
The IT Experts Podcast · 2026-06-28 · 38 min
Key moments - from our scoring
Substance score
57 / 100
Five dimensions, 20 points each
Ken Roulston, a 47-year veteran in IT services who built an MSP to £17m revenue and 120 staff before acquisition, walks through a devastating ransomware attack on the newly acquired southwest London business in September 2021. The hackers exploited a non-compliant two-person customer to gain entry, then waited months before launching the attack during financial year-end - the worst possible timing. The private data center serving 42 major clients (solicitors, professional services) was crippled, and Roulston's team discovered their backup transition from Tiered backup to Microsoft Blob had failed catastrophically; neither primary nor secondary backups were functional or usable. After negotiating the ransom down from £1m to £300k through dark web intermediaries, the team spent three weeks rebuilding 42 environments from scratch while managing client fury, ICO investigations, and Met Police involvement. The total £500k impact (£300k ransom plus £200k in rebuild costs, overtime, compensation, and legal fees) was partially offset by migrating 85% of revenue-bearing clients to Azure on three-year contracts, though some smaller clients were lost. The core lesson: backup verification, isolated secondary backups, and enforcing Cyber Essentials+ compliance on every client are non-negotiable, and complacency around security will cost you the business.
A small two-person customer who rejected security recommendations was running unprotected systems and became the initial entry point. Once inside, the attackers used compromised credentials as a master key to access all systems and data across the data center undetected.
The acquired company had been transitioning from Tiered backup to Microsoft Blob between June and September but failed to verify the backups were actually working. Neither the primary backup nor the isolated secondary backup were functional or contained usable data.
The ransom was negotiated down to £300k (from an initial demand of £1m) through dark web negotiations, but the total £500k cost included £200k in additional expenses for system rebuilds, staff overtime, customer compensation, legal fees, and new security tools.
After three weeks of around-the-clock rebuilding, the MSP retained 85% of revenue-bearing clients and moved them to three-year Azure contracts as part of the recovery. Some smaller clients were lost during the downtime period.
Yes, the attackers provided the key on Sunday and even offered a week of customer service support afterward. The Met Police cybercrime division suggested this particular ransomware group was well-known and maintained a reputation by honoring ransom agreements to avoid getting bad references.
Our reviewer’s read on each dimension, with quotes from the episode.
The first-hand narrative contains genuinely useful operational detail - how the attack propagated from a non-compliant acquired client, the stripe-backup failure mode, the Friday-night banking trap for crypto transfers, and the hackers' timing around financial year-end. However, the 'lessons' segment retreats into well-worn MSP security platitudes and the episode has significant filler and host throat-clearing.
they had started to move away from using TIP backup to Microsoft Blob and were in the middle of that transition, but failed to verify that the backups were actually working. So not only was the primary backup not complete, also the secondary backup which was off site
they unveiled it or launched it I say in mid September. So we had gone through the whole situation and found that what had happened was due to human error
The 'it's not if but when' framing is repeated verbatim multiple times and the three closing lessons (baseline client security, verify backups, eat your own dog food) are well-circulated MSP advice. The genuinely fresh angle is the hacker-reputation-maintenance observation and the hackers tracking acquisition announcements to size the target, but these are anecdotal rather than developed as contrarian frameworks.
when they did provide the key on the Sunday, they also provided us with a week's worth of customer service facility to help with any issues
this particular ransomware group...had a reputation to maintain and they didn't want to get a bad reference by not actually fulfilling their commitment
Ken is a genuine MSP operator with real scale - built from scratch in 2009, grew through six acquisitions to £17M revenue and 120 staff before a trade sale. He is speaking from direct lived experience of the specific event described, not as a vendor or thought-leader, which gives him high credibility for the MSP audience.
in 2009 I started an MSP from scratch, bought two businesses, put them together, and then over the next number of years acquired four more companies. So we got up to the point whereby in 2023 we were turning over about 17 million of revenue, had 120 staff
I've described to many people as the worst period in my life for reasons which will become obvious
The episode is anchored in concrete numbers throughout: £300k ransom paid, £200k in ancillary costs, 42 affected managed service clients, 85% recurring revenue retained, three weeks to restore, a £5M revenue base in the acquired entity, and a specific timeline from June to mid-September 2021. The backup failure mechanism (mid-migration from TIP to Azure Blob, producing unrestorable stripe backups) is technically specific. Deductions for no named ransomware group and no named client examples.
