Skip to main content
Emerging ThreatsMalware & Ransomware

MSPs Face Ransomware Onslaught, Seek Integrated Protection

Brightly-lit IT support environment with a central computer workstation.

"Ransomware protection for MSPs should deliver six tested outcomes: reduce exposure, detect activity before encryption, provide 24/7 response, preserve isolated recovery points, recover cleanly and operate consistently across tenants," Acronis writes.

That prescription is grounded in an urgent operational reality: the Acronis Cyberthreats Report identified 143 MSP, IT-service provider and telecom ransomware victims in 2025, with phishing accounting for 52% of initial access cases and unpatched vulnerabilities for 27%. The practical takeaway in Acronis’s checklist is straightforward: backup or endpoint detection alone is not enough. MSPs must assemble prevention, detection, response and recovery into a rehearsed, measurable service.

The six tested outcomes Acronis prescribes

Acronis frames a complete ransomware protection service around six outcomes. MSPs should require tenant- and workload-specific evidence for each:

  • Reduce exposure through proactive controls and hardening.
  • Detect malicious activity before encryption begins (EDR/XDR-level detection).
  • Provide 24/7 response with named ownership, escalation paths and approval boundaries.
  • Preserve isolated recovery points with immutability and access separation.
  • Recover cleanly by selecting and validating a malware-free recovery point and performing isolated restoration.
  • Operate consistently across tenants with multi-tenant roles, reporting and audit evidence.

Important note from the checklist: immutable, offline and air-gapped are different controls. Verify each separately rather than assuming one covers the others.

How EDR, XDR and MDR fit together in the Acronis model

Acronis lays out complementary roles for detection and response technologies. EDR monitors endpoint activity and supports investigation, isolation and remediation. XDR connects endpoint signals with other attack surfaces so analysts see one incident rather than separate alerts. MDR adds people and process: a staffed service investigates and responds around the clock.

In Acronis’s example architecture, Acronis EDR provides endpoint detection and response, Acronis XDR extends visibility to email, identity and Microsoft 365 applications, and Acronis MDR operates on EDR or XDR. Acronis Cyber Protect Cloud supplies the backup, management and multi-tenant operating layer. The vendor emphasizes that immutability is one recovery control; it is not the same as an offline or air-gapped copy.

The recovery runbook: cut recovery time at every handoff

Acronis defines recovery time as the sum of detection, triage, containment, clean-point selection, restoration and validation. The checklist focuses on shortening every stage and eliminating delays at handoffs between security, backup, identity, networking and the client. Prescribed steps include:

  • Declare the incident, assign one commander and open an out-of-band channel.
  • Identify affected tenants, identities, workloads and likely initial access.
  • Isolate compromised endpoints and block malicious sessions, tokens and remote access.
  • Preserve evidence before wiping systems or rotating logs away.
  • Close the entry point by patching, disabling access and rotating credentials.
  • Choose the latest recovery point that predates compromise and passes validation.
  • Restore identity and infrastructure dependencies before applications and user data.
  • Scan, test, reconnect in stages and monitor for renewed attacker activity.

Acronis notes that backup scanning and malware-free recovery capabilities can help validate candidate recovery points and that Acronis Disaster Recovery can coordinate workflows where licensed. Automation should remove repeatable waits, but an incident commander must approve high-impact actions. After each drill, record achieved RPO/RTO and every delay, then revise the runbook using evidence from the exercise.

Immutable backup and double-extortion: why copy protection isn't enough

Acronis warns that immutable backup protects recoverability but cannot retract data attackers already stole or eliminate breach-notification duties. A complete service must look for exfiltration and identity abuse before encryption begins. That requires correlating telemetry across endpoints, identity, email, Microsoft 365, DNS, proxy and egress channels.

During response, Acronis advises isolating devices, revoking sessions and tokens, rotating credentials, blocking attacker destinations and preserving evidence for legal and notification decisions. Network egress evidence may still come from firewalls, SIEM or other client controls — test those handoffs in advance.

What this means for MSPs, technologists, and procurement leaders

MSPs should require a live demonstration of coverage across client workloads and tenant tiers, prevention and detection before broad encryption, named 24/7 response ownership, immutable-storage behavior and privileged-access separation, clean-point selection and isolated restoration, measured RPO/RTO from a dependency-ordered recovery drill, and multi-tenant roles, reporting and RMM/PSA/API integrations. Acronis recommends a live incident-and-recovery test using the production configuration and validating the selected MDR tier and operational responsibilities.

Technologists and security teams must rehearse restores, map dependencies, validate candidate clean points and automate safe steps while preserving human approval for high-impact actions such as mass isolation and credential resets.

Procurement leaders should demand per-tenant, per-workload evidence for the service tier they buy and verify storage architecture, integrations and incident-response responsibilities before standardizing a platform.

Ransomware resilience, Acronis argues, is not a product line item but a tested service outcome: contain attacks early, preserve a recovery path and prove critical services can return on schedule. Acronis Cyber Protect Cloud with Acronis MDR is presented as an integrated example — but the checklist is clear that MSPs must validate tiers, architecture and operational responsibilities, and they must exercise the runbook until measured RPO/RTO match contractual commitments.

Read the original Acronis checklist and guidance