Aaron Jacobs has seen a few things. With nearly 25 years in the IT industry, including 20 as an MSP and now as a principal sales engineer at Sophos, Jacobs is on the front lines of cybersecurity incident response and managed detection response services. He’s been a first-hand witness to a lot of funny, outrageous and downright scary security stories.He’ll share some of these real-life experiences during a keynote session at the GTIA ANZ Community meetings 17 March in Auckland, New Zealand and 1 April in Melbourne, Australia. We asked Jacobs a few questions about what he’s seen, what to expect from the session and how MSPs can improve their cybersecurity posture. Here’s what he had to say.
What is it like to be on the front line of responding to a cybersecurity attack?
I’ve seen plenty of disaster stories from the emergency incident response side, where we get to pull an incident apart forensically and see all the steps that were taken and the root cause, but also then at mass scale with MDR, to see what attackers are doing, how their methods change over time, and what the flavour of the month is.
What is the biggest cybersecurity challenge for MSPs today?
Many MSPs struggle to confidently articulate the value of cybersecurity investments, leading them to prioritize cost over security. This often results in deploying solutions they don’t fully understand, only realizing the gaps when an incident occurs.
What is the most egregious incident you’ve worked on?
One case involved a remote access tool intended for a building management system that was breached due to fault of the external contractor. It doesn't seem like much, but the result was the attacker laterally moving from that device to the core of the environment, stealing a significant amount of very confidential information, destroying the entire backup infrastructure and deploying ransomware to almost half of the computers in a 10,000-user organization. This resulted in a ransomware payment of many millions of dollars. A small misconfiguration and lack of visibility can have massive consequences.
What is one simple way MSPs can improve their security?
Aligning to a vendor or specialist to outsource the complex, resource-intensive parts of security operations, like 24x7 monitoring for example, and focus on consultative services like proper deployment, configuration, security posture improvement and framework alignment. This approach is not only easier to deliver but also far more profitable for MSPs.
What is the biggest weak point you see in MSPs?
The biggest risk isn’t a particular weak spot or attacker technique or procedure—it’s the months of recovery work, business disruption and financial loss that follow. What’s often overlooked is the mental toll on those involved. A major breach can be crippling, not just for customers, but for the MSP staff itself.
How are attackers changing their methods?
We’re seeing a trend away from vulnerability exploitation toward abusing exposed remote access methods without MFA. While gaining access via vulnerabilities is still very significant, attacks targeting VPNs with stolen credentials have surged. It’s a low-effort, high-reward strategy. Why break in through a vulnerability, when you can just log in with stolen or purchased credentials? This has caused a huge spike in social engineering efforts to simply ask users for their credentials—which works far more often than you would think!
Are MSPs bigger targets for attacks than two years ago?
Yes and no. While MSPs remain attractive targets due to their access across multiple customers, many are moving to more secure RMM platforms that enforce MFA by default. Vendors are forcing stronger authentication methods against their cloud-based platforms where the MSP is no longer responsible for patching, reducing some risks, but MSPs must still take ownership of their security.
What is your best advice for MSPs around cybersecurity?
Get the basics right—everywhere. Many major cyber incidents stem from fundamental mistakes and human error. Cybersecurity shouldn’t be an optional extra; it must be a core part of managed services. I will explain and demonstrate this further in my session, breaking down real-world examples of where things go wrong and how MSPs can better protect themselves and their customers.
Follow us on LinkedIn! #WeAreGTIA