we were able to negotiate the price down to 300,000...The other 200,000 came from the costs that we had to incur. To rebuild the systems, the overtime that we had to pay, the compensation that we had to pay out to some customers, the legal fees
we retained 85% of the revenue, recurring revenue we had from M, our client base. And what's more, we got them all onto three year contracts based on us moving them to Azure
The host asks a few substantive follow-ups (how the attackers communicated, whether targeting was deliberate, the size of the business at the time) but frequently defaults to affirmation and echo ('absolutely', 'brilliant', 'that's just mad') rather than pushing on hard edges - for example, the decision to pay the ransom or the absence of cyber insurance on the acquired entity are never meaningfully challenged.
Do you believe that they targeted you because they knew the size of the business and what was going on with the acquisitions
what would be the three absolute non negotiable actions, specific actions that every single MSP should be doing this year
Computed from the transcript - who did the talking, and the words that came up most.
In this episode of The IT Experts Podcast, we share one of the most honest and eye-opening conversations we have ever had about a ransomware attack and the devastating impact it can have on an MSP. Ken Roulston joins me to openly discuss the events that led to a real world cyber incident which ultimately cost more than £500,000, challenged every part of the business, and tested the resilience of the leadership team in ways few business owners ever experience. This conversation is not designed to create fear. It is designed to create awareness. Every MSP owner believes they have the right security in place, the right backups running and the right processes protecting both their own business and their clients. Ken's experience demonstrates why confidence must always be backed up with verification, discipline, and continual improvement. Ken shares the full story of how a successful acquisition appeared to strengthen the business before a ransomware attack turned everything upside down. What began as a routine business trip quickly became one of the most stressful weekends of his career.
Transcribed and scored by The B2B Podcast Index.
Speaker A: In this episode of the IT Experts Podcast, we share with you the real details behind an MSP ransomware attack. Welcome to the IT Experts Podcast, the only podcast to help MSPs scale to 1 million. And if already there, get to 5 and go fast. At the end of the day, isn't it all about building a business that works for you rather than you for it? I hope you enjoy the show. So, good morning, good afternoon, good evening, welcome to the IT Experts Podcast. Great to see you again. And today we've got a bit of a sobering podcast for you with our, uh, amazing friend of the MSP growth hub, Ken Raulston. How you doing, Ken?
Speaker B: I'm good, thank you, Ken.
Speaker A: Through the conversations that we've had with Ken, who's, I'll, uh, get him to explain who he is and who he helps in a minute, but his amazing legacy in the channel, we are going to talk to you today about a situation, very unfortunate situation, where Ken's previous business was hit by a ransomware attack. And the purpose of this isn't to scare you. The purpose of this is to bring to real life and to, uh, help you understand how it feels when that horrible event happens. And we all sit there, we talk to many MSPs. It's not a matter of if, it's a matter of when. And you sit in MSPs going, I've got my security stack in place, I've got this in place, I've got that in place. And we don't want anybody who listens to this podcast to be affected by this. So we're going to share Ken's story today, which is going to be, uh, very deep, I think, and very interesting on exactly what happened. But before we get cracking, Ken, do you want to share with the audience who are you, what do you do and who do you help?
Speaker B: Okay. I've worked in the IT services industry now for 47 years. Started off as an engineer, moved into sales and into management, ran an IT break fix business during the 90s, and then in 2009 I started an MSP from scratch, bought two businesses, put them together, and then over the next number of years acquired four more companies. So we got up to the point whereby in 2023 we were turning over about 17 million of revenue, had 120 staff, and we got bought by a larger MSP player based up in Manchester. Since then, I've been working with a number of vendors, giving talks at different events, primarily on my area of particular interest, which is M and A helping organizations grow strategically through acquisition, helping them through that journey. So I work with a number of MSPs around the UK and Ireland specifically in that regard, either on a retainer or project basis. Yeah, that was the enjoyable fun side of the msp, the bit that we're going to be talking about today. I've described to many people as the worst period in my life for reasons which will become obvious. But yeah, I'm happy to do it on the basis that I do feel that a lot of MSP owners are potentially complacent and not necessarily fully aware of the risks that they are undertaking in running their business. So happy to do whatever you need and throw whatever questions at me you want.
Speaker A: Yeah, sure. And I think straight off the bat, we only know you, Ken, as the successful fun go giver, uh, that you are. And I think today we're going to, as you said before we got cracking, we're going to rip up some memories that may not want to come through but for good use for the listeners here today. So talk us through what was going on in the msp, what was the size of the msp, what was happening, what was the environment like before the attack took place.
Speaker B: Okay, that's a very interesting place to start because in June 2021 we had just completed our last acquisition, which was a company in just southwest London. It was a business that uh, we decided to acquire because it had a very strong capability in cloud. It was running its own private data center, but it had uh, developed skills in Azure and was starting to move some of its clients across into the Azure world. So we saw a good opportunity to acquire a business that had high levels of profitability, had a good customer base, had a strong track record and we knew that by acquiring that business we were going to be adding significant value to our own customers company because we would increase the ebitda, uh, it would fill in some of the gaps in our portfolio. So as of June 21, the roses were definitely red and life was good. What then happened was that we had been approached by a couple of organizations who were interested in acquiring us, um, subject to us completing that acquisition. And then I remembered very well, I went across from, from Belfast, where you can tell by my accent I'm from, and arrived at uh, Heathrow on a Tuesday morning, switched on my phone for it to blow up essentially in my hands. Not in a Israeli attack type of way, but in terms of the amount of messages and calls that I was getting.
Speaker A: So other attacks are available?
Speaker B: Yeah, essentially I got a, my initial message was the Private data center that belong to the company that we acquired in June 21st appeared to be down. None of the customers were able to access anything. Didn't sound good. But I was literally on my way to two meetings that day with companies who were potentially interested in acquiring us and had provided sort of an outline of the valuations which were definitely of interest. So I suddenly found myself sitting with people talking about selling the business and how wonderful our business was. But at the same time, in the back of my head I knew that there was a problem back at the ranch, but I wasn't sure how serious it was. By the end of the day it was fairly obvious for a number of reasons that we had been hacked. The private data center, I should say, of the company that we acquired had been hacked. Thankfully we had not yet, uh, integrated that's network with our main systems. So it was still standalone. So it didn't affect all of the other systems that CMI had in place, but it did affect all of the customers, which was 42 major customers using that uh, data center to differing degrees. But essentially what it turned out was that none of the 42 businesses had any IT capabilities apart from email. Everything else was run out of the data center which was effectively wrecked by the hackers. And we then got the message through to say that we had been hacked and that we could buy the key to unlock uh, all of the data and get our hacked for an amount of money, which was initially, I think they're first offer was about a million. We went back to them and said we can't justify a million. And we saw something funny in their message which made us think, I don't think they've got the right company. And we went back to them and pointed out that I don't think you've got the right business here. And they said, oh, apologies for that. We know with you it'll be half a million. That actually, oh my word, they were dealing with somebody else at that same time. So they brought it down from a million to half a million. Oh, we got a discount then we got a discount. So that of course was something that we didn't want to do for obvious reasons. We spent the next couple of days trying to see what we could do to recover our systems, to see if we could back up or use our backups, but through a variety of circumstances. And I can explain a wee bit more, not particularly technically, a wee bit more about how it all happened, but one of the key things that we found out was that we didn't have any backups or at least any working backups. The situation came about because once we got through the whole thing and obviously there's a bit more to talk about and we were able to look back through various records, we found that the attack had started through one of the smallest customers, that this business that we acquired had a very small sort of two man outfit who didn't really buy into it, didn't necessarily value it, hadn't taken up any of the recommendations, but had been allowed to continue to run their systems relatively unprotected only for them to be hacked. A few days after our announcement was made public about us making the acquisition. So it looks and still appears to us to be a case whereby the hackers had identified that we may be a good target to get some money out of because we were in a business. So they targeted, we acquired, targeted and got into the least capable user but didn't, they just left what they did there, they didn't push the button on until September when we were a few weeks away from our financial year end. And of course that was the worst possible time potentially for us to get hit. So they unveiled it or launched it I say in mid September. So we had gone through the whole situation and found that what had happened was due to human error on the company's part that we had acquired the backups that they had been using, were providing some problems and between June and September, uh, they had started to move away from using TIP backup to Microsoft Blob and were in the middle of that transition, but failed to verify that the backups were actually working. So not only was the primary backup not complete, also the secondary backup which was off site. So we found ourselves by the Friday of that week in a situation whereby we knew we couldn't restore the systems, we couldn't recover the data and we felt we had no option but to effectively pay the ransom. That was something that none of us wanted to do. We decided that we would take some legal advice. We actually spoke to somebody who was high up in the cybercrime division of the Met Police who said officially his position and their position is do not pay the ransom. But uh, unofficially pretty much said look, doesn't look like you have any other options, you're going to have to do it. And our concern of course was we pay the money to these people which of course had to be done through uh, a cryptocurrency. Yeah, not normal bank transfer which led to uh, another whole issue. But we pay the money only for them not to provide the key. And then we find ourselves in a situation whereby we've let out money and we still don't have our data. So that over that Friday meant that I spent some time through a colleague doing stuff on the dark. Where were these people? Was able to negotiate the price down to 300,000, so got a further discount for good behavior. We basically said, okay, we will pay you the money. This got to late on a Friday afternoon after the point in time when banks are able to transfer money normally. And um, of course we didn't actually have the money sitting in our own account, but we needed to get the money. So we found mechanisms to pull the money together, which was problematic because moving large sums of money around outside normal working hours on a Friday evening fell into the banking system's traps of money laundering all the rest. And we were getting repeated issues coming up about who's this money going to, what's it for, et cetera. So it literally took us all that evening and all that night to get to a point where by around about 9:00 clock the next morning, Saturday morning, the money was finally in a position to be transferred. We then held our breath. By the Sunday we got word that the money had been received and that they were releasing the key. So we thought, okay, it's been rough, but at least now we get the data back and we can move forward. Because you can imagine at this stage, clients were down three or four days, it had no access and they weren't very happy, it's fair to say. So we got the key and what we found was that we were able to get just about all, not all, uh, but most of the data back. But what we found out was that not only did they steal the data, but when doing it, they trashed all of the systems, virtual systems that we had running within the data center in order to extract the data. So what we were faced with on the Monday morning was having to rebuild 42 environments from scratch. Anybody who runs an MSP or understands what that involves, it's not a simple process, requires a lot of work, not only to get the basic bones of it built, but to get it configured and tailored and tweaked. That has maybe been years worth of amendments made to get it to the operational level it was at prior to the event.
Speaker A: Wow.
Speaker B: Uh, the story goes on and apologies for waffling on, um, but.
Speaker A: No, no, keep going.
Speaker B: But what that kicked off was three weeks of literally working around the clock, having our staff working around the clock, working through all of these different customer sites. To get them back up to an operational state. And of course another three weeks of downtime on top of the three or four days worth of downtime only made the customers ever so slightly more irate. And of course lots of uh, flak was flying from every source legally and so on. We had to get involved with the ico, we were involved with the Met Police. So it was a very challenging period. But the good news is after three weeks we got everybody up. We did lose a few clients through the process, thankfully from our viewpoint, some of the smaller clients. But what we did was we retained 85% of the revenue, recurring revenue we had from M, our client base. And what's more, we got them all onto three year contracts based on us moving them to Azure as a matter of priority, which is what we then set about doing. So the three weeks to get them back up and running was the next part of the process. So it went from three days initially to three weeks and then it was three months probably to get everybody signed up and not signed up, but get everybody across into Azure and away from that old platform which had been working for 14 years without a hitch. Everybody was quite happy with it and then all of a sudden, bang, all went mad.
