and Response (EDR) monitors endpoint activity for investigation, isolation, and remediation. Extended Detection and Response (XDR) integrates endpoint signals with other attack surfaces like email and identity to provide a unified incident view. Managed Detection and Response (MDR) adds human expertise for round-the-clock investigation and response. Immutable backup protects recovery points but does not detect data theft or eliminate breach notification obligations. These tools are most effective when used together.
A recovery runbook is recommended to reduce recovery time by streamlining each stage of the incident response process, especially handoffs between different teams. Key steps include declaring the incident, assigning a commander, isolating compromised systems, preserving evidence, closing entry points, and restoring from a validated clean recovery point. Automation can remove repeatable delays, but high-impact actions should still be approved by an incident commander.
While immutable backup can preserve recoverability, it does not address data exfiltration in double-extortion ransomware attacks. Therefore, a comprehensive protection service must look for data theft and identity abuse before encryption. This involves correlating telemetry from endpoints, identity systems, email, Microsoft 365, DNS, proxies, and egress points. During response, devices should be isolated, sessions and tokens revoked, credentials rotated, attacker destinations blocked, and evidence preserved.






