Ransomware attacks on Managed Service Providers (MSPs) have become increasingly common, with 143 such incidents reported in 2025 alone. These attacks not only disrupt business operations but also put sensitive customer data at risk. To combat this threat, MSPs need a robust ransomware protection service that goes beyond mere backup and endpoint detection.
A recent report from Acronis highlights six critical controls that an effective ransomware protection service should deliver. These controls are designed to prevent exposure, detect activity before encryption, provide 24/7 response, preserve isolated recovery points, recover cleanly, and operate consistently across tenants. While backup alone is not enough, endpoint detection without a rehearsed recovery path is also inadequate.
To ensure that an MSP’s ransomware protection service meets these requirements, it’s essential to verify specific controls for each tenant, workload, storage configuration, and service tier being sold. This means demanding evidence from the vendor of their capability to deliver these outcomes.
A complete ransomware protection service should integrate prevention, detection, response, and recovery capabilities. For example, Acronis Cyber Protect Cloud provides vulnerability assessment, patch management, URL filtering, and role-based administration. However, it’s crucial to verify that these services are enabled per tenant and that the vendor has a robust process in place for monitoring and responding to incidents.
One of the most critical aspects of ransomware protection is detection. A service should be able to identify an actionable incident before widespread encryption occurs. This requires running controlled behavioral tests to confirm that endpoint isolation and identity, email, and Microsoft 365 response actions are properly configured. Acronis Active Protection and EDR cover endpoint behavior, while Acronis XDR adds visibility into email, identity, and Microsoft 365 applications.
Effective response is also crucial in mitigating the impact of a ransomware attack. A service should confirm who monitors, investigates, contains, and contacts the client after hours, as well as test escalation paths and document which actions require approval. Acronis MDR provides 24/7/365 monitoring and response on top of Acronis EDR or XDR.
Preserving recovery points is another critical aspect of ransomware protection. A service should use access-separated, immutable, and offline copies to ensure that data can be recovered even if the primary system is compromised. Attempting deletion with compromised credentials and verifying retention, alerts, and storage-policy changes are essential steps in ensuring that recovery points are protected.
Finally, a service should be able to recover cleanly by selecting a known-good point, scanning it, restoring in isolation, rebuilding dependencies in order, and validating the application. Recording the achieved recovery point objective (RPO) and recovery time objective (RTO) is also essential, as this provides a clear understanding of how quickly data can be restored.
In conclusion, protecting against ransomware attacks requires more than just backup and endpoint detection. MSPs need a robust service that integrates prevention, detection, response, and recovery capabilities. By verifying specific controls for each tenant, workload, storage configuration, and service tier being sold, MSPs can ensure that their customers’ data is protected from the growing threat of ransomware attacks.
Source: Bleeping Computer — 2026-09-02