Speaker A: Thank you for sharing that, Ken. That was just. That must have been your longest weekend of your life. Are you going to come? Where are we going to get this money from? Who's judging us? And that's, that's ah, nothing else but net profit. Right. That takes a long time to recover from that. That doesn't sit around. That sort of money doesn't sit around lightly. It must have been extremely scary as well. Communicating with people that you have absolutely zero minus trust on whether or not they're going to say the right thing, do the right thing, even give you the information back.
Speaker B: Absolutely. But an interesting point, um, which is actually quite funny is that when they did provide the key on the Sunday, they also provided us with a week's worth of customer service facility to help with any issues. Now in fairness there was very little that they could do to help us at that stage because they'd done all the damage that there was to be done and they weren't in any position, but it was the fact that they offered this. Now I should have said that one of the reasons why we decided to move ahead was that this particular ransomware group, which we believe was Ukraine based, interesting enough at the time, but may have been Russian, not entirely sure, were a, uh, well known hacker in the industry. And when we spoke to the head of cybercrime in the Met, or I'm not sure his exact title, but somewhere of that level. And we mentioned our concern about paying this money only for to get nothing back. He said that he felt confident that we would get the key because this group was well known and therefore they had a reputation to maintain and they didn't want to get a bad reference by not actually fulfilling their commitment. In an ironic way, we were probably attacked by one of the better hackers in that sense because they didn't want to blot their copybook by not delivering upon the service and on their commitment.
Speaker A: Quite incredible, isn't it? I'm sitting here thinking that you got your customer service there, you've got. They're in communication with you. Do you find them on Trust the trader or trustthehacker.com and it's like. It's just an absolute crazy, crazy situation.
Speaker C: Hey, just a quick one from me for everybody that's listening. Stuart here. If you're serious about growing your msp, but you're not sure what helps, right, for you, then just grab our ultimate MSP Growth Guide. It's a really simple way to check out what's out there for support that could really help you work. There's no fluff, there's no filler, just facts. Or alternatively, if you want to meet us face to face and see how we do things up close, come along to one of our events. They're regularly put on. They're all in the links below. Go check them out. And now it's back to the show.
Speaker A: Thanks, Stuart. What is interesting with this, Kent, is that if you're an MSP and you're sitting here right now going, yeah, we do backups, so we're safe, what would you say to them?
Speaker B: Yeah, God, it's one thing doing a backup, it's another thing verifying that what you're backing up and what you've got is actually usable and, um, that it's secure. The first point about verifying it is an obvious thing. And, and the guys that were in that business who were running that part of the business thought that whenever they saw whatever was coming up on the screen that the backup was working, but they never actually tested it out. And, um, what came to the fore was that it was backing up some of the data, but not all of it. But the way it was backing it up, uh, meant that none of the data was actually usable. It was backing it up. And technically, as I'm not the person to do this, but in a way where it was like stripe sort of backups, where it was taking bits of data from different folders but nothing complete. So that would be the first thing is always make sure that if you're doing any backups of your own systems, and of course this is good advice for your customers as well, is make sure that you're verifying and checking that the backups, uh, are actually working. In terms of the second aspect of it, the way I've tried to describe this situation to people, it's a bit like somebody being given the key, the master key to a hotel. They can use that master key to get through the front door, which was getting through from the naive user's business into the private data center. So the key that they had unlocked, uh, a mechanism to get around the systems that were in place. Now, I have to say the systems that were in place were actually fair and reasonable. The ICO gave us a clear bill of health for the protection that was in place. But as we say to, uh, anybody, or as I used to say to everybody, you can never provide 100% risk free guarantees when it comes to security, even in your own systems. So these guys were clever enough to find the way around our internal system. So once they got into the hotel with that master key, they were literally able to go into every bedroom with that master key and take any valuables out of the room, which is the data, but undetected. Undetected. And trash the room at the same time. And then of course, imagine the analogy going along the lines that you store a lot of your valuables in a safe, the safe was also accessible, and then the backup safe was also deemed to be accessible because it wasn't sufficiently isolated from the main backup system. So there was lots of lessons. One, verify that you're doing the backups are working. Make sure that your secondary backup is sufficiently isolated and regularly updated to ensure that if something goes wrong, the primary backup, at least the secondary backup is available essentially, in many respects. Even though, as I said, the ICO gave us a relatively clean bill of health, the hackers were clever enough to get around our systems and do considerable damage. The backup issue was our fault. It was a human error issue, which is when it comes to cyber security issues and human error is the biggest risk. And ah, obviously the situation with us, I should say that also the title of the presentation was about the 500,000 hit. Half a million hit. And I've said the answer 300,000. The other 200,000 came from the costs that we had to incur. To rebuild the systems, the overtime that we had to pay, the compensation that we had to pay out to some customers, the legal fees, additional systems that we had to put into place, hard costs, never mind the soft costs of all the time and hassle and distress that it caused for everybody in the business.
