Six things MSPs should actually test before the next ransomware hit
Acronis lays out a practical checklist for managed service providers, moving the conversation past backups and antivirus to the full arc of prevention, detection and recovery.

Key points
- Acronis has published a six-point checklist for managed service providers (MSPs), the outside IT firms that run technology for smaller businesses.
- The guidance covers the full ransomware lifecycle: reducing exposure, hardening systems, detecting intrusions, preserving clean recovery points, restoring operations, and learning from each incident.
- Backups alone are not enough, because modern ransomware crews search for and delete backup files before triggering encryption.
- The checklist is vendor guidance, not a regulation, but it maps closely to the recovery expectations regulators now write into rules like the SEC's cyber disclosure requirements and the EU's NIS2 directive.
Ransomware, the crime where hackers scramble a company's files and demand payment to unscramble them, keeps hitting the same soft target: small and mid-sized firms that outsource their IT to a managed service provider. If the MSP falls, every client falls with it.
Acronis, a backup and security vendor, has published a six-point checklist aimed at those providers. It was written up this week by BleepingComputer. The document is not a standard or a rule. It is a self-assessment, and a useful one, because it reframes ransomware defence as a chain rather than a single product.
What is actually on the checklist?
The six capabilities are exposure reduction, system hardening, attack detection, recovery-point preservation, rapid restore, and post-incident review. Acronis argues an MSP should be able to demonstrate each of these across every client environment it manages, not just the flagship accounts.
Here is the shape of it in plain terms.
| Capability | What it means in practice |
|---|---|
| Reduce exposure | Shrink the number of internet-facing systems and open accounts an attacker can reach. |
| Harden systems | Patch software, turn on multi-factor login, remove default passwords. |
| Detect attacks | Spot unusual file activity or logins before encryption starts. |
| Preserve recovery points | Keep backups that ransomware cannot reach or delete. |
| Restore quickly | Rehearse getting a client fully working again, not just the file server. |
| Review and improve | Run a post-mortem after every incident, real or simulated. |
Why does this matter beyond the MSP world?
Because when an MSP is hit, the blast radius is every business it serves. A single break-in at a provider can encrypt hundreds of dental practices, law firms or town councils in one night. Regulators have noticed.
The US Securities and Exchange Commission's cyber disclosure rule, adopted in final form in July 2023 under Item 1.05 of Form 8-K, requires public companies to report material cyber incidents within four business days of determining materiality. That clock does not pause because the incident happened at a vendor. The SEC's final rule makes clear that third-party breaches count.
In the EU, the NIS2 directive (Directive (EU) 2022/2555), which member states were required to transpose by 17 October 2024, pulls managed service providers directly into scope under Annex I. That means the same providers Acronis is addressing now sit inside a regulated perimeter, with incident notification duties of their own.
What should a customer of an MSP do with this?
Ask your provider to walk you through the six points, in writing, with dates. A customer who cannot get a straight answer on how quickly their systems would be restored, and from backups stored where, is a customer flying blind.
Two questions carry most of the weight. First: if our production systems were encrypted tonight, when would we be taking bookings, payments or patient records again tomorrow? Second: are our backups held in a form the attackers cannot reach from our network?
Neither question is technical. Both are answerable.
Common questions
Is this checklist a legal requirement?
No. It is guidance from a vendor. It does, however, line up with the recovery and reporting expectations built into the SEC rule and NIS2, so treating it as a floor rather than a ceiling is reasonable.
Do backups on their own still count as ransomware protection?
Not really. Modern ransomware groups hunt for backup servers first and delete or encrypt them before hitting production. Backups only help if they are isolated, tested, and paired with detection that catches the intrusion earlier in the chain.



