⚡ QUICK ANSWER
When a cyberattack hits, your first hour is critical. Immediately isolate affected machines and disable compromised accounts. Activate your incident response plan—notify staff, insurers and regulators. Then begin restoring from clean, verified backups. Speed and order matter more than perfection.
"You can have the best security in the world. You can have multiple layers of security, twenty different security products protecting your network. At some point, something will get through. It's just a matter of time," said Kieron Moore, European enterprise sales manager – cloud at Acronis during a ChannelCon EMEA session.
And that window is shrinking fast. With half a million new malware variants generated daily and a 115% surge in AI-generated ransomware, no defense is airtight. For ITSPs, the message is clear: A breach isn't a question of if—it's when. What separates good providers from great ones is what happens next.
Why Do MSPs Need an AI Governance Policy Now?
Your clients' data is already at risk
80% of companies experienced a cyber incident in 2025—ranging from lost data to full-scale breaches. Large enterprises may absorb the costs, but small businesses with 25–30 staff cannot afford two or three days of downtime.
That's where ITSPs play a critical role. As Moore put it: "You are their cyber staff. You are the guys that are protecting their organizations, stopping them from incurring around £31,000 to £1.3 million in costs every single day their organization is down."
What Is Cyber Resilience?
Cyber resilience is defined by NIST as: "The ability to anticipate, withstand, recover from and adapt to adverse conditions, stresses, attacks or compromises on systems."
In practice, resilience isn't about avoiding every breach—it's about recovering to an impact-less state as fast as possible. "You want that cyber response to be hours rather than days," Moore said.
To achieve that, Moore outlined a three-part response model:
- Proactive protection
- Best practice and compliance
- People and communication
The Three-Part Cyber Response Model
1. Proactive Protection
Proactive protection means finding vulnerabilities before attackers do—and layering defenses so that when something gets through, the damage is contained.
Key components:
- Robust EDR, XDR and MDR tooling
- Network security and segmentation
- Off-site, immutable backups
- Tested disaster recovery capabilities
Moore flagged a common gap: "It's all well and good having cloud backups, but that 24-hour SLA you've promised might not be possible if you've got to wait three days for a new piece of hardware to be delivered."
For clients in finance or insurance who can't work remotely, he advised preparing emergency office contingencies—and testing them proactively. "Talk about those fifty staff that can't work from home and make plans for them."
2. Best Practice and Compliance
Technology alone isn't enough. Clients need to be training, testing, and auditing on a regular cadence.
Align to a recognized framework:
- ISO standards
- Cyber Essentials Plus
- NIST
Test regularly with:
- Penetration tests
- Backup validation
- Full disaster-recovery drills
On cyber insurance: 40% of cyber insurance claims are rejected due to poor audit trails. Coverage is only effective when it's backed by documented best practice. Moore's advice: Notify your insurer immediately when an incident occurs—they should be the first call after the police. Early notification gives them the opportunity to advise and ensures you stay compliant with your policy.
3. People and Communication
When systems go dark, communication is often the first casualty. If your CRM, work emails and staff contact information are encrypted, you lose the ability to coordinate at exactly the moment you need it most.
Moore's practical fixes:
- Keep a USB stick (or offline document) with personal email addresses and phone numbers for all staff
- Maintain offline records for customers, suppliers, regulators and insurers
- Notify suppliers whose systems are connected to your network—they may be at risk too
And test everything—not just backups, but full-scenario simulations. "We're talking about full-scenario testing—your CRM going down, a full ransomware attack. These things need to be tested regularly," Moore said.
What Should You Do in the First Hour of a Cyberattack?
When a breach hits, follow this sequence:
Step 1: Contain >> Isolate affected machines. Apply network segregation. Disable compromised accounts. Most EDR and XDR tools support all of these actions.
Step 2: Activate >> Trigger your incident response plan immediately. Communicate with staff, suppliers and regulators. Notify your cyber insurer—early.
Step 3: Recover >> Restore from verified, stable backups. Confirm systems are clean before reconnecting. Validate that business functions are operational.
Step 4: Monitor >> Don't assume recovery means safety. Dormant ransomware can sit undetected in backups for months. Post-incident monitoring is critical to prevent reinfection.
Frequently Asked Questions
Do I need a cyber insurance policy as an ITSP? Yes—but coverage is only as strong as your documentation. 40% of claims are rejected due to poor audit trails. Align to a recognized framework and keep records of every action taken during an incident.
How long does it take to recover from a cyberattack? Recovery time varies, but the goal should always be hours rather than days. ITSPs with tested incident response plans, immutable backups, and clear communication protocols recover significantly faster than those without.
Should I inform my clients' suppliers during a cyberattack? Yes. If a supplier has software connected to your client's network, they may also be at risk. Notification should be part of your standard incident response communications.
What is the NIST definition of cyber resilience? NIST defines cyber resilience as "the ability to anticipate, withstand, recover from and adapt to adverse conditions, stresses, attacks or compromises on systems."
What documentation should I keep during a cyberattack? Document everything—and start immediately. Whether it's a notepad, a notes app or a full EDR/XDR platform, a complete audit trail supports insurance claims, regulatory compliance, and post-incident review.
Turning Chaos into Calm
Attacks are going to happen. But preparation is what turns panic into process. ITSPs who invest in proactive protection, tested response plans and clear communication frameworks will recover faster—and protect their clients better—when the inevitable occurs. Because when the breach hits, it's not panic you need. It's a playbook.
ChannelCon EMEA │ 9-10 November │ London │ Register Now
GTIA Members: Check out the Cyber Resource Hub on the Member Portal.
Not a member yet? Join now!