Speaker A: How big was the business again at that time?
Speaker B: Uh, that bit of the business was doing about 5 million of revenue.
Speaker A: Okay.
Speaker B: At that point in time with about 42 active managed service clients. So you can tell from that that each of the clients were on, um, in the main, fairly significant. They were, yeah, pretty good, pretty special services businesses, solicitors.
Speaker A: All the wrong people. All the wrong people.
Speaker B: So people who rely on their it a lot.
Speaker A: Yeah. So every time I hear that there's been an event or a hack or compromise, we talked a lot about the backup. But the ultimate problem here is that uh, they, you allowed one of the clients, customers to be non compliant and to hand the master key out, didn't we? That's kind of the problem here. I remember years ago when I was at college, uh, someone said to me, what's the main fuel for a gas fire? And I said, it's gas, isn't it? He said, no, it's not. It's electric because electricity lights the gas. And it was like, okay, that's interesting. So the real problem is not the fact that the backups didn't work. That was like cock up. Number two. The real problem was the fact that I say you, but the business allowed somebody to be running a non compliant security. And this is where I'm now going to be pointing. Everybody, I have this conversation back to. If you're not Minimum Cyber Essentials plus and taking this seriously and all your clients as well, you need to go and listen to this podcast because it's a scary environment. You're letting somebody hand out the master key to your kingdom, aren't you?
Speaker B: Absolutely. And uh, the core CMI business at that stage, the Mothership, for want of a better term, had a very strict policy of all of its customers needing to have a baseline of security for us to provide them with the service. Because we were still in the early stages of integration, we hadn't got around to enforcing that policy on all of the customers of the company we acquired. But absolutely since that and when I've given this presentation or talk at other times, and every client that I meet, every MSP that I talk to, I say you've got to make sure that your clients have got the best level of security in place, whether it's cyber essentials or even a higher level. But you are putting your business at risk if you allow them to effectively not take on board that recommendation. And you need to be prepared to walk away from clients who don't effectively take that on board. Because security is scary. It's going to get even more scary, I believe, uh, going forward with advances in technology and AI and all the rest of it. So it is just something that you cannot be complacent about. And you have to absolutely make sure, even though it may be uncomfortable, you need to force your clients to make sure that they've got the basic, least the basic levels of protection in place that meets the minimum sort of thresholds.
Speaker A: Do you believe that they targeted you because they knew the size of the business and what was going on with the acquisitions and they knew that you could pay a significant sum of money?
Speaker B: Yeah, we were advised that this organization was very, uh, professional in its ways of approaching things. It would have picked up on the fact that we had done that acquisition and immediately gone searching into the, our accounts and um, what are the accounts of the company that we acquired and therefore determine what sort of level of compensation that we were able to pay without necessarily, I'm going to say the company that we acquired, if they've been hit with a half million bill, it would have sunk them. We had the capacity to effectively to pay it and stay in business, albeit with severe dent to our profitability as a result. So, yeah, these guys that are doing this are clever. They are not stupid people. And they're not stupid neither technically nor commercially. They know what they're about and they're one step ahead of most of the rest of us at any given point in time, if not further. So, yeah, from what we understand, the timing of it and of them accessing that user site when they activated the widget, that kicked things off. Yeah, we're fairly convinced that they were tracking us and, um, were fully aware of who we were and what we were doing, even though they sent us the wrong ransom note when it came to it.
Speaker A: Well, that's just an administration error, Ken. You should leave them about administration.
Speaker B: So they were able to correct that issue and send the right one.
Speaker A: How did they communicate with you?
Speaker B: It's all done through the Dark Web and I, to this day haven't got a clue how that, uh, worked. My technical director, he was able to manage it and yeah, we had to sit around his machine in an isolated context just to work on this channel.
Speaker A: Obviously now we know a little bit more about how it actually happens. We hear about it in presentations from vendors but this is like real life and I'm sure that everybody is just bolted in just going crazy. This is just mad. You can feel it and you can hear it, the frustration and the pain that you went through. But okay, it's an illegal business, but it's a business all the same. And they, there's no point in them hacking someone who's if they turn up to a five or six seven hundred thousand pound MSP and said I want half, three hundred grand, they're going to go just take it mate, because I'm shutting the business down. So what would you say to so they obviously want to be a good customer for them would be someone who we're going to charge them X amount of money that's going to be relevant to what we think that they could get hold of that A we're going to get the cash and B it's not going to completely crush that business. So for a smaller MSP that could be 20 or 30 grand, what would you say to an MSP who's under a million pound, who's sitting there going well you know what, they're just not going to bother with us because they're only going to want a small amount of money.
Speaker B: That would be very naive because these guys run their systems in a very efficient way, very automated way and to them it's all about, it's a numbers game. If they can get to 100 MSPs relatively easily, they'll do it no matter what size they are. Of course they'll adjust the ransomware demand to a level as you say, that ah, is within that scope of ability to pay. But yeah, they'll quite happily take a lot of small clients along the way as well as the bigger fish because it's a very low cost of sale from their viewpoint. They deploy a bit of software, goes off there, finds its way through a system. So to them the same amount of work is involved in hacking into small businesses, a large one. Okay, the rewards are less but it would be naive to think that a small business isn't going to get attacked because we any MSP is a gateway to lots of other customers. Yeah. Um, and it's if targeting one MSP they can effectively affect 20 or 30 end users as a result of that's easier for them to do to hit one MSP than to go to 20 or 30 small end users or smaller. Again yeah, no, I can't give it any more succinctly than you've just got to assume, um, it's not a matter of if, it's a matter of when you're going to get it. So you've got to make sure that you've got your systems in place, your backups protected. You gotta have your cyber insurance covered off too, because that was the other thing that the owner of that business was relatively, again, maybe naive might be the word. Who felt that, like a lot of people do, why pay insurance? Because they never pay out. But if we had the insurance cover in that business that we or should have had, we would at least have had some redress. Might not have it all back. We were having redress, of course, we had it in the mothership business. Yeah, it was too late at the point in time it happened. We were all distracted by the issues of talking to customers, updating processes, getting the staff on board. The first 90 days of any acquisition, you tend not to make many changes. You tend to be listening and learning. And that's what we were doing. We were only getting around starting to integrate when of course the situation hit again. So I would say don't be complacent, don't be naive. Put all those mechanisms in place to at least mitigate the issue as and when it does happen.
Speaker A: That's absolutely brilliant. Thank you, Ken, for your openness, your vulnerability, the honesty around this, and we're doing it to help share with everyone what are some of the you just mentioned there. Get your systems in place, get your backups protected, etc, what would be the three absolute non negotiable actions, specific actions that every single MSP should be doing this year, if not now, if not as soon as they get off this podcast to help mitigate themselves from being in this position. What does making sure your systems are in place look like in terms? A little bit of detail.
Speaker B: We've touched on most of these points I think already, but the first is make sure that all of your customers have a baseline security.
Speaker A: Great point. Yeah. Is that Cyber Essentials plus or is that Cyber Essentials or is that just. Does it not matter?
Speaker B: I think every MSP probably has slightly different views as to what level of security they're comfortable with. But you've got to have the basics. You got to have at least Cyber Essentials in place in, in all of the customers daily. Cyber Essentials Plus. But some businesses may want even on enhanced levels of protection beyond that. But there are businesses out there that are running with antivirus software thinking that's them covered.
Speaker A: I'm so it's madness.
Speaker B: So that would definitely be the first thing. The second point and again we've touched on is which is at the other end of the of the situation is if it does happen, make sure your backups, you've got backup tested them and that they are capable of restoring your systems in the event of something happening. Yeah.
Speaker A: How often would you do that? What would be a frequency that you would recommend? Is that daily thing, is it a weekly thing, is it a uh. I suppose it's how much data do you want to lose? Right.
Speaker B: Look, it's going to again vary from company to company. Of course it should be done as much as possible on a real time basis. Yeah, if it's all possible but that may not be feasible due to cost and overheads and etc. But as frequently as is humanly again I can't dictate that. I say ideally it's real time, anything less efficient but certainly there used to be the old father, grandfather, son father, grandfather type way of storing data and it's that type of approach you need to be doing daily backups of course and weekly backups and monthly backups but it's the verification of those that can take the time.
Speaker A: Yeah, got it, got it.
Speaker B: That's what falls into disaster recovery processes and so on. In terms of the third one, this probably goes into the heart of the system is assuming somebody does get through the front door for whatever reason through one of the users. You've got to. Don't be cobbler's children. Many MSPs talk a very good story when it comes to cybersecurity and they tell their clients to put, put this, that and the other layers of security in and wrap the various layers of the onions but they don't do it themselves. So I think you're never going to be 100% capable of stopping a very good hacker getting through because they will always find a mechanism. But you got to do your absolute most to protect that uh, system M and that means making an investment into your own security to a level whereby you are eating your own dog food in terms of what you're promoting. That may be painful in terms of cost, might be painful in terms of the impact it has on your day to day working. But I'm telling you, you just do not want to go through what my, what I and our staff went through because quite honestly it was the worst period of my life and I think a number of my colleagues would say exactly the same thing. I wouldn't wish it on my worst enemy.
Speaker A: No thanks once again for all those msp owners out there listening to this. Hopefully it struck a chord. Get your teams to listen to this podcast. Do that analysis on what Ken was talking about. Are you keeping safe with your clients? Keeping you safe? Are you making sure that you're running that level, the backups and then putting those tripwires and those alarms? So if anybody does get the master key, you, you pick it out. As always, Ken, thank you for your, your time putting this together to help the community. Lots of learning. I don't think there's anything more to say apart from what a shame, it was horrible to hear, but it's happening and it's happening even more, isn't it?
Speaker B: It's going to. I honestly believe it's a personal view that, uh, A.I. is going to make cyber security even more of an issue going forward because these bad actors, they will use AI to its fullest capability. Situations today that we take for granted will be severely under threat going forward. So the days of providing just basic managed services are probably coming to a natural sort of ceiling, but what businesses now need to do is really focus on making sure that they're developing their cyber capability to add more value to their company. Please.
Speaker A: Absolutely. Absolutely. I look forward to catching up on our next episode, which I'm not sure when it is. It's very shortly. I think it, hopefully it should be a little bit more jovial, but anyway, Ken, thanks again for your time and look forward to catching up with you soon. You take care.
Speaker B: All the best. Bye. Bye.
Speaker A: And if you've ever wondered what it feels like to be part of the UK's most powerful MSP community, then in next week's show, we lift the lid on our, uh, May 2026 client intensive event. We interview Stuart and the other coaches. We share with you the frameworks that we went through. We told you what's working right now, what's not working right now, and the biggest takeaways these clients had from taking action by stepping away from their business and focusing on it for two whole days, you're going to absolutely love this show. Don't forget to check it out next week. Oh, but one last thing just before you shoot off, and if you're curious about how this episode links with the ability to scale your MSP to a million, or if you're already there, accelerate to five. Then we want to invite you to come and take the MSP Mastery Quiz. And in just three minutes, you're going to get a 360 degree scan of your business where you can identify the one or two tactics that can help you, uh, find more time, engage and align your people and help generate more leads in your msp. It's really simple. Just click on the link in the show notes and if you have enjoyed this episode, we'd love to get some feedback from you by means of a rating review review on Spotify or itunes or your podcast platform of choice. We really appreciate every single one of them. Now you can go and enjoy the rest of your day and we look forward to catching up and connecting with you soon. All the best.
Speaker C: Now